BigHugger
sk Skill · mukul975

performing-cloud-forensics-with-aws-cloudtrail

Investigate AWS account compromise by querying CloudTrail with boto3's LookupEvents or AWS Athena SQL over S3-delivered logs, filtering on suspicious user agents, source IPs, and event names to reconstruct an attacker timeline. Use when tracing unauthorized API calls, S3 data exfiltration, IAM privilege escalation, or credential exposure, and building a forensic report of findings and remediation steps.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
s3boto3Pythondfirforensicsincident-responsecloudtrailawscloud-security
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python