Analyzing Cloud Storage Access Patterns

mukul975/Anthropic-Cybersecurity-Skills/skills/analyzing-cloud-storage-access-patterns

作者 mukul97554a798831d2266a3ca61ce68a7acb80b81160d57Apache-2.0收錄於 2026年10月9日更新於 2026年10月9日

Detect abnormal access in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics for after-hours bulk downloads, new-IP access, and API-call spikes (e.g. GetObject) via statistical baselines and time-series anomaly detection. Use when investigating suspected cloud data exfiltration or building related detection rules.

AI 產生的概覽

透過統計基準與異常偵測,辨識 AWS S3、GCS 和 Azure Blob 儲存體中的異常存取行為。

功能
分析 CloudTrail Data Events、GCS 稽核記錄和 Azure Storage Analytics 等雲端儲存體存取記錄,建立包含每小時請求量、每位使用者物件數量和來源 IP 歷史的存取基準。它會標記非上班時間存取、大量下載、新來源 IP 以及 ListBucket 列舉激增,並產生依優先順序排列的發現報告。隨附的 Python 指令碼會執行分析並輸出 JSON 結果。
適用情境
適用於調查疑似雲端資料外洩或異常儲存體存取的情況。也適合建立偵測規則、威脅狩獵查詢,以及驗證相關攻擊技術的安全監控涵蓋範圍。
執行需求
需要 Python 3.8+ 並安裝 boto3 和 requests,同時需要存取雲端儲存體存取記錄以及相應的測試授權。此技能隨附可執行指令碼(scripts/agent.py),並需要相關雲端服務商的記錄資料和認證資訊。

Analyzing Cloud Storage Access Patterns

When to Use

  • When investigating security incidents that require analyzing cloud storage access patterns
  • When building detection rules or threat hunting queries for this domain
  • When SOC analysts need structured procedures for this analysis type
  • When validating security monitoring coverage for related attack techniques

Prerequisites

  • Familiarity with cloud security concepts and tools
  • Access to a test or lab environment for safe execution
  • Python 3.8+ with required dependencies installed
  • Appropriate authorization for any testing activities

Instructions

  1. Install dependencies: pip install boto3 requests
  2. Query CloudTrail for S3 Data Events using AWS CLI or boto3.
  3. Build access baselines: hourly request volume, per-user object counts, source IP history.
  4. Detect anomalies:
    • After-hours access (outside 8am-6pm local time)
    • Bulk downloads: >100 GetObject calls from single principal in 1 hour
    • New source IPs not seen in the prior 30 days
    • ListBucket enumeration spikes (reconnaissance indicator)
  5. Generate prioritized findings report.
bash
python scripts/agent.py --bucket my-sensitive-data --hours-back 24 --output s3_access_report.json

Examples

CloudTrail S3 Data Event

json
{"eventName": "GetObject", "requestParameters": {"bucketName": "sensitive-data", "key": "financials/q4.xlsx"}, "sourceIPAddress": "203.0.113.50", "userIdentity": {"arn": "arn:aws:iam::123456789012:user/analyst"}}

來源與署名

來源:mukul975/Anthropic-Cybersecurity-Skills位於skills/analyzing-cloud-storage-access-patterns提交54a7988

授權條款: Apache-2.0

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架