{"meta":{"title":"Organizing remediation efforts for leaked secrets","intro":"Systematically organize and manage the remediation of leaked secrets using security campaigns and alert assignments.","product":"Security and code quality","breadcrumbs":[{"href":"/en/code-security","title":"Security and code quality"},{"href":"/en/code-security/tutorials","title":"Tutorials"},{"href":"/en/code-security/tutorials/secure-your-organization","title":"Secure your organization"},{"href":"/en/code-security/tutorials/secure-your-organization/organize-leak-remediation","title":"Organize leak remediation"}],"documentType":"article"},"body":"# Organizing remediation efforts for leaked secrets\n\nSystematically organize and manage the remediation of leaked secrets using security campaigns and alert assignments.\n\n## Introduction\n\nIn this tutorial, you'll organize remediation efforts for leaked secrets. You'll learn how to:\n\n* Create security campaigns to track remediation work\n* Assign alerts based on ownership\n* Monitor remediation progress\n* Communicate with stakeholders\n\n## Prerequisites\n\n* You must have both GitHub Secret Protection and secret scanning enabled for your organization. See [Pricing and enabling GitHub Secret Protection](/en/code-security/how-tos/secure-at-scale/configure-organization-security/configure-specific-tools/protect-your-secrets).\n* You must have existing secret scanning alerts available.\n\n## Step 1: Review your secret scanning alerts\n\nBefore taking action, you need to understand the current state of your organization's security alerts.\n\n1. On GitHub, navigate to the main page of the organization.\n\n2. Under your organization name, click the **<svg version=\"1.1\" width=\"16\" height=\"16\" viewBox=\"0 0 16 16\" class=\"octicon octicon-shield\" aria-label=\"shield\" role=\"img\"><path d=\"M7.467.133a1.748 1.748 0 0 1 1.066 0l5.25 1.68A1.75 1.75 0 0 1 15 3.48V7c0 1.566-.32 3.182-1.303 4.682-.983 1.498-2.585 2.813-5.032 3.855a1.697 1.697 0 0 1-1.33 0c-2.447-1.042-4.049-2.357-5.032-3.855C1.32 10.182 1 8.566 1 7V3.48a1.75 1.75 0 0 1 1.217-1.667Zm.61 1.429a.25.25 0 0 0-.153 0l-5.25 1.68a.25.25 0 0 0-.174.238V7c0 1.358.275 2.666 1.057 3.86.784 1.194 2.121 2.34 4.366 3.297a.196.196 0 0 0 .154 0c2.245-.956 3.582-2.104 4.366-3.298C13.225 9.666 13.5 8.36 13.5 7V3.48a.251.251 0 0 0-.174-.237l-5.25-1.68ZM8.75 4.75v3a.75.75 0 0 1-1.5 0v-3a.75.75 0 0 1 1.5 0ZM9 10.5a1 1 0 1 1-2 0 1 1 0 0 1 2 0Z\"></path></svg> Security and quality** tab.\n\n3. In the left sidebar, under \"Findings\", click the <svg version=\"1.1\" width=\"16\" height=\"16\" viewBox=\"0 0 16 16\" class=\"octicon octicon-chevron-down\" aria-label=\"chevron-down\" role=\"img\"><path d=\"M12.78 5.22a.749.749 0 0 1 0 1.06l-4.25 4.25a.749.749 0 0 1-1.06 0L3.22 6.28a.749.749 0 1 1 1.06-1.06L8 8.939l3.72-3.719a.749.749 0 0 1 1.06 0Z\"></path></svg> symbol to the right of **Secret scanning**.\n\n4. In the dropdown list, select `Default`. `Default` relates to supported patterns and specified custom patterns.\n\n5. Alternatively, you can select `Generic` to review unstructured secrets like passwords. However, generic patterns typically produce more false positives than default patterns, so consider reviewing these alerts after addressing higher-priority leaks.\n\n6. Review the total number of open alerts and repositories affected.