analyzing-cloud-storage-access-patterns
Detect abnormal access in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics for after-hours bulk downloads, new-IP access, and API-call spikes (e.g. GetObject) via statistical baselines and time-series anomaly detection. Use when investigating suspected cloud data exfiltration or building related detection rules.
来源信息
- 仓库
- mukul975/Anthropic-Cybersecurity-Skills
- 最近来源活动
- 2026年8月2日 16:32
- 检测到的 SKILL.md 语言
- 英语
- 星标
- 33,552
- 分支
- 4,068
安装方式
默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。
检查来源文件
决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。
正在显示 SKILL.md
- name
- analyzing-cloud-storage-access-patterns
- description
- Detect abnormal access in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics for after-hours bulk downloads, new-IP access, and API-call spikes (e.g. GetObject) via statistical baselines and time-series anomaly detection. Use when investigating suspected cloud data exfiltration or building related detection rules.
- domain
- cybersecurity
- subdomain
- cloud-security
- tags
- ["cloud-security","aws-s3","gcs","azure-blob-storage","cloudtrail","data-access-anomaly","exfiltration-detection"]
- version
- 1.0
- author
- mahipal
- license
- Apache-2.0
- atlas_techniques
- ["AML.T0024","AML.T0056"]
- nist_ai_rmf
- ["MEASURE-2.7","MAP-5.1","MANAGE-2.4"]
- nist_csf
- ["PR.IR-01","ID.AM-08","GV.SC-06","DE.CM-01"]
- mitre_attack
- ["T1530","T1567.002","T1619","T1078.004","T1048"]