Skip to main content
Applies to BloodHound Enterprise and CE This page covers configuring the OpenHound GitHub collector for your GitHub organization or enterprise account. Use this page to choose an authentication method and configure the collector settings in the secrets.toml file or environment variables.

Prerequisites

Before you configure the GitHub collector, ensure that the following prerequisites are met:

Configure OpenHound

The GitHub collector needs different settings based on the authentication method you choose. You can set those values in one of two places: Click the tab that matches your authentication setup for details and example configurations.
Use this option when you need enterprise-scoped collection.secrets.toml
~/.dlt/secrets_github.toml
Environment variables
The pat_token field is optional for enterprise collection, but strongly recommended. If you omit it, the collector continues to collect GitHub App-supported enterprise and organization data, but enterprise SAML SSO, SCIM, and self-hosted runner nodes and relationships are not collected.The scopes you grant the PAT determine what it collects: read:enterprise for SAML SSO and SCIM data, and manage_runners:enterprise for self-hosted runner data. Grant only the scopes you need. The manage_runners:enterprise scope permits runner-management operations and is not read-only.

Configure GitHub Enterprise Server endpoints

GitHub.com is the default deployment and requires no endpoint configuration. To collect from GitHub Enterprise Server (GHES), set both the REST and GraphQL endpoint URLs in the [sources.github] section of config.toml or as environment variables. config.toml
~/.dlt/config_github.toml
Environment variables
rest_api_url and graphql_url must be configured together. Both values must use HTTPS and share the same origin. If you authenticate with a GitHub App, credentials.api_uri can only override the path on that same origin, not the origin itself.GitHub App authentication and secret scanning PAT validation use the configured REST endpoint instead of assuming GitHub.com, so existing GitHub.com configurations continue to work without changes.

Running OpenHound and Collecting Data

After you set the required configuration parameters, run OpenHound to start the collector and collect data from your . The collector will generate JSON files in the output directory that can be uploaded to BloodHound for analysis.
If your GitHub collection includes SCIM nodes and edges, upload the SCIM extension schema before importing the collected data.
Large GitHub organizations or enterprises can trigger GitHub’s API rate limits during collection. If you see failed or retried requests, tune the HTTP request parameters to ride out rate limits instead of failing the run.