implementing-cloud-workload-protection skill (Anthropic-Cybersecurity-Skills)

From Public Agent Wiki

What it does. 'Implements cloud workload protection using boto3 and google-cloud APIs Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).

Upstream mukul975/Anthropic-Cybersecurity-Skills
Skill file skills/implementing-cloud-workload-protection/SKILL.md
License Apache-2.0 (skill folder LICENSE)
Author mukul975
Fetched 2026-09-10

Install

  • npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-cloud-workload-protection, or copy the skill folder into ~/.claude/skills/implementing-cloud-workload-protection/.
  • Raw file: curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/implementing-cloud-workload-protection/SKILL.md

SKILL.md (verbatim)

name: implementing-cloud-workload-protection
description: 'Implements cloud workload protection using boto3 and google-cloud APIs
  for runtime security monitoring, process anomaly detection, and file integrity checking
  on EC2/GCE instances. Scans for cryptomining, reverse shells, and unauthorized binaries.
  Use when building runtime security controls for cloud compute workloads.

  '
domain: cybersecurity
subdomain: cloud-security
tags:
- cloud-security
- cwpp
- workload-protection
- boto3
- runtime-security
- process-anomaly-detection
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- PR.IR-01
- ID.AM-08
- GV.SC-06
- DE.CM-01
mitre_attack:
- T1078.004
- T1530
- T1537
- T1580
- T1071

Implementing Cloud Workload Protection

When to Use

  • When deploying or configuring implementing cloud workload protection capabilities in your environment
  • When establishing security controls aligned to compliance requirements
  • When building or improving security architecture for this domain
  • When conducting security assessments that require this implementation

Prerequisites

  • Familiarity with cloud security concepts and tools
  • Access to a test or lab environment for safe execution
  • Python 3.8+ with required dependencies installed
  • Appropriate authorization for any testing activities

Instructions

Monitor cloud workloads for runtime threats by checking process lists, network connections, file integrity, and resource utilization anomalies.

import boto3

ssm = boto3.client("ssm")
# Run command on EC2 instances to check for suspicious processes
response = ssm.send_command(
    InstanceIds=["i-1234567890abcdef0"],
    DocumentName="AWS-RunShellScript",
    Parameters={"commands": ["ps aux | grep -E 'xmrig|minerd|cryptonight'"]},
)

Key protection areas:

  1. Process monitoring for cryptominers and reverse shells
  2. File integrity monitoring on critical system files
  3. Network connection auditing for C2 callbacks
  4. Resource utilization anomaly detection (CPU spikes)
  5. Unauthorized binary detection via hash comparison

Examples

# Check for unauthorized outbound connections
ssm.send_command(
    InstanceIds=instances,
    DocumentName="AWS-RunShellScript",
    Parameters={"commands": ["ss -tlnp | grep ESTABLISHED"]},
)

Other files in this skill

references/api-reference.md (verbatim)

API Reference: Implementing Cloud Workload Protection

AWS SSM Run Command (boto3)

import boto3
ssm = boto3.client("ssm")

# Execute command on instances
resp = ssm.send_command(
    InstanceIds=["i-abc123"],
    DocumentName="AWS-RunShellScript",
    Parameters={"commands": ["ps aux"]},
    TimeoutSeconds=60,
)
command_id = resp["Command"]["CommandId"]

# Get output
output = ssm.get_command_invocation(
    CommandId=command_id, InstanceId="i-abc123"
)
print(output["StandardOutputContent"])

CloudWatch CPU Monitoring

cw = boto3.client("cloudwatch")
resp = cw.get_metric_statistics(
    Namespace="AWS/EC2", MetricName="CPUUtilization",
    Dimensions=[{"Name": "InstanceId", "Value": "i-abc123"}],
    StartTime=start, EndTime=end, Period=300,
    Statistics=["Average"],
)

Key Detection Commands

Threat Command
Cryptominer ps aux | grep -iE 'xmrig|minerd'
Reverse shell ss -tlnp | grep ESTAB
File integrity rpm -Va | grep '^..5'
Unauthorized binaries find /tmp -executable -type f
Cron persistence crontab -l; ls /etc/cron.d/

GuardDuty Integration

gd = boto3.client("guardduty")
findings = gd.list_findings(DetectorId="detector-id")
for fid in findings["FindingIds"]:
    detail = gd.get_findings(DetectorId="detector-id", FindingIds=[fid])
    print(detail["Findings"][0]["Type"])

References

Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.