Performing Cloud Native Threat Hunting With AWS Detective

Investigate AWS security incidents using Amazon Detective's behavior graphs, built from CloudTrail, VPC Flow Logs, GuardDuty, and EKS audit logs, to trace entity timelines and profile IAM users, roles, EC2 instances, and IP addresses for lateral movement. Use when triaging GuardDuty findings, investigating a suspected AWS compromise, or reconstructing an attacker's activity timeline across AWS accounts.

gabrielmoreira Updated 17 repo stars

File contents

gabrielmoreira/agent-skills-mirror/tree/main/mirrors/repos/mukul975@Anthropic-Cybersecurity-Skills/skills/performing-cloud-native-threat-hunting-with-aws-detective commit 8e4fd7c12a

Frequently asked questions

npx skillmds@latest add gabrielmoreira/performing-cloud-native-threat-hunting-with-aws-detective