performing-cloud-forensics-with-aws-cloudtrail skill (Anthropic-Cybersecurity-Skills)

From Public Agent Wiki

What it does. Investigate AWS account compromise by querying CloudTrail with boto3's LookupEvents Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).

Upstream mukul975/Anthropic-Cybersecurity-Skills
Skill file skills/performing-cloud-forensics-with-aws-cloudtrail/SKILL.md
License Apache-2.0 (skill folder LICENSE)
Author mukul975
Fetched 2026-09-10

Install

  • npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-cloud-forensics-with-aws-cloudtrail, or copy the skill folder into ~/.claude/skills/performing-cloud-forensics-with-aws-cloudtrail/.
  • Raw file: curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/performing-cloud-forensics-with-aws-cloudtrail/SKILL.md

SKILL.md (verbatim)

name: performing-cloud-forensics-with-aws-cloudtrail
description: Investigate AWS account compromise by querying CloudTrail with boto3's LookupEvents
  or AWS Athena SQL over S3-delivered logs, filtering on suspicious user agents, source IPs, and
  event names to reconstruct an attacker timeline. Use when tracing unauthorized API calls, S3
  data exfiltration, IAM privilege escalation, or credential exposure, and building a forensic
  report of findings and remediation steps.
domain: cybersecurity
subdomain: cloud-security
tags:
- cloud-security
- aws
- cloudtrail
- forensics
- incident-response
- dfir
- boto3
- s3
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- PR.IR-01
- ID.AM-08
- GV.SC-06
- DE.CM-01
mitre_attack:
- T1078.004
- T1530
- T1537
- T1580
- T1003

Performing Cloud Forensics with AWS CloudTrail

When to Use

  • When investigating suspected AWS account compromise
  • After detecting unauthorized API calls or credential exposure
  • During incident response involving cloud infrastructure
  • When analyzing S3 data exfiltration or IAM privilege escalation
  • For post-incident forensic timeline reconstruction

Prerequisites

  • AWS account with CloudTrail enabled (management and data events)
  • IAM permissions for cloudtrail:LookupEvents, s3:GetObject, athena:StartQueryExecution
  • boto3 Python SDK installed
  • CloudTrail logs delivered to S3 with optional Athena table configured
  • AWS CLI configured with appropriate credentials

Workflow

  1. Scope Investigation: Identify timeframe, affected accounts, and compromised credentials.
  2. Query CloudTrail: Use boto3 lookup_events or Athena to retrieve relevant API events.
  3. Filter by Indicators: Search for suspicious user agents, source IPs, and event names.
  4. Reconstruct Timeline: Build chronological sequence of attacker actions from API calls.
  5. Analyze Access Patterns: Identify data access, IAM changes, and resource modifications.
  6. Identify Persistence: Check for new IAM users, access keys, roles, or Lambda functions.
  7. Generate Report: Produce forensic timeline with findings and remediation steps.

Key Concepts

Concept Description
LookupEvents CloudTrail API to query management events (last 90 days)
Athena Queries SQL queries against CloudTrail logs in S3 for historical analysis
User Agent Analysis Identify tool signatures (AWS CLI, SDK, console, custom)
AccessKeyId Track activity by specific IAM access key
EventName AWS API action name (e.g., GetObject, CreateUser, AssumeRole)
sourceIPAddress Origin IP of API call for geolocation analysis

Tools & Systems

Tool Purpose
boto3 CloudTrail client Programmatic CloudTrail event lookup
AWS Athena SQL-based analysis of CloudTrail S3 logs
AWS CLI Command-line CloudTrail queries
jq JSON processing for CloudTrail event parsing
CloudTrail Lake Advanced event data store with SQL query support

Output Format

Forensic Report: AWS-IR-[DATE]-[SEQ]
Account: [AWS Account ID]
Timeframe: [Start] to [End]
Compromised Credentials: [Access Key IDs]
Suspicious Events: [Count]
Source IPs: [List of attacker IPs]
Actions Taken: [API calls by attacker]
Data Accessed: [S3 objects, secrets, etc.]
Persistence Mechanisms: [New users, keys, roles]

Other files in this skill

references/api-reference.md (verbatim)

AWS CloudTrail Forensics API Reference

boto3 CloudTrail Client

import boto3
client = boto3.client("cloudtrail", region_name="us-east-1")

lookup_events

response = client.lookup_events(
    LookupAttributes=[
        {"AttributeKey": "Username", "AttributeValue": "compromised-user"},
    ],
    StartTime=datetime(2025, 1, 1),
    EndTime=datetime(2025, 1, 2),
    MaxResults=50,
)

LookupAttributes Keys

AttributeKey Description
EventId Unique event identifier
EventName AWS API action (e.g., CreateUser, GetObject)
ReadOnly true/false for read-only API calls
Username IAM user or role session name
ResourceType AWS resource type (e.g., AWS::S3::Object)
ResourceName Name or ARN of the resource accessed
EventSource AWS service (e.g., iam.amazonaws.com)
AccessKeyId IAM access key used for the API call

Response Structure

{
    "Events": [
        {
            "EventId": "abc123",
            "EventName": "CreateUser",
            "EventTime": "2025-01-01T12:00:00Z",
            "Username": "attacker",
            "CloudTrailEvent": "{\"sourceIPAddress\":\"1.2.3.4\",\"userAgent\":\"aws-cli/2.0\",...}"
        }
    ],
    "NextToken": "..."
}

Paginator Usage

paginator = client.get_paginator("lookup_events")
for page in paginator.paginate(
    LookupAttributes=[{"AttributeKey": "AccessKeyId", "AttributeValue": "AKIA..."}],
    StartTime=start, EndTime=end
):
    for event in page["Events"]:
        ct = json.loads(event["CloudTrailEvent"])
        print(ct["sourceIPAddress"], ct["eventName"])

AWS CLI Equivalents

# Lookup events by username
aws cloudtrail lookup-events \
  --lookup-attributes AttributeKey=Username,AttributeValue=compromised-user \
  --start-time 2025-01-01T00:00:00Z \
  --output json

# Search by access key
aws cloudtrail lookup-events \
  --lookup-attributes AttributeKey=AccessKeyId,AttributeValue=AKIAEXAMPLE \
  --max-results 50

Athena Query for S3 CloudTrail Logs

SELECT eventtime, eventname, useridentity.arn, sourceipaddress, useragent,
       requestparameters, responseelements, errorcode
FROM cloudtrail_logs
WHERE eventtime BETWEEN '2025-01-01' AND '2025-01-02'
  AND useridentity.accesskeyid = 'AKIAEXAMPLE'
ORDER BY eventtime;

Key Forensic Event Names

Event Name Service Forensic Significance
CreateUser IAM Persistence - new user account
CreateAccessKey IAM Persistence - new credential
AssumeRole STS Lateral movement / privilege escalation
GetObject S3 Data exfiltration
StopLogging CloudTrail Anti-forensics
PutBucketPolicy S3 Permission modification
RunInstances EC2 Cryptomining / C2 infrastructure
GetSecretValue SecretsManager Credential theft

Suspicious User Agents

User Agent Pattern Tool
Pacu/... AWS exploitation framework
python-requests Custom Python scripts
aws-cli/2.x from unusual IP CLI from attacker machine
Scout Suite Cloud security assessment
Prowler AWS security scanner

Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.