analyzing-cloud-storage-access-patterns
Detect abnormal access in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics for after-hours bulk downloads, new-IP access, and API-call spikes (e.g. GetObject) via statistical baselines and time-series anomaly detection. Use when investigating suspected cloud data exfiltration or building related detection rules.
Source facts
- Repository
- mukul975/Anthropic-Cybersecurity-Skills
- Last source activity
- August 2, 2026 at 16:32
- Detected SKILL.md language
- English
- Stars
- 33,552
- Forks
- 4,068
Install options
The review-first prompt is selected by default. You can switch to a direct command or download a local copy.
Review the source files
Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.
Showing SKILL.md
- name
- analyzing-cloud-storage-access-patterns
- description
- Detect abnormal access in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics for after-hours bulk downloads, new-IP access, and API-call spikes (e.g. GetObject) via statistical baselines and time-series anomaly detection. Use when investigating suspected cloud data exfiltration or building related detection rules.
- domain
- cybersecurity
- subdomain
- cloud-security
- tags
- ["cloud-security","aws-s3","gcs","azure-blob-storage","cloudtrail","data-access-anomaly","exfiltration-detection"]
- version
- 1.0
- author
- mahipal
- license
- Apache-2.0
- atlas_techniques
- ["AML.T0024","AML.T0056"]
- nist_ai_rmf
- ["MEASURE-2.7","MAP-5.1","MANAGE-2.4"]
- nist_csf
- ["PR.IR-01","ID.AM-08","GV.SC-06","DE.CM-01"]
- mitre_attack
- ["T1530","T1567.002","T1619","T1078.004","T1048"]