Dd Audit Security Investigation

作者 datadog-labs5b40c73824ec无许可证177 个星标收录于 2026年10月8日更新于 2026年10月8日仓库今天更新

Answer "who did what" security questions from Audit Trail — deletions, config changes, login activity, permission changes, actions from a specific user or IP.

AI 生成的概览

使用 pup audit-logs 查询 Datadog Audit Trail 日志,回答安全调查问题。

功能
提供一组现成的 pup audit-logs 搜索查询和 jq 过滤示例,用于常见安全调查问题,例如谁删除了资源、谁修改了某个资源、某个用户或 IP 做了哪些操作、登录与登录失败活动、权限变更以及 API 密钥的创建或删除。还包含 Audit Trail 事件类别参考表,以及需要提示的异常信号清单,例如支持人员访问、批量删除、异常地理位置、非工作时间活动和首次出现的 ASN。产出的是调查指引和查询模式,而不是生成的文件。
适用场景
适用于调查 Datadog 组织内“谁做了什么”的场景,例如怀疑发生删除、配置变更、权限变更或异常登录之后。适合需要按用户、资源、IP 或时间窗口追踪操作的事件响应和审计复核。
运行要求
需要 pup CLI 并具备访问 Datadog Audit Trail 的认证(通过 OAuth2 执行 pup auth login,或使用具有 audit_logs_read 权限的 DD_API_KEY 与 DD_APP_KEY),以及用于示例中 JSON 过滤的 jq。需要访问 Datadog 的网络连接。该技能不附带脚本,仅为说明文档。

Audit Trail: Security Investigation

Answer common security investigation questions using pup audit-logs.

Prerequisites

bash
pup auth login   # OAuth2 (recommended)# or set DD_API_KEY + DD_APP_KEY with audit_logs_read scope

Command Execution Order

  1. Clarify the investigation scope: who, what resource type, what time window.
  2. Run the most specific query first; broaden only if results are empty.
  3. If results are large, pipe to jq to group or summarize.
  4. Highlight anomalies: bulk operations, unusual geo, off-hours activity, support user actions.

Common Investigation Queries

Who deleted resources in a time window?

bash
pup audit-logs search --query "@action:deleted" --from 24h -o json \  | jq '[.data[] | {      timestamp: .attributes.timestamp,      user: .attributes.attributes.usr.email,      actor_type: .attributes.attributes.evt.actor.type,      resource_type: .attributes.attributes.asset.type,      resource_id: .attributes.attributes.asset.id,      country: .attributes.attributes.network.client.geoip.country.name    }]'

Who modified a specific resource (by ID)?

bash
pup audit-logs search --query "@asset.id:RESOURCE_ID" --from 7d -o json \  | jq '[.data[] | {      timestamp: .attributes.timestamp,      user: .attributes.attributes.usr.email,      action: .attributes.attributes.action,      event: .attributes.attributes.evt.name    }]'

What did a specific user do?

bash
pup audit-logs search --query "@usr.email:[email protected]" --from 7d --limit 200 -o json \  | jq '[.data[] | {      timestamp: .attributes.timestamp,      action: .attributes.attributes.action,      event: .attributes.attributes.evt.name,      resource_type: .attributes.attributes.asset.type,      resource_id: .attributes.attributes.asset.id,      ip: .attributes.attributes.network.client.ip,      country: .attributes.attributes.network.client.geoip.country.name    }]'

Login activity — all logins with geo

bash
pup audit-logs search --query "@evt.name:Authentication @action:login" --from 7d --limit 200 -o json \  | jq '[.data[] | {      timestamp: .attributes.timestamp,      user: .attributes.attributes.usr.email,      status: .attributes.attributes.status,      ip: .attributes.attributes.network.client.ip,      city: .attributes.attributes.network.client.geoip.city.name,      country: .attributes.attributes.network.client.geoip.country.name,      asn: .attributes.attributes.network.client.geoip.as.name    }]'

Failed logins only

bash
pup audit-logs search --query "@evt.name:Authentication @action:login @status:error" --from 7d --limit 200 -o json \  | jq '[.data[] | {      timestamp: .attributes.timestamp,      user: .attributes.attributes.usr.email,      ip: .attributes.attributes.network.client.ip,      country: .attributes.attributes.network.client.geoip.country.name    }]'

Who changed roles or permissions?

bash
pup audit-logs search --query "@evt.name:\"Access Management\"" --from 30d --limit 200 -o json \  | jq '[.data[] | {      timestamp: .attributes.timestamp,      user: .attributes.attributes.usr.email,      action: .attributes.attributes.action,      resource_type: .attributes.attributes.asset.type,      resource_id: .attributes.attributes.asset.id    }]'

What actions came from a specific IP?

bash
pup audit-logs search --query "@network.client.ip:1.2.3.4" --from 30d --limit 200 -o json \  | jq '[.data[] | {      timestamp: .attributes.timestamp,      user: .attributes.attributes.usr.email,      actor_type: .attributes.attributes.evt.actor.type,      action: .attributes.attributes.action,      event: .attributes.attributes.evt.name,      resource_type: .attributes.attributes.asset.type    }]'

Who created or deleted API keys?

bash
pup audit-logs search --query "@evt.name:Authentication @asset.type:api_key" --from 90d --limit 200 -o json \  | jq '[.data[] | {      timestamp: .attributes.timestamp,      user: .attributes.attributes.usr.email,      action: .attributes.attributes.action,      key_id: .attributes.attributes.asset.id,      ip: .attributes.attributes.network.client.ip,      country: .attributes.attributes.network.client.geoip.country.name    }]'

Event Category Reference

Category (@evt.name)What it covers
AuthenticationLogins, API key create/delete/modify
Access ManagementRoles, user add/remove, restriction policies
DashboardCreate, modify, delete, share
MonitorCreate, modify, delete, resolve
Log ManagementPipelines, indexes, archives, exclusion filters
IntegrationAdd/modify/delete integrations
MetricsCustom metric create/modify/delete
Organization ManagementChild org creation, org settings
NotebookCreate, modify, delete
APMRetention filters, sampling config
Cloud Security PlatformCWS rules, security signal state changes
Bits AI SREMCP tool calls, AI investigations

Anomaly Flags to Surface

When presenting investigation results, call out:

  • Actor type SUPPORT_USER — Datadog support accessed the org
  • Bulk deletions — same user, same action, many resources in a short window
  • Unexpected geography — country not seen in prior logins for this user
  • Off-hours activity — actions at unusual times for the user's typical timezone
  • First-time ASN — action from a cloud provider or VPN not seen before (@network.client.geoip.as.name)

References

来源与署名

来源:datadog-labs/agent-skills位于dd-audit/security-investigation提交5b40c73

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架