> For the complete documentation index, see [llms.txt](https://docs.oort.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.oort.io/understanding-check-failures/oort-insights/identity-threat-detection-insights/code-exfiltration-by-guest-account.md).

# Code Exfiltration By Guest Account

Detects external accounts that have recently been created and have successfully downloaded a repository. Such activity could potentially indicate an attempt to exfiltrate data. If an external user's account was created within the past 7 days and they download a repository, they will fail this check.

**Recommended Actions**

Please contact the user that invited the external account, or their manager, to verify the origin of the actions.

**Default Check Settings**

Number Of Days Between Invite Sent And Download: 7

**Compatibility**

[GitHub](/integrations/github.md)
