secrets.toml file or environment variables.
Prerequisites
Before you configure the GitHub collector, ensure that the following prerequisites are met:- OpenHound installed with the GitHub collector included.
- For BloodHound Community Edition, install the OpenHound CLI.
- For BloodHound Enterprise, deploy OpenHound as a container.
- One of the following authentication setups configured:
Configure OpenHound
The GitHub collector needs different settings based on the authentication method you choose. You can set those values in one of two places:
Click the tab that matches your authentication setup for details and example configurations.
- Enterprise GitHub App
- Organization GitHub App
- Fine-grained PAT
Use this option when you need enterprise-scoped collection.Environment variables
secrets.toml~/.dlt/secrets_github.toml
The
pat_token field is optional for enterprise collection, but strongly recommended. If you omit it, the collector continues to collect GitHub App-supported enterprise and organization data, but enterprise SAML SSO, SCIM, and self-hosted runner nodes and relationships are not collected.The scopes you grant the PAT determine what it collects: read:enterprise for SAML SSO and SCIM data, and manage_runners:enterprise for self-hosted runner data. Grant only the scopes you need. The manage_runners:enterprise scope permits runner-management operations and is not read-only.Configure GitHub Enterprise Server endpoints
GitHub.com is the default deployment and requires no endpoint configuration. To collect from GitHub Enterprise Server (GHES), set both the REST and GraphQL endpoint URLs in the[sources.github] section of config.toml or as environment variables.
config.toml
~/.dlt/config_github.toml
rest_api_url and graphql_url must be configured together. Both values must use HTTPS and share the same origin. If you authenticate with a GitHub App, credentials.api_uri can only override the path on that same origin, not the origin itself.GitHub App authentication and secret scanning PAT validation use the configured REST endpoint instead of assuming GitHub.com, so existing GitHub.com configurations continue to work without changes.Running OpenHound and Collecting Data
After you set the required configuration parameters, run OpenHound to start the collector and collect data from your . The collector will generate JSON files in the output directory that can be uploaded to BloodHound for analysis.If your GitHub collection includes SCIM nodes and edges, upload the SCIM extension schema before importing the collected data.
Large GitHub organizations or enterprises can trigger GitHub’s API rate limits during collection. If you see failed or retried requests, tune the HTTP request parameters to ride out rate limits instead of failing the run.