What it does. Deploy privileged access management for database systems including Oracle, Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).
Install
npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-pam-for-database-access, or copy the skill folder into ~/.claude/skills/implementing-pam-for-database-access/.
- Raw file:
curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/implementing-pam-for-database-access/SKILL.md
SKILL.md (verbatim)
name: implementing-pam-for-database-access
description: Deploy privileged access management for database systems including Oracle,
SQL Server, PostgreSQL, and MySQL, covering session proxy configuration, credential
vaulting, query auditing, dynamic credential generation, and least-privilege database
roles. Use when securing DBA access, implementing database PAM controls, or auditing
privileged database sessions.
domain: cybersecurity
subdomain: identity-access-management
tags:
- iam
- identity
- access-control
- privileged-access
- pam
- database
- dba
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- PR.AA-01
- PR.AA-02
- PR.AA-05
- PR.AA-06
mitre_attack:
- T1078
- T1110
- T1556
- T1098
- T1003
mitre_f3:
version: '1.1'
tactics:
- initial-access
- positioning
- resource-development
techniques:
- id: T1586
name: Compromise Accounts
tactic: resource-development
source: attack
- id: T1110
name: Brute Force
tactic: initial-access
source: attack
- id: F1033
name: Insider Access Abuse
tactic: initial-access
source: f3
- id: F1005.004
name: 'Account Manipulation: Change Account Details'
tactic: positioning
source: f3
- id: F1006.002
name: 'Account Takeover: Exposed Login Credential'
tactic: initial-access
source: f3
Implementing PAM for Database Access
Overview
Deploy privileged access management for database systems including Oracle, SQL Server, PostgreSQL, and MySQL. Covers session proxy configuration, credential vaulting, query auditing, dynamic credential generation, and least-privilege database roles.
When to Use
- When deploying or configuring implementing pam for database access capabilities in your environment
- When establishing security controls aligned to compliance requirements
- When building or improving security architecture for this domain
- When conducting security assessments that require this implementation
Prerequisites
- Familiarity with identity access management concepts and tools
- Access to a test or lab environment for safe execution
- Python 3.8+ with required dependencies installed
- Appropriate authorization for any testing activities
Objectives
- Implement comprehensive implementing pam for database access capability
- Establish automated discovery and monitoring processes
- Integrate with enterprise IAM and security tools
- Generate compliance-ready documentation and reports
- Align with NIST 800-53 access control requirements
Security Controls
| Control |
NIST 800-53 |
Description |
| Account Management |
AC-2 |
Lifecycle management |
| Access Enforcement |
AC-3 |
Policy-based access control |
| Least Privilege |
AC-6 |
Minimum necessary permissions |
| Audit Logging |
AU-3 |
Authentication and access events |
| Identification |
IA-2 |
User and service identification |
Verification
Other files in this skill
references/api-reference.md (verbatim)
API Reference: Implementing PAM for Database Access
HashiCorp Vault Database Secrets Engine
# Enable database secrets engine
vault secrets enable database
# Configure PostgreSQL connection
vault write database/config/postgresql \
plugin_name=postgresql-database-plugin \
connection_url="postgresql://{{username}}:{{password}}@db.example.com:5432/mydb" \
allowed_roles="readonly,readwrite" \
username="vault_admin" password="admin_pass"
# Create dynamic credential role
vault write database/roles/readonly \
db_name=postgresql \
creation_statements="CREATE ROLE \"{{name}}\" WITH LOGIN PASSWORD '{{password}}' VALID UNTIL '{{expiration}}'; GRANT SELECT ON ALL TABLES IN SCHEMA public TO \"{{name}}\";" \
default_ttl="1h" max_ttl="24h"
# Generate dynamic credentials
vault read database/creds/readonly
hvac Python Client
import hvac
client = hvac.Client(url='http://127.0.0.1:8200', token='s.xxx')
creds = client.secrets.database.generate_credentials('readonly')
# creds['data']['username'], creds['data']['password']
CyberArk Privileged Cloud API
| Endpoint |
Method |
Description |
/api/Accounts?search=database |
GET |
List database accounts |
/api/Accounts/{id}/Password/Retrieve |
POST |
Check out password |
/api/Accounts/{id}/CheckIn |
POST |
Check in password |
/api/LiveSessions |
GET |
List active PSM sessions |
/api/Recordings |
GET |
List session recordings |
Privileged Database Roles
| Database |
Privileged Roles |
Risk |
| PostgreSQL |
pg_read_all_data, rds_superuser |
Critical |
| MySQL |
SUPER, ALL PRIVILEGES, GRANT OPTION |
Critical |
| Oracle |
DBA, SYSDBA, SYSOPER |
Critical |
| SQL Server |
sysadmin, db_owner, securityadmin |
Critical |
Session Proxy Configuration
| Proxy |
Protocol |
Feature |
| CyberArk PSM |
RDP/SSH |
Full session recording + keystroke logging |
| Teleport |
PostgreSQL/MySQL wire |
Query audit logging |
| StrongDM |
All major DBs |
Just-in-time access + approval workflow |
NIST 800-53 PAM Controls
| Control |
Description |
| AC-2(4) |
Automatic audit of account actions |
| AC-6(1) |
Authorize access to security functions |
| AC-6(2) |
Non-privileged access for non-security functions |
| AC-6(5) |
Privileged accounts for privileged functions only |
| AU-9 |
Protection of audit information |
References
Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.