analyzing-cloud-storage-access-patterns
mukul975/Anthropic-Cybersecurity-Skills
Detects abnormal access patterns across major cloud storage platforms, including AWS S3, GCS, and Azure Blob Storage. By analyzing cloud audit logs (CloudTrail, etc.), this tool identifies critical security threats such as after-hours bulk data downloads, sudden spikes in API calls (GetObject spikes), access from new geographic IPs, and potential data exfiltration. It utilizes statistical baselines and time-series anomaly detection for proactive threat hunting and security incident investigation.