Dd Audit Key Compromise

作者 datadog-labs5b40c73824ec無授權條款177 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫今天更新

Investigate a potentially compromised Datadog API key — timeline of actions, geo/IP breakdown, endpoints called, anomaly flags, and remediation steps.

僅含說明Security
AI 產生的概覽

透過稽核記錄調查可能外洩的 Datadog API 金鑰:時間軸、地理位置/IP 來源、呼叫端點、異常訊號與處置建議。

功能
引導代理使用可疑 API 金鑰 ID 查詢 Datadog 稽核記錄,重建操作時間軸、來源地理位置/IP 與 ASN,以及被呼叫的端點。提供異常判斷訊號,例如異常國家、雲端或 VPN 的 ASN、破壞性刪除操作、短時間內的大量活動,以及非上班時段的存取。提供結構化的調查報告格式,並列出處置步驟,包括在 Datadog 介面或透過 API 撤銷金鑰。
適用情境
當懷疑某個 Datadog API 金鑰遭外洩、盜用或濫用,需要還原其實際行為時使用。也適合在事件後檢視金鑰的活動、來源與破壞性操作,以便撤銷金鑰並還原受影響的資源。
執行需求
需要 Datadog 稽核記錄存取權:透過 pup auth login 使用 OAuth2,或使用具備 audit_logs_read 權限範圍的 DD_API_KEY 與 DD_APP_KEY;撤銷金鑰需要 manage_api_keys 權限範圍。需要 pup CLI 與 jq,以及可疑金鑰的金鑰 ID。僅為說明文件,未附帶指令碼。

Audit Trail: API Key Compromise Investigation

Reconstruct what a Datadog API key did, where requests originated, and which resources were affected.

Prerequisites

bash
pup auth login   # OAuth2 (recommended)# or set DD_API_KEY + DD_APP_KEY with audit_logs_read scope

You need the key ID of the suspect key (not the key value). Find it in Datadog UI under Organization Settings > API Keys, or from context showing @metadata.api_key.id.

Investigation Workflow

Step 1 — Establish timeline

bash
pup audit-logs search --query "@metadata.api_key.id:KEY_ID" --from 90d --limit 200 -o json \  | jq '[.data[] | {      timestamp: .attributes.timestamp,      action: .attributes.attributes.action,      event: .attributes.attributes.evt.name,      resource_type: .attributes.attributes.asset.type,      resource_id: .attributes.attributes.asset.id,      endpoint: .attributes.attributes.http.url_details.path,      method: .attributes.attributes.http.method,      ip: .attributes.attributes.network.client.ip,      city: .attributes.attributes.network.client.geoip.city.name,      country: .attributes.attributes.network.client.geoip.country.name,      asn: .attributes.attributes.network.client.geoip.as.name    }]'

Step 2 — Geo/IP breakdown

bash
pup audit-logs search --query "@metadata.api_key.id:KEY_ID" --from 90d --limit 500 -o json \  | jq '[.data[] | {      country: .attributes.attributes.network.client.geoip.country.name,      asn: .attributes.attributes.network.client.geoip.as.name,      ip: .attributes.attributes.network.client.ip    }]    | group_by(.country)    | map({        country: .[0].country,        count: length,        asns: [.[].asn] | unique,        ips: [.[].ip] | unique      })    | sort_by(-.count)'

Step 3 — Endpoint breakdown

bash
pup audit-logs search --query "@metadata.api_key.id:KEY_ID" --from 90d --limit 500 -o json \  | jq '[.data[] | {      method: .attributes.attributes.http.method,      path: .attributes.attributes.http.url_details.path    }]    | group_by(.path)    | map({path: .[0].path, methods: [.[].method] | unique, count: length})    | sort_by(-.count)'

Step 4 — Destructive action check

bash
pup audit-logs search --query "@metadata.api_key.id:KEY_ID @action:deleted" --from 90d -o json \  | jq '[.data[] | {      timestamp: .attributes.timestamp,      resource_type: .attributes.attributes.asset.type,      resource_id: .attributes.attributes.asset.id,      ip: .attributes.attributes.network.client.ip,      country: .attributes.attributes.network.client.geoip.country.name    }]'

Step 5 — When was the key created and by whom?

bash
pup audit-logs search --query "@asset.type:api_key @asset.id:KEY_ID @action:created" --from 90d -o json \  | jq '[.data[] | {      created_at: .attributes.timestamp,      created_by: .attributes.attributes.usr.email,      creator_ip: .attributes.attributes.network.client.ip,      creator_country: .attributes.attributes.network.client.geoip.country.name    }]'

Anomaly Flags

SignalWhy it matters
Country not in org's normal baselinePossible exfiltration from unexpected region
ASN is a cloud/VPN provider (AWS, Cloudflare, NordVPN, etc.)Proxied traffic; obscured origin
DELETE actions on monitors, dashboards, or log pipelinesPotential sabotage
Burst of activity in short windowAutomated scraping or bulk exfiltration
Activity outside business hoursOff-hours access
Key used from multiple IPs simultaneouslyKey shared or stolen

Investigation Output Format

Key ID: <key_id>Created: <timestamp> by <user_email>Active period: <first_seen> to <last_seen>Total events: <N>
Origins:  - <Country> (<ASN>): <N> events — [NORMAL / FLAG: first-time origin]
Endpoints called (top 5):  - <METHOD> <path>: <N> calls
Destructive actions: <N> deletions — [resource types affected]
Recommended actions:  1. Revoke the key immediately if not already done  2. Review affected resources: [list]  3. Check if any deleted resources need restoration  4. Audit who else had access to this key

Remediation

Revoke in Datadog UI: Organization Settings > API Keys > Revoke.

Or via API (requires manage_api_keys scope):

bash
pup api-keys delete KEY_ID

References

來源與署名

來源:datadog-labs/agent-skills位於dd-audit/key-compromise提交5b40c73

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架