performing-cloud-native-threat-hunting-with-aws-detective
mukul975/Anthropic-Cybersecurity-Skills
AWS Detective automatically analyzes log data from CloudTrail, VPC Flow Logs, GuardDuty, and EKS audit logs to build interactive behavior graphs. This tool enables security analysts to investigate suspicious activity, trace lateral movement across accounts, profile compromised entities (IAM users, EC2 instances), and reconstruct complex attack timelines without manual log parsing. Ideal for triaging GuardDuty findings or investigating suspected AWS compromises.