Does anyone know what to look for in the github audit logs, exactly?
If you email GitHub support they can pull out detailed logs from oauth app interactions from their internal tools.
I would expect the GH security team to have relevant queries ready by now, maybe even do some proactive queries and start alerting anyone who had suspicious activity. (But this is just how I'd do it I have no special insight if they are doing this or something else).
https://github.com/organizations/<ORG_NAME>/settings/audit-l...
... but the real question is what would malicious activity look like, exactly?
I've reached out to Heroku support to ask.