| name | detecting-compromised-cloud-credentials |
| description | Detecting compromised cloud credentials across AWS, Azure, and GCP by analyzing anomalous API activity, impossible travel patterns, unauthorized resource provisioning, and credential abuse indicators using GuardDuty, Defender for Identity, and SCC Event Threat Detection. . Use when working with detecting compromised cloud credentials. |
| domain | cybersecurity |
| tags | ["cloud-security","credential-compromise","threat-detection","guardduty","incident-response","anomaly-detection"] |
| subdomain | cloud-security |
| version | 1.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["PR.IR-01","ID.AM-08","GV.SC-06","DE.CM-01"] |
Detecting Compromised Cloud Credentials
Overview
Cybersecurity skill for detecting compromised cloud credentials. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"detecting compromised cloud credentials"
-
"Detecting compromised cloud credentials across AWS, Azure, and GCP by analyzing "
-
When investigating alerts about unusual cloud API activity from unfamiliar locations
-
When building detection rules for credential theft and abuse across cloud environments
-
When responding to notifications from cloud providers about exposed credentials
-
When monitoring for credential stuffing or brute force attacks against cloud identities
-
When assessing the scope of a credential compromise after initial detection
Do not use for preventing credential compromise (use MFA, credential rotation, and secrets management), for detecting application-level credential theft (use application security monitoring), or for endpoint credential harvesting detection (use EDR tools).
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- AWS GuardDuty enabled across all accounts and regions
- Azure Defender for Identity and Entra ID Protection configured
- GCP Security Command Center with Event Threat Detection enabled
- CloudTrail, Azure Activity Log, and GCP Audit Log centralized for analysis
- SIEM integration for cross-cloud correlation of credential abuse indicators
- Threat intelligence feeds for known malicious IP ranges
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs() -> :
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}