Agent skill

Analyzing Cloud Storage Access Patterns

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Detect abnormal access in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics for after-hours bulk downloads, new-IP access, and…

Apache-2.0Auto-check passedData & Analytics

Install Analyzing Cloud Storage Access Patterns

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill analyzing-cloud-storage-access-patterns -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills analyzing-cloud-storage-access-patterns --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/analyzing-cloud-storage-access-patterns .claude/skills/analyzing-cloud-storage-access-patterns && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
analyzing-cloud-storage-access-patterns
GitHub stars
34k
Token cost
~599 tokens
SKILL.md length
157 words
Files
4 (incl. scripts, references)
Skills in repo
639
Repo updated
First seen
Licence
Apache-2.0

At a glance

Detect abnormal access in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics for after-hours bulk downloads, new-IP access, and…

  • Works in 5 steps: Install dependencies: pip install boto3… → Query CloudTrail for S3 Data Events… → Build access baselines: hourly request… → …
  • Investigating suspected cloud data exfiltration
  • SKILL.md covers When to Use, Prerequisites, Instructions and Examples
  • Runs Python scripts from its folder; calls python and pip

What it does

Analyzing Cloud Storage Access Patterns is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Detect abnormal access in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics for after-hours bulk downloads, new-IP access, and API-call spikes (e.g. GetObject) via statistical baselines and time-series anomaly detection. Use when investigating suspected cloud data exfiltration or building related detection rules.

Its SKILL.md is about 600 tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Data & Analytics, covering Anomaly detection and Forecasting and time series. It works with Amazon S3, Azure Blob Storage and Microsoft Azure. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Investigating suspected cloud data exfiltration
  • Building related detection rules

Example prompts

  • “/analyzing-cloud-storage-access-patterns”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Install dependencies: pip install boto3 requests
  2. Query CloudTrail for S3 Data Events using AWS CLI or boto3.
  3. Build access baselines: hourly request volume, per-user object counts, source IP history.
  4. Detect anomalies
  5. Generate prioritized findings report.

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Analyzing Cloud Storage Access Patterns loads about 599 tokens when it runs, and up to ~984 if it reads all its reference files. Until then it costs about 105 tokens; SKILL.md has 157 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~105
When it runs · the whole SKILL.md, loaded when a task matches
~599
With references · SKILL.md plus every file in references/, read only if the agent opens them
~984

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 157 words, ~599 tokens.

Download SKILL.mdSave it as .claude/skills/analyzing-cloud-storage-access-patterns/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
analyzing-cloud-storage-access-patterns
description
Detect abnