Detects abnormal cloud storage access in AWS S3, GCS and Azure Blob logs using statistical baselines and anomaly detection.
- What it does
- Analyzes cloud storage access logs such as CloudTrail Data Events, GCS audit logs and Azure Storage Analytics to build access baselines covering hourly request volume, per-user object counts and source IP history. It flags after-hours access, bulk downloads, new source IPs and ListBucket enumeration spikes, then produces a prioritized findings report. A bundled Python script runs the analysis and writes JSON output.
- When to use it
- Use it when investigating suspected cloud data exfiltration or unusual storage access. It also fits building detection rules, threat hunting queries and validating security monitoring coverage for related attack techniques.
- Requirements
- Python 3.8+ with boto3 and requests installed, plus access to cloud storage access logs and appropriate authorization for testing. It ships an executable script (scripts/agent.py) and requires cloud log data and credentials for the relevant provider.