Cloud Incident Investigation

Investigate suspected compromise in AWS, Azure, or GCP: find the right logs (CloudTrail, AzureActivity, Entra audit, GCP Cloud Audit Logs), reconstruct what an identity or access key did, spot the high-signal control-plane events (access key creation, role assumption chains, StopLogging, PutBucketPolicy, role assignments, Key Vault reads, setIamPolicy, service account key creation), size the blast radius, and contain safely (rotate, deny, SCP, revoke) while preserving evidence. Use it whenever someone mentions a leaked or exposed access key, a GuardDuty / Defender for Cloud / Security Command Center finding, an unexpected cloud bill, a public bucket, an unknown IAM user or role, "someone logged into the console", "who created this resource", or pastes CloudTrail, Activity Log, or audit log JSON, even if they do not say "incident". Also use it for post-hoc "what did this credential touch" reviews.

ftrout Updated

File contents

ftrout/secops-claude-skills/tree/main/skills/cloud-incident-investigation commit 3d4beb4d8f

Frequently asked questions

npx skillmds@latest add ftrout/cloud-incident-investigation