performing-cloud-native-threat-hunting-with-aws-detective

mukul975/performing-cloud-native-threat-hunting-with-aws-detective · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Hunt for threats in AWS environments using Detective behavior graphs, entity investigation timelines, GuardDuty finding correlation, and automated entity profiling across IAM users, EC2 instances, and IP addresses.

SKILL.md

Files

This skill is a package of 6 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁assets
  • 📄template.md 1.1 KB
  • 📁references
  • 📄api-reference.md 8.5 KB
  • 📄standards.md 1.1 KB
  • 📄workflows.md 1.1 KB
  • 📁scripts
  • ⚙️process.py 6.9 KB

Related

  1. detecting-aws-cloudtrail-anomalies · mukul975 bundle
    Query AWS CloudTrail events with boto3, build statistical baselines of normal API activity, and detect anomalies such as unusual event sources, geographic anomalies, high-frequency API calls, and first-time API usage patterns.
    24.6k
    repo stars
  2. detecting-s3-data-exfiltration-attempts · mukul975 bundle
    Analyze CloudTrail, GuardDuty, Macie, and VPC Flow Logs to detect unauthorized bulk downloads and cross-account data transfers from AWS S3.
    24.6k
    repo stars
  3. implementing-security-chaos-engineering · mukul975 bundle
    Deliberately disables or degrades security controls to verify detection and response capabilities, including WAF bypass, firewall rule removal, log pipeline disruption, and EDR disablement scenarios using boto3 and subprocess.
    24.6k
    repo stars
  4. performing-cloud-forensics-with-aws-cloudtrail · mukul975 bundle
    Investigate AWS account compromises by querying CloudTrail logs to reconstruct attacker activity, identify compromised credentials, and analyze API call patterns.
    24.6k
    repo stars
  5. detecting-cryptomining-in-cloud · mukul975 bundle
    Detect and respond to unauthorized cryptocurrency mining in AWS and Azure environments using cost anomalies, compute utilization, network traffic analysis, and runtime monitoring.
    24.6k
    repo stars
  6. performing-cloud-log-forensics-with-athena · mukul975 bundle
    Query AWS CloudTrail, VPC Flow Logs, S3 access logs, and ALB logs with Athena for forensic investigation of security incidents.
    24.6k
    repo stars

Frequently asked questions

How do I install the performing-cloud-native-threat-hunting-with-aws-detective skill?

Run npx skillmds add mukul975/performing-cloud-native-threat-hunting-with-aws-detective in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the performing-cloud-native-threat-hunting-with-aws-detective skill do?

Hunt for threats in AWS environments using Detective behavior graphs, entity investigation timelines, GuardDuty finding correlation, and automated entity profiling across IAM users, EC2 instances, and IP addresses. It is listed under Security, DevOps & Infra, Incident Response, Vulnerability Scanning on SkillMD.

Is performing-cloud-native-threat-hunting-with-aws-detective safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with performing-cloud-native-threat-hunting-with-aws-detective?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is performing-cloud-native-threat-hunting-with-aws-detective free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published performing-cloud-native-threat-hunting-with-aws-detective?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.