Dd Audit Key Compromise

作者 datadog-labs5b40c73824ec无许可证177 个星标收录于 2026年10月8日更新于 2026年10月8日仓库今天更新

Investigate a potentially compromised Datadog API key — timeline of actions, geo/IP breakdown, endpoints called, anomaly flags, and remediation steps.

仅含说明Security
AI 生成的概览

通过审计日志调查可能泄露的 Datadog API 密钥:时间线、地理位置/IP 来源、调用端点、异常信号与处置建议。

功能
指导代理使用可疑 API 密钥 ID 查询 Datadog 审计日志,重建操作时间线、来源地理位置/IP 与 ASN,以及被调用的端点。提供异常判断信号,例如异常国家、云或 VPN 的 ASN、破坏性删除操作、短时间内的活动爆发和非工作时段访问。给出结构化的调查报告格式,并列出处置步骤,包括在 Datadog 界面或通过 API 吊销密钥。
适用场景
当怀疑某个 Datadog API 密钥被泄露、盗用或滥用,需要还原其具体行为时使用。也适用于事件后复盘密钥的活动、来源和破坏性操作,以便吊销密钥并恢复受影响资源。
运行要求
需要 Datadog 审计日志访问权限:通过 pup auth login 使用 OAuth2,或使用具备 audit_logs_read 权限范围的 DD_API_KEY 与 DD_APP_KEY;吊销密钥需要 manage_api_keys 权限范围。需要 pup CLI 和 jq,以及可疑密钥的密钥 ID。仅为说明文档,不附带脚本。

Audit Trail: API Key Compromise Investigation

Reconstruct what a Datadog API key did, where requests originated, and which resources were affected.

Prerequisites

bash
pup auth login   # OAuth2 (recommended)# or set DD_API_KEY + DD_APP_KEY with audit_logs_read scope

You need the key ID of the suspect key (not the key value). Find it in Datadog UI under Organization Settings > API Keys, or from context showing @metadata.api_key.id.

Investigation Workflow

Step 1 — Establish timeline

bash
pup audit-logs search --query "@metadata.api_key.id:KEY_ID" --from 90d --limit 200 -o json \  | jq '[.data[] | {      timestamp: .attributes.timestamp,      action: .attributes.attributes.action,      event: .attributes.attributes.evt.name,      resource_type: .attributes.attributes.asset.type,      resource_id: .attributes.attributes.asset.id,      endpoint: .attributes.attributes.http.url_details.path,      method: .attributes.attributes.http.method,      ip: .attributes.attributes.network.client.ip,      city: .attributes.attributes.network.client.geoip.city.name,      country: .attributes.attributes.network.client.geoip.country.name,      asn: .attributes.attributes.network.client.geoip.as.name    }]'

Step 2 — Geo/IP breakdown

bash
pup audit-logs search --query "@metadata.api_key.id:KEY_ID" --from 90d --limit 500 -o json \  | jq '[.data[] | {      country: .attributes.attributes.network.client.geoip.country.name,      asn: .attributes.attributes.network.client.geoip.as.name,      ip: .attributes.attributes.network.client.ip    }]    | group_by(.country)    | map({        country: .[0].country,        count: length,        asns: [.[].asn] | unique,        ips: [.[].ip] | unique      })    | sort_by(-.count)'

Step 3 — Endpoint breakdown

bash
pup audit-logs search --query "@metadata.api_key.id:KEY_ID" --from 90d --limit 500 -o json \  | jq '[.data[] | {      method: .attributes.attributes.http.method,      path: .attributes.attributes.http.url_details.path    }]    | group_by(.path)    | map({path: .[0].path, methods: [.[].method] | unique, count: length})    | sort_by(-.count)'

Step 4 — Destructive action check

bash
pup audit-logs search --query "@metadata.api_key.id:KEY_ID @action:deleted" --from 90d -o json \  | jq '[.data[] | {      timestamp: .attributes.timestamp,      resource_type: .attributes.attributes.asset.type,      resource_id: .attributes.attributes.asset.id,      ip: .attributes.attributes.network.client.ip,      country: .attributes.attributes.network.client.geoip.country.name    }]'

Step 5 — When was the key created and by whom?

bash
pup audit-logs search --query "@asset.type:api_key @asset.id:KEY_ID @action:created" --from 90d -o json \  | jq '[.data[] | {      created_at: .attributes.timestamp,      created_by: .attributes.attributes.usr.email,      creator_ip: .attributes.attributes.network.client.ip,      creator_country: .attributes.attributes.network.client.geoip.country.name    }]'

Anomaly Flags

SignalWhy it matters
Country not in org's normal baselinePossible exfiltration from unexpected region
ASN is a cloud/VPN provider (AWS, Cloudflare, NordVPN, etc.)Proxied traffic; obscured origin
DELETE actions on monitors, dashboards, or log pipelinesPotential sabotage
Burst of activity in short windowAutomated scraping or bulk exfiltration
Activity outside business hoursOff-hours access
Key used from multiple IPs simultaneouslyKey shared or stolen

Investigation Output Format

Key ID: <key_id>Created: <timestamp> by <user_email>Active period: <first_seen> to <last_seen>Total events: <N>
Origins:  - <Country> (<ASN>): <N> events — [NORMAL / FLAG: first-time origin]
Endpoints called (top 5):  - <METHOD> <path>: <N> calls
Destructive actions: <N> deletions — [resource types affected]
Recommended actions:  1. Revoke the key immediately if not already done  2. Review affected resources: [list]  3. Check if any deleted resources need restoration  4. Audit who else had access to this key

Remediation

Revoke in Datadog UI: Organization Settings > API Keys > Revoke.

Or via API (requires manage_api_keys scope):

bash
pup api-keys delete KEY_ID

References

来源与署名

来源:datadog-labs/agent-skills位于dd-audit/key-compromise提交5b40c73

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架