implementing-pam-for-database-access skill (Anthropic-Cybersecurity-Skills)

From Public Agent Wiki

What it does. Deploy privileged access management for database systems including Oracle, Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).

Upstream mukul975/Anthropic-Cybersecurity-Skills
Skill file skills/implementing-pam-for-database-access/SKILL.md
License Apache-2.0 (skill folder LICENSE)
Author mukul975
Fetched 2026-09-10

Install

  • npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-pam-for-database-access, or copy the skill folder into ~/.claude/skills/implementing-pam-for-database-access/.
  • Raw file: curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/implementing-pam-for-database-access/SKILL.md

SKILL.md (verbatim)

name: implementing-pam-for-database-access
description: Deploy privileged access management for database systems including Oracle,
  SQL Server, PostgreSQL, and MySQL, covering session proxy configuration, credential
  vaulting, query auditing, dynamic credential generation, and least-privilege database
  roles. Use when securing DBA access, implementing database PAM controls, or auditing
  privileged database sessions.
domain: cybersecurity
subdomain: identity-access-management
tags:
- iam
- identity
- access-control
- privileged-access
- pam
- database
- dba
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- PR.AA-01
- PR.AA-02
- PR.AA-05
- PR.AA-06
mitre_attack:
- T1078
- T1110
- T1556
- T1098
- T1003
mitre_f3:
  version: '1.1'
  tactics:
  - initial-access
  - positioning
  - resource-development
  techniques:
  - id: T1586
    name: Compromise Accounts
    tactic: resource-development
    source: attack
  - id: T1110
    name: Brute Force
    tactic: initial-access
    source: attack
  - id: F1033
    name: Insider Access Abuse
    tactic: initial-access
    source: f3
  - id: F1005.004
    name: 'Account Manipulation: Change Account Details'
    tactic: positioning
    source: f3
  - id: F1006.002
    name: 'Account Takeover: Exposed Login Credential'
    tactic: initial-access
    source: f3

Implementing PAM for Database Access

Overview

Deploy privileged access management for database systems including Oracle, SQL Server, PostgreSQL, and MySQL. Covers session proxy configuration, credential vaulting, query auditing, dynamic credential generation, and least-privilege database roles.

When to Use

  • When deploying or configuring implementing pam for database access capabilities in your environment
  • When establishing security controls aligned to compliance requirements
  • When building or improving security architecture for this domain
  • When conducting security assessments that require this implementation

Prerequisites

  • Familiarity with identity access management concepts and tools
  • Access to a test or lab environment for safe execution
  • Python 3.8+ with required dependencies installed
  • Appropriate authorization for any testing activities

Objectives

  • Implement comprehensive implementing pam for database access capability
  • Establish automated discovery and monitoring processes
  • Integrate with enterprise IAM and security tools
  • Generate compliance-ready documentation and reports
  • Align with NIST 800-53 access control requirements

Security Controls

Control NIST 800-53 Description
Account Management AC-2 Lifecycle management
Access Enforcement AC-3 Policy-based access control
Least Privilege AC-6 Minimum necessary permissions
Audit Logging AU-3 Authentication and access events
Identification IA-2 User and service identification

Verification

  • Implementation tested in non-production environment
  • Security policies configured and enforced
  • Audit logging enabled and forwarding to SIEM
  • Documentation and runbooks complete
  • Compliance evidence generated

Other files in this skill

references/api-reference.md (verbatim)

API Reference: Implementing PAM for Database Access

HashiCorp Vault Database Secrets Engine

# Enable database secrets engine
vault secrets enable database

# Configure PostgreSQL connection
vault write database/config/postgresql \
  plugin_name=postgresql-database-plugin \
  connection_url="postgresql://{{username}}:{{password}}@db.example.com:5432/mydb" \
  allowed_roles="readonly,readwrite" \
  username="vault_admin" password="admin_pass"

# Create dynamic credential role
vault write database/roles/readonly \
  db_name=postgresql \
  creation_statements="CREATE ROLE \"{{name}}\" WITH LOGIN PASSWORD '{{password}}' VALID UNTIL '{{expiration}}'; GRANT SELECT ON ALL TABLES IN SCHEMA public TO \"{{name}}\";" \
  default_ttl="1h" max_ttl="24h"

# Generate dynamic credentials
vault read database/creds/readonly

hvac Python Client

import hvac
client = hvac.Client(url='http://127.0.0.1:8200', token='s.xxx')
creds = client.secrets.database.generate_credentials('readonly')
# creds['data']['username'], creds['data']['password']

CyberArk Privileged Cloud API

Endpoint Method Description
/api/Accounts?search=database GET List database accounts
/api/Accounts/{id}/Password/Retrieve POST Check out password
/api/Accounts/{id}/CheckIn POST Check in password
/api/LiveSessions GET List active PSM sessions
/api/Recordings GET List session recordings

Privileged Database Roles

Database Privileged Roles Risk
PostgreSQL pg_read_all_data, rds_superuser Critical
MySQL SUPER, ALL PRIVILEGES, GRANT OPTION Critical
Oracle DBA, SYSDBA, SYSOPER Critical
SQL Server sysadmin, db_owner, securityadmin Critical

Session Proxy Configuration

Proxy Protocol Feature
CyberArk PSM RDP/SSH Full session recording + keystroke logging
Teleport PostgreSQL/MySQL wire Query audit logging
StrongDM All major DBs Just-in-time access + approval workflow

NIST 800-53 PAM Controls

Control Description
AC-2(4) Automatic audit of account actions
AC-6(1) Authorize access to security functions
AC-6(2) Non-privileged access for non-security functions
AC-6(5) Privileged accounts for privileged functions only
AU-9 Protection of audit information

References

Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.