Log Triage

Identity-log triage workflow — anomaly patterns per provider (AWS CloudTrail, Azure AD/Entra, Google Workspace, Okta), session and token misuse, MFA-bypass signals, conditional-access evasion, and cross-provider correlation. Produces a prioritized finding list routed to ir-runbook or detection-engineer.

roodlicht ad7307f 10.9 KB Updated

File contents

roodlicht/accans-sec-skills/tree/main/skills/log-triage commit ad7307fe21

Frequently asked questions

npx skillmds@latest add roodlicht/log-triage