\n\n7. Use filters to identify the most urgent alerts and prioritize your remediation efforts.\n   * To show leaks in **public** repositories, use `publicly-leaked`.\n   * To show secret leaks found in **more than one repository** within the same organization or enterprise, use `is:multi-repository`.\n   * To show secrets that are still **valid**, use `validity:active`.\n   * To filter by specific **service** credentials (AWS, Azure, GitHub), use `provider:`.\n   * To filter by specific **token types**, use `secret-type:`.\n\n8. Optionally, in the sidebar under \"Insights,\" click **Secret scanning** to see:\n   * Secret types that have been blocked or bypassed most frequently\n   * Repositories with the most blocked pushes or bypasses\n\n## Step 2: Create a security campaign\n\nYou can set up a security campaign to organize and track your remediation work across repositories.\n\n1. Navigate to your organization and click **<svg version=\"1.1\" width=\"16\" height=\"16\" viewBox=\"0 0 16 16\" class=\"octicon octicon-shield\" aria-label=\"shield\" role=\"img\"><path d=\"M7.467.133a1.748 1.748 0 0 1 1.066 0l5.25 1.68A1.75 1.75 0 0 1 15 3.48V7c0 1.566-.32 3.182-1.303 4.682-.983 1.498-2.585 2.813-5.032 3.855a1.697 1.697 0 0 1-1.33 0c-2.447-1.042-4.049-2.357-5.032-3.855C1.32 10.182 1 8.566 1 7V3.48a1.75 1.75 0 0 1 1.217-1.667Zm.61 1.429a.25.25 0 0 0-.153 0l-5.25 1.68a.25.25 0 0 0-.174.238V7c0 1.358.275 2.666 1.057 3.86.784 1.194 2.121 2.34 4.366 3.297a.196.196 0 0 0 .154 0c2.245-.956 3.582-2.104 4.366-3.298C13.225 9.666 13.5 8.36 13.5 7V3.48a.251.251 0 0 0-.174-.237l-5.25-1.68ZM8.75 4.75v3a.75.75 0 0 1-1.5 0v-3a.75.75 0 0 1 1.5 0ZM9 10.5a1 1 0 1 1-2 0 1 1 0 0 1 2 0Z\"></path></svg> Security and quality**.\n2. On the left panel, select **<svg version=\"1.1\" width=\"16\" height=\"16\" viewBox=\"0 0 16 16\" class=\"octicon octicon-goal\" aria-label=\"goal\" role=\"img\"><path d=\"M13.637 2.363h-.001l1.676.335c.09.018.164.084.19.173a.25.25 0 0 1-.062.249l-1.373 1.374a.876.876 0 0 1-.619.256H12.31L9.45 7.611A1.5 1.5 0 1 1 6.5 8a1.501 1.501 0 0 1 1.889-1.449l2.861-2.862V2.552c0-.232.092-.455.256-.619L12.88.559a.25.25 0 0 1 .249-.062c.089.026.155.1.173.19Z\"></path><path d=\"M2 8a6 6 0 1 0 11.769-1.656.751.751 0 1 1 1.442-.413 7.502 7.502 0 0 1-12.513 7.371A7.501 7.501 0 0 1 10.069.789a.75.75 0 0 1-.413 1.442A6.001 6.001 0 0 0 2 8Z\"></path><path d=\"M5 8a3.002 3.002 0 0 0 4.699 2.476 3 3 0 0 0 1.28-2.827.748.748 0 0 1 1.045-.782.75.75 0 0 1 .445.61A4.5 4.5 0 1 1 8.516 3.53a.75.75 0 1 1-.17 1.49A3 3 0 0 0 5 8Z\"></path></svg> Campaigns**.\n3. Click **Create campaign <svg version=\"1.1\" width=\"16\" height=\"16\" viewBox=\"0 0 16 16\" class=\"octicon octicon-triangle-down\" aria-label=\"triangle down icon\" role=\"img\"><path d=\"m4.427 7.427 3.396 3.396a.25.25 0 0 0 .354 0l3.396-3.396A.25.25 0 0 0 11.396 7H4.604a.25.25 0 0 0-.177.427Z\"></path></svg>**, then either:\n   * Select a pre-defined Secrets campaign template.\n   * Use custom filters to target specific alerts (for example, `is:open provider:azure` or `is:open validity:active`).\n4. Review the alerts (maximum 1000) and adjust filters if needed.\n5. Click **Save as** and choose **Publish campaign**.\n6. Fill out your campaign information, then click **Publish campaign**.\n\n## Step 3: Assign alerts to team members\n\nAfter creating your campaign, you'll want to assign individual alerts to the developers responsible for fixing them.\n\n1. On your campaign page, click <svg version=\"1.1\" width=\"16\" height=\"16\" viewBox=\"0 0 16 16\" class=\"octicon octicon-chevron-right\" aria-label=\"Toggle to expand or collapse the repository view\" role=\"img\"><path d=\"M6.22 3.22a.75.75 0 0 1 1.06 0l4.25 4.25a.75.75 0 0 1 0 1.06l-4.25 4.25a.751.751 0 0 1-1.042-.018.751.751 0 0 1-.018-1.042L9.94 8 6.22 4.28a.75.75 0 0 1 0-1.06Z\"></path></svg> to expand a repository and view its alerts.\n2. Click an alert to open its details page.\n3. In the right sidebar, click **Assignees**.\n4. Select a developer you want to fix the alert. Typically, this is the person who committed the secret or the repository administrator where the leak is detected. They must have write access.\n\n## Step 4: Monitor remediation progress\n\nOnce alerts are assigned, you need to regularly track your campaign's progress to ensure timely completion.\n\n1. On your campaign page, review the campaign summary. You'll see:\n   * **Campaign progress**: How many alerts are closed (fixed or dismissed) or still left to review\n   * **Status**: How many days until the campaign's due date\n2. You can explore campaign details:\n   * Expand any repository to see its progress in alert remediation.\n   * Set **Group by** to **None** to show a list of all alerts.\n   * Use filters to focus on specific repositories or alerts.\n3. Identify areas needing attention based on repositories with the most open alerts or no recent progress, then reach out to support those repository maintainers or assignees.\n\n## Step 5: Communicate with stakeholders\n\nThroughout the remediation process, you should keep stakeholders informed with regular progress updates. You can use information from your campaign dashboard to help you generate these updates.\n\n1. Navigate to the campaign dashboard.\n2. Identify the information you want to include in your reports. Consider these key metrics:\n   * Alerts resolved this week\n   * Remaining open alerts\n   * On-track vs. at-risk items\n   * Notable achievements or blockers\n3. Incorporate the metrics into your update, then distribute via email, Slack, Teams, or security meetings.\n\n## Step 6: Document remediation procedures\n\nFinally, you should create standardized procedures to make future remediation efforts more efficient.\n\n1. Develop secret-type-specific guides. For example:\n   * **AWS credentials**: How to rotate access keys and update services\n   * **GitHub tokens**: How to revoke and regenerate Personal Access Tokens\n   * **API keys**: Service-specific rotation procedures\n   * **Database credentials**: Safe rotation without service disruption\n2. Create a remediation checklist.\n   1. Verify the secret is actually leaked.\n   2. Determine if the secret is still active.\n   3. Revoke or rotate the compromised secret.\n   4. Update all systems using the old secret.\n   5. Test that systems function with new credentials.\n   6. Document the incident and remediation steps.\n   7. Mark the alert as resolved.\n3. Establish escalation paths.\n   * Define when to escalate to security leadership.\n   * Identify subject matter experts for different secret types.\n   * Create incident response procedures for critical leaks."}