Dd Audit Security Investigation

作者 datadog-labs5b40c73824ec無授權條款177 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫今天更新

Answer "who did what" security questions from Audit Trail — deletions, config changes, login activity, permission changes, actions from a specific user or IP.

AI 產生的概覽

使用 pup audit-logs 查詢 Datadog Audit Trail 記錄,回答安全調查問題。

功能
提供一組現成的 pup audit-logs 搜尋查詢與 jq 篩選範例,用於常見的安全調查問題,例如誰刪除了資源、誰修改了某個資源、某個使用者或 IP 做了哪些動作、登入與登入失敗活動、權限變更,以及 API 金鑰的建立或刪除。也包含 Audit Trail 事件類別對照表,以及需要提醒的異常訊號清單,例如支援人員存取、大量刪除、異常地理位置、非上班時間活動和首次出現的 ASN。產出的是調查指引與查詢模式,而不是產生的檔案。
適用情境
適用於調查 Datadog 組織內「誰做了什麼」的情境,例如懷疑發生刪除、設定變更、權限變更或異常登入之後。適合需要依使用者、資源、IP 或時間範圍追蹤動作的事件應變與稽核複核。
執行需求
需要 pup CLI 並具備存取 Datadog Audit Trail 的驗證(透過 OAuth2 執行 pup auth login,或使用具有 audit_logs_read 權限的 DD_API_KEY 與 DD_APP_KEY),以及用於範例中 JSON 篩選的 jq。需要連線至 Datadog 的網路存取。此技能未附帶指令碼,僅為說明文件。

Audit Trail: Security Investigation

Answer common security investigation questions using pup audit-logs.

Prerequisites

bash
pup auth login   # OAuth2 (recommended)# or set DD_API_KEY + DD_APP_KEY with audit_logs_read scope

Command Execution Order

  1. Clarify the investigation scope: who, what resource type, what time window.
  2. Run the most specific query first; broaden only if results are empty.
  3. If results are large, pipe to jq to group or summarize.
  4. Highlight anomalies: bulk operations, unusual geo, off-hours activity, support user actions.

Common Investigation Queries

Who deleted resources in a time window?

bash
pup audit-logs search --query "@action:deleted" --from 24h -o json \  | jq '[.data[] | {      timestamp: .attributes.timestamp,      user: .attributes.attributes.usr.email,      actor_type: .attributes.attributes.evt.actor.type,      resource_type: .attributes.attributes.asset.type,      resource_id: .attributes.attributes.asset.id,      country: .attributes.attributes.network.client.geoip.country.name    }]'

Who modified a specific resource (by ID)?

bash
pup audit-logs search --query "@asset.id:RESOURCE_ID" --from 7d -o json \  | jq '[.data[] | {      timestamp: .attributes.timestamp,      user: .attributes.attributes.usr.email,      action: .attributes.attributes.action,      event: .attributes.attributes.evt.name    }]'

What did a specific user do?

bash
pup audit-logs search --query "@usr.email:[email protected]" --from 7d --limit 200 -o json \  | jq '[.data[] | {      timestamp: .attributes.timestamp,      action: .attributes.attributes.action,      event: .attributes.attributes.evt.name,      resource_type: .attributes.attributes.asset.type,      resource_id: .attributes.attributes.asset.id,      ip: .attributes.attributes.network.client.ip,      country: .attributes.attributes.network.client.geoip.country.name    }]'

Login activity — all logins with geo

bash
pup audit-logs search --query "@evt.name:Authentication @action:login" --from 7d --limit 200 -o json \  | jq '[.data[] | {      timestamp: .attributes.timestamp,      user: .attributes.attributes.usr.email,      status: .attributes.attributes.status,      ip: .attributes.attributes.network.client.ip,      city: .attributes.attributes.network.client.geoip.city.name,      country: .attributes.attributes.network.client.geoip.country.name,      asn: .attributes.attributes.network.client.geoip.as.name    }]'

Failed logins only

bash
pup audit-logs search --query "@evt.name:Authentication @action:login @status:error" --from 7d --limit 200 -o json \  | jq '[.data[] | {      timestamp: .attributes.timestamp,      user: .attributes.attributes.usr.email,      ip: .attributes.attributes.network.client.ip,      country: .attributes.attributes.network.client.geoip.country.name    }]'

Who changed roles or permissions?

bash
pup audit-logs search --query "@evt.name:\"Access Management\"" --from 30d --limit 200 -o json \  | jq '[.data[] | {      timestamp: .attributes.timestamp,      user: .attributes.attributes.usr.email,      action: .attributes.attributes.action,      resource_type: .attributes.attributes.asset.type,      resource_id: .attributes.attributes.asset.id    }]'

What actions came from a specific IP?

bash
pup audit-logs search --query "@network.client.ip:1.2.3.4" --from 30d --limit 200 -o json \  | jq '[.data[] | {      timestamp: .attributes.timestamp,      user: .attributes.attributes.usr.email,      actor_type: .attributes.attributes.evt.actor.type,      action: .attributes.attributes.action,      event: .attributes.attributes.evt.name,      resource_type: .attributes.attributes.asset.type    }]'

Who created or deleted API keys?

bash
pup audit-logs search --query "@evt.name:Authentication @asset.type:api_key" --from 90d --limit 200 -o json \  | jq '[.data[] | {      timestamp: .attributes.timestamp,      user: .attributes.attributes.usr.email,      action: .attributes.attributes.action,      key_id: .attributes.attributes.asset.id,      ip: .attributes.attributes.network.client.ip,      country: .attributes.attributes.network.client.geoip.country.name    }]'

Event Category Reference

Category (@evt.name)What it covers
AuthenticationLogins, API key create/delete/modify
Access ManagementRoles, user add/remove, restriction policies
DashboardCreate, modify, delete, share
MonitorCreate, modify, delete, resolve
Log ManagementPipelines, indexes, archives, exclusion filters
IntegrationAdd/modify/delete integrations
MetricsCustom metric create/modify/delete
Organization ManagementChild org creation, org settings
NotebookCreate, modify, delete
APMRetention filters, sampling config
Cloud Security PlatformCWS rules, security signal state changes
Bits AI SREMCP tool calls, AI investigations

Anomaly Flags to Surface

When presenting investigation results, call out:

  • Actor type SUPPORT_USER — Datadog support accessed the org
  • Bulk deletions — same user, same action, many resources in a short window
  • Unexpected geography — country not seen in prior logins for this user
  • Off-hours activity — actions at unusual times for the user's typical timezone
  • First-time ASN — action from a cloud provider or VPN not seen before (@network.client.geoip.as.name)

References

來源與署名

來源:datadog-labs/agent-skills位於dd-audit/security-investigation提交5b40c73

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架