BigHugger
sk Skill · mukul975

performing-cloud-native-threat-hunting-with-aws-detective

Investigate AWS security incidents using Amazon Detective's behavior graphs, built from CloudTrail, VPC Flow Logs, GuardDuty, and EKS audit logs, to trace entity timelines and profile IAM users, roles, EC2 instances, and IP addresses for lateral movement. Use when triaging GuardDuty findings, investigating a suspected AWS compromise, or reconstructing an attacker's activity timeline across AWS accounts.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
bashPythonec2jsonincident-investigationiamguarddutybehavior-graphcloud-securitypythonawsthreat-huntingaws-detective
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python