account-manipulation
mukul975/Anthropic-Cybersecurity-Skills
This solution provides a comprehensive framework for detecting compromised cloud credentials across AWS, Azure, and GCP. It analyzes anomalous API activity, impossible travel patterns, and indicators of credential stuffing by leveraging services like AWS GuardDuty, Azure Defender, and GCP SCC. Use this when investigating suspicious cloud API calls, responding to exposed credential alerts, or scoping a potential account takeover.