performing-cloud-forensics-investigation

mukul975/performing-cloud-forensics-investigation · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Collect and analyze logs, snapshots, and metadata from AWS, Azure, and GCP to investigate security breaches in cloud environments.

SKILL.md

Files

This skill is a package of 4 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 2.4 KB
  • 📁scripts
  • ⚙️agent.py 8.4 KB
  • 📄LICENSE 11.0 KB

Related

  1. conducting-cloud-incident-response · mukul975 bundle
    Responds to security incidents in cloud environments (AWS, Azure, GCP) by performing identity-based containment, cloud-native log analysis, resource isolation, and forensic evidence acquisition adapted for ephemeral cloud infrastructure.
    24.6k
    repo stars
  2. performing-cloud-incident-containment-procedures · mukul975 bundle
    Execute cloud-native incident containment across AWS, Azure, and GCP by isolating compromised resources, revoking credentials, preserving forensic evidence, and applying security group restrictions to prevent lateral movement.
    24.6k
    repo stars
  3. deploying-cloud-deception-with-decoy-resources · mukul975 bundle
    Deploy cloud-native deception across AWS, Azure, and GCP using decoy resources that generate high-fidelity alerts when attackers interact with them.
    24.6k
    repo stars
  4. performing-cloud-forensics-with-aws-cloudtrail · mukul975 bundle
    Investigate AWS account compromises by querying CloudTrail logs to reconstruct attacker activity, identify compromised credentials, and analyze API call patterns.
    24.6k
    repo stars
  5. detecting-compromised-cloud-credentials · mukul975 bundle
    Detect compromised cloud credentials across AWS, Azure, and GCP by analyzing anomalous API activity, impossible travel patterns, unauthorized resource provisioning, and credential abuse indicators using GuardDuty, Defender for Identity, and SCC Event Threat Detection.
    24.6k
    repo stars
  6. cloud-security · alirezarezvani bundle
    Assess cloud infrastructure for security misconfigurations, IAM privilege escalation paths, S3 public exposure, open security group rules, and IaC security gaps across AWS, Azure, and GCP with MITRE ATT&CK mapping.
    20.4k
    repo stars

Frequently asked questions

How do I install the performing-cloud-forensics-investigation skill?

Run npx skillmds add mukul975/performing-cloud-forensics-investigation in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the performing-cloud-forensics-investigation skill do?

Collect and analyze logs, snapshots, and metadata from AWS, Azure, and GCP to investigate security breaches in cloud environments. It is listed under Security, DevOps & Infra, Cloud Platforms, Incident Response on SkillMD.

Is performing-cloud-forensics-investigation safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: WARNING, Skill Scanner: PASS. Capability flags: executes scripts. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with performing-cloud-forensics-investigation?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is performing-cloud-forensics-investigation free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published performing-cloud-forensics-investigation?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.