Detecting Shadow IT Cloud Usage
Overview
Shadow IT refers to unauthorized SaaS applications and cloud services used without IT approval. This skill analyzes proxy logs, DNS query logs, and firewall/netflow data to identify unauthorized cloud service usage, classify discovered domains against known SaaS categories, measure data transfer volumes, and flag high-risk services based on security posture and compliance requirements.
When to Use
Trigger phrases:
"detecting shadow it cloud usage"
"Detect unauthorized SaaS and cloud service usage (shadow IT) by analyzing proxy "
When investigating security incidents that require detecting shadow it cloud usage
When building detection rules or threat hunting queries for this domain
When SOC analysts need structured procedures for this analysis type
When validating security monitoring coverage for related attack techniques
Prerequisites
- Python 3.9+ with
pandas, tldextract
- Proxy logs (Squid, Zscaler, or Palo Alto format) or DNS query logs
- SaaS application catalog/blocklist for classification
- Network firewall logs with FQDN resolution (optional)
Steps
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
- Parse proxy access logs and extract destination domains with traffic volumes
- Parse DNS query logs to identify resolved cloud service domains
- Aggregate traffic by domain using pandas — total bytes, request counts, unique users
- Classify domains against known SaaS categories (storage, email, dev tools, AI)
- Flag unauthorized services not on the approved application list
- Calculate risk scores based on data volume, user count, and service category
- Generate shadow IT discovery report with remediation recommendations
Expected Output
- JSON report listing discovered cloud services with traffic volumes, user counts, risk scores, and approval status
- Top unauthorized services ranked by data exfiltration risk
When NOT to Use
- You need to perform the attack to test detection (use performing-* skills)
- Task is about analyzing past incidents (use analyzing-* skills)
- You need to implement detection rules (use implementing-* skills)
- Task is about threat hunting proactively (use hunting-* skills)
- You don't have access to logs or monitoring data
- Task requires incident response (use IR skills)
Red Flags
- Performing actions without explicit written authorization from the asset owner
- Testing against production systems without a defined scope and rules of engagement
- Modifying cloud IAM policies or security groups without approval
- Exposing cloud credentials or secrets in logs or reports
- Running scans that generate excessive API calls and trigger billing alerts
Process
- Reconnaissance — Gather target information, identify attack surface, enumerate services
- Analysis/Exploitation — Execute the technique, analyze results, document findings
- Reporting — Document IOCs, write findings, provide remediation recommendations
Verification
- All steps executed successfully against a test environment before production use
- Output documented with screenshots or logs demonstrating expected behavior
- Cloud resource changes reverted or documented as intentional
- IAM policies reviewed for least-privilege compliance after testing
- No residual test resources left running (cost and security check)
Anti-Rationalization Table
| Rationalization |
Reality |
| "We are too small to be targeted" |
Automated attacks target everyone. Size does not matter. |
| "Security slows us down" |
A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" |
Vulnerabilities in production are exploited within hours. Fix before deploy. |
1---2name: detecting-shadow-it-cloud-usage3description: Use when detect unauthorized SaaS and cloud service usage (shadow IT) by analyzing proxy logs, DNS query logs, and netflow data using Python pandas for traffic pattern analysis and domain classification. Use when detecting unauthorized saas and cloud service usage (shadow it) by.4license: Apache-2.05---678# Detecting Shadow IT Cloud Usage910## Overview1112Shadow IT refers to unauthorized SaaS applications and cloud services used without IT approval. This skill analyzes proxy logs, DNS query logs, and firewall/netflow data to identify unauthorized cloud service usage, classify discovered domains against known SaaS categories, measure data transfer volumes, and flag high-risk services based on security posture and compliance requirements.131415## When to Use16**Trigger phrases:**17- "detecting shadow it cloud usage"18- "Detect unauthorized SaaS and cloud service usage (shadow IT) by analyzing proxy "192021- When investigating security incidents that require detecting shadow it cloud usage22- When building detection rules or threat hunting queries for this domain23- When SOC analysts need structured procedures for this analysis type24- When validating security monitoring coverage for related attack techniques2526## Prerequisites2728- Python 3.9+ with `pandas`, `tldextract`29- Proxy logs (Squid, Zscaler, or Palo Alto format) or DNS query logs30- SaaS application catalog/blocklist for classification31- Network firewall logs with FQDN resolution (optional)3233## Steps3435```python36# Example: IOC detection37import re3839IOC_PATTERNS = {40 "ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",41 "domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",42 "hash_md5": r"\b[a-f0-9]{32}\b",43 "hash_sha256": r"\b[a-f0-9]{64}\b",44}4546def extract_iocs(text: str) -> dict:47 return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}48```49501. Parse proxy access logs and extract destination domains with traffic volumes512. Parse DNS query logs to identify resolved cloud service domains523. Aggregate traffic by domain using pandas — total bytes, request counts, unique users534. Classify domains against known SaaS categories (storage, email, dev tools, AI)545. Flag unauthorized services not on the approved application list556. Calculate risk scores based on data volume, user count, and service category567. Generate shadow IT discovery report with remediation recommendations5758## Expected Output5960- JSON report listing discovered cloud services with traffic volumes, user counts, risk scores, and approval status61- Top unauthorized services ranked by data exfiltration risk62## When NOT to Use6364- You need to perform the attack to test detection (use performing-* skills)65- Task is about analyzing past incidents (use analyzing-* skills)66- You need to implement detection rules (use implementing-* skills)67- Task is about threat hunting proactively (use hunting-* skills)68- You don't have access to logs or monitoring data69- Task requires incident response (use IR skills)707172## Red Flags7374- Performing actions without explicit written authorization from the asset owner75- Testing against production systems without a defined scope and rules of engagement76- Modifying cloud IAM policies or security groups without approval77- Exposing cloud credentials or secrets in logs or reports78- Running scans that generate excessive API calls and trigger billing alerts7980## Process81821. **Reconnaissance** — Gather target information, identify attack surface, enumerate services831. **Analysis/Exploitation** — Execute the technique, analyze results, document findings841. **Reporting** — Document IOCs, write findings, provide remediation recommendations8586## Verification8788- All steps executed successfully against a test environment before production use89- Output documented with screenshots or logs demonstrating expected behavior90- Cloud resource changes reverted or documented as intentional91- IAM policies reviewed for least-privilege compliance after testing92- No residual test resources left running (cost and security check)9394## Anti-Rationalization Table9596| Rationalization | Reality |97|---|---|98| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |99| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |100| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |