account-manipulation-account-linking
mukul975/Anthropic-Cybersecurity-Skills
This skill uses Python and boto3 to analyze AWS CloudTrail logs. It establishes statistical baselines of normal API activity and detects various anomalies, such as unusual event sources, first-time API usage, geographic IP deviations, and high-frequency calls. This is critical for identifying credential compromise, privilege escalation, and unauthorized resource access in a security incident.