跳到主要内容
知仓学习社ZHICANG

performing-cloud-forensics-with-aws-cloudtrail

Investigate AWS account compromise by querying CloudTrail with boto3's LookupEvents

写文件无严重或高危命中mukul975/Anthropic-Cybersecurity-Skills

它会碰到什么

扫了多少4 个文本文件,26 KB
它会碰到什么写文件
命中总数1 处
命中统计严重 0 · 高 0 · 中 1 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Performing Cloud Forensics with AWS CloudTrail

When to Use

  • When investigating suspected AWS account compromise
  • After detecting unauthorized API calls or credential exposure
  • During incident response involving cloud infrastructure
  • When analyzing S3 data exfiltration or IAM privilege escalation
  • For post-incident forensic timeline reconstruction

Prerequisites

  • AWS account with CloudTrail enabled (management and data events)
  • IAM permissions for cloudtrail:LookupEvents, s3:GetObject, athena:StartQueryExecution
  • boto3 Python SDK installed
  • CloudTrail logs delivered to S3 with optional Athena table configured
  • AWS CLI configured with appropriate credentials

Workflow

  1. Scope Investigation: Identify timeframe, affected accounts, and compromised credentials.
  2. Query CloudTrail: Use boto3 lookup_events or Athena to retrieve relevant API events.
  3. Filter by Indicators: Search for suspicious user agents, source IPs, and event names.
  4. Reconstruct Timeline: Build chronological sequence of attacker actions from API calls.
  5. Analyze Access Patterns: Identify data access, IAM changes, and resource modifications.
  6. Identify Persistence: Check for new IAM users, access keys, roles, or Lambda functions.
  7. Generate Report: Produce forensic timeline with findings and remediation steps.

Key Concepts

| Concept | Description |

|---------|-------------|

| LookupEvents | CloudTrail API to query management events (last 90 days) |

| Athena Queries | SQL queries against CloudTrail logs in S3 for historical analysis |

| User Agent Analysis | Identify tool signatures (AWS CLI, SDK, console, custom) |

| AccessKeyId | Track activity by specific IAM access key |

| EventName | AWS API action name (e.g., GetObject, CreateUser, AssumeRole) |

| sourceIPAddress | Origin IP of API call for geolocation analysis |

Tools & Systems

| Tool | Purpose |

|------|---------|

| boto3 CloudTrail client | Programmatic CloudTrail event lookup |

| AWS Athena | SQL-based analysis of CloudTrail S3 logs |

| AWS CLI | Command-line CloudTrail queries |

| jq | JSON processing for CloudTrail event parsing |

| CloudTrail Lake | Advanced event data store with SQL query support |

Output Format

Forensic Report: AWS-IR-[DATE]-[SEQ]
Account: [AWS Account ID]
Timeframe: [Start] to [End]
Compromised Credentials: [Access Key IDs]
Suspicious Events: [Count]
Source IPs: [List of attacker IPs]
Actions Taken: [API calls by attacker]
Data Accessed: [S3 objects, secrets, etc.]
Persistence Mechanisms: [New users, keys, roles]

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。