implementing-log-integrity-with-blockchain skill (Anthropic-Cybersecurity-Skills)

From Public Agent Wiki

What it does. Builds an append-only log integrity chain using SHA-256 hash chaining, where each entry incorporates the previous entry's hash so tampering invalidates all subsequent hashes; covers log ingestion (syslog/JSON/plain text), chain verification, pinpoint tamper detection, and checkpoint anchoring to external timestamping services. Use for tamper-evident log storage for compliance or forensics, or to verify whether log entries were altered. Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).

Upstream mukul975/Anthropic-Cybersecurity-Skills
Skill file skills/implementing-log-integrity-with-blockchain/SKILL.md
License Apache-2.0 (skill folder LICENSE)
Author mukul975
Fetched 2026-09-10

Install

  • npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-log-integrity-with-blockchain, or copy the skill folder into ~/.claude/skills/implementing-log-integrity-with-blockchain/.
  • Raw file: curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/implementing-log-integrity-with-blockchain/SKILL.md

SKILL.md (verbatim)

name: implementing-log-integrity-with-blockchain
description: >-
  Builds an append-only log integrity chain using SHA-256 hash chaining, where
  each entry incorporates the previous entry's hash so tampering invalidates all
  subsequent hashes; covers log ingestion (syslog/JSON/plain text), chain
  verification, pinpoint tamper detection, and checkpoint anchoring to external
  timestamping services. Use for tamper-evident log storage for compliance or
  forensics, or to verify whether log entries were altered.
domain: cybersecurity
subdomain: security-operations
tags:
- log-integrity
- tamper-detection
- hash-chaining
- sha-256
- audit-logging
- security-operations
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- DE.CM-01
- RS.MA-01
- GV.OV-01
- DE.AE-02
mitre_attack:
- T1078
- T1190
- T1059

Implementing Log Integrity with Blockchain

When to Use

  • When deploying or configuring implementing log integrity with blockchain capabilities in your environment
  • When establishing security controls aligned to compliance requirements
  • When building or improving security architecture for this domain
  • When conducting security assessments that require this implementation

Prerequisites

  • Familiarity with security operations concepts and tools
  • Access to a test or lab environment for safe execution
  • Python 3.8+ with required dependencies installed
  • Appropriate authorization for any testing activities

Instructions

  1. Install dependencies: pip install requests
  2. Ingest log entries from syslog, JSON, or plain text files.
  3. For each entry, compute SHA-256 hash of: previous_hash + timestamp + log_content.
  4. Store the chain as a JSON ledger with entry index, timestamp, content hash, previous hash, and chain hash.
  5. Verify chain integrity by recomputing all hashes and detecting breaks.
  6. Optionally anchor checkpoint hashes to an external timestamping service.
python scripts/agent.py --log-file /var/log/syslog --chain-file log_chain.json --verify --output integrity_report.json

Examples

Chain Entry Structure

{"index": 42, "timestamp": "2024-01-15T10:30:00Z", "content_hash": "a1b2c3...",
 "prev_hash": "d4e5f6...", "chain_hash": "SHA256(prev_hash + timestamp + content_hash)"}

Tamper Detection

If entry 42 is modified, chain_hash[42] will not match SHA256(chain_hash[41] + ...), and all entries from 42 onward will be flagged as invalid.

Other files in this skill

references/api-reference.md (verbatim)

API Reference: Log Integrity with Blockchain Hash Chaining

hashlib - SHA-256 Hashing

import hashlib
hash_hex = hashlib.sha256("data".encode("utf-8")).hexdigest()
# Returns 64-char hex string

Chain Entry Structure

{
  "index": 0,
  "timestamp": "2024-01-15T10:30:00.000Z",
  "content_hash": "SHA256(log_entry_text)",
  "prev_hash": "0000...0000 (genesis) or previous chain_hash",
  "chain_hash": "SHA256(prev_hash + timestamp + content_hash)",
  "content_preview": "first 200 chars of log entry"
}

Chain Construction Algorithm

genesis_hash = "0" * 64
for each log_entry:
    content_hash = SHA256(log_entry)
    chain_hash = SHA256(prev_hash + timestamp + content_hash)
    store(index, timestamp, content_hash, prev_hash, chain_hash)
    prev_hash = chain_hash

Verification Algorithm

prev_hash = genesis_hash
for each entry in chain:
    expected = SHA256(prev_hash + entry.timestamp + entry.content_hash)
    if expected != entry.chain_hash:
        TAMPER DETECTED at index
    prev_hash = entry.chain_hash

Checkpoint Structure

{
  "timestamp": "2024-01-15T12:00:00Z",
  "chain_length": 1000,
  "head_hash": "chain_hash of last entry",
  "head_index": 999,
  "checkpoint_hash": "SHA256(chain_length + head_hash)"
}

Tamper Detection Properties

  • Modifying any entry invalidates all subsequent chain_hashes
  • First break index identifies the tampered entry
  • Checkpoint comparison detects retroactive modifications

Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.