Performing Cloud Forensics With AWS Cloudtrail

Investigate AWS account compromise by querying CloudTrail with boto3's LookupEvents or AWS Athena SQL over S3-delivered logs, filtering on suspicious user agents, source IPs, and event names to reconstruct an attacker timeline. Use when tracing unauthorized API calls, S3 data exfiltration, IAM privilege escalation, or credential exposure, and building a forensic report of findings and remediation steps.

gabrielmoreira Updated 17 repo stars

File contents

gabrielmoreira/agent-skills-mirror/tree/main/mirrors/repos/mukul975@Anthropic-Cybersecurity-Skills/skills/performing-cloud-forensics-with-aws-cloudtrail commit 0e656eff37

Frequently asked questions

npx skillmds@latest add gabrielmoreira/performing-cloud-forensics-with-aws-cloudtrail