Performing Cloud Log Forensics With Athena
Overview
Cybersecurity skill for performing cloud log forensics with athena. Follows industry best practices and security standards.
When to Use
Trigger phrases:
"performing cloud log forensics with athena"
"When investigating AWS security incidents that require querying massive volumes"
"When performing forensic analysis across CloudTrail, VPC Flow Logs, S3 access lo"
"When building reusable Athena tables with partition projection for ongoing incid"
When investigating AWS security incidents that require querying massive volumes of cloud logs
When performing forensic analysis across CloudTrail, VPC Flow Logs, S3 access logs, and ALB logs
When building reusable Athena tables with partition projection for ongoing incident response
When hunting for indicators of compromise across multiple AWS log sources simultaneously
When creating evidence-grade SQL queries for compliance audits or legal proceedings
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- AWS account with Athena, S3, and Glue permissions
- CloudTrail configured to deliver logs to an S3 bucket
- VPC Flow Logs enabled and publishing to S3
- S3 server access logging enabled on target buckets
- ALB access logging enabled and publishing to S3
- Python 3.8+ with boto3 installed
- Appropriate IAM permissions for Athena queries and S3 access
Workflow
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
- Plan Operations — Define objectives, scope, and success criteria for cloud log forensics operations.
- Prepare Environment — Set up tools, access, and data sources required for cloud log forensics.
- Execute Core Workflow — Use athena to perform cloud log forensics operations following established procedures.
- Validate Results — Verify that results meet quality standards and objectives.
- Report Findings — Document results, observations, and recommendations.
- Follow Up — Track remediation actions and verify fixes where applicable.
Tools
- athena — Primary tool for this skill
- Analysis Platform — Data processing and visualization
- Collaboration Tools — Team coordination and knowledge sharing
Process
- Reconnaissance — Gather target information, identify attack surface, enumerate services
- Analysis/Exploitation — Execute the technique, analyze results, document findings
- Reporting — Document IOCs, write findings, provide remediation recommendations
Verification
Anti-Rationalization Table
| Rationalization |
Reality |
| "We are too small to be targeted" |
Automated attacks target everyone. Size does not matter. |
| "Security slows us down" |
A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" |
Vulnerabilities in production are exploited within hours. Fix before deploy. |
1---2name: performing-cloud-log-forensics-with-athena3description: Use when uses AWS Athena to query CloudTrail, VPC Flow Logs, S3 access logs, and ALB logs for forensic investigation. Covers CREATE TABLE DDL with partition projection, forensic SQL queries for detecting unauthorized access, data exfiltration, lateral movement, and privilege escalation. Use when investigating AWS security incidents or building cloud-native forensic workflows at scale.4license: Apache-2.05---67# Performing Cloud Log Forensics With Athena89## Overview1011Cybersecurity skill for performing cloud log forensics with athena. Follows industry best practices and security standards.1213## When to Use1415**Trigger phrases:**16- "performing cloud log forensics with athena"17- "When investigating AWS security incidents that require querying massive volumes"18- "When performing forensic analysis across CloudTrail, VPC Flow Logs, S3 access lo"19- "When building reusable Athena tables with partition projection for ongoing incid"202122- When investigating AWS security incidents that require querying massive volumes of cloud logs23- When performing forensic analysis across CloudTrail, VPC Flow Logs, S3 access logs, and ALB logs24- When building reusable Athena tables with partition projection for ongoing incident response25- When hunting for indicators of compromise across multiple AWS log sources simultaneously26- When creating evidence-grade SQL queries for compliance audits or legal proceedings272829## When NOT to Use3031- When you lack proper authorization for testing32- For production systems without change management33- When the task requires legal or compliance expertise beyond technical scope343536## Prerequisites3738- AWS account with Athena, S3, and Glue permissions39- CloudTrail configured to deliver logs to an S3 bucket40- VPC Flow Logs enabled and publishing to S341- S3 server access logging enabled on target buckets42- ALB access logging enabled and publishing to S343- Python 3.8+ with boto3 installed44- Appropriate IAM permissions for Athena queries and S3 access4546## Workflow4748```python49# Example: IOC detection50import re5152IOC_PATTERNS = {53 "ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",54 "domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",55 "hash_md5": r"\b[a-f0-9]{32}\b",56 "hash_sha256": r"\b[a-f0-9]{64}\b",57}5859def extract_iocs(text: str) -> dict:60 return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}61```62631. **Plan Operations** — Define objectives, scope, and success criteria for cloud log forensics operations.642. **Prepare Environment** — Set up tools, access, and data sources required for cloud log forensics.653. **Execute Core Workflow** — Use athena to perform cloud log forensics operations following established procedures.664. **Validate Results** — Verify that results meet quality standards and objectives.675. **Report Findings** — Document results, observations, and recommendations.686. **Follow Up** — Track remediation actions and verify fixes where applicable.6970## Tools7172- **athena** — Primary tool for this skill73- **Analysis Platform** — Data processing and visualization74- **Collaboration Tools** — Team coordination and knowledge sharing757677## Process78791. **Reconnaissance** — Gather target information, identify attack surface, enumerate services801. **Analysis/Exploitation** — Execute the technique, analyze results, document findings811. **Reporting** — Document IOCs, write findings, provide remediation recommendations8283## Verification8485- [ ] All cloud log forensics procedures executed completely and documented86- [ ] Findings validated against multiple data sources87- [ ] False positives identified and filtered88- [ ] Results documented with evidence and timestamps89- [ ] Recommendations provided with risk-based prioritization9091## Anti-Rationalization Table9293| Rationalization | Reality |94|---|---|95| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |96| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |97| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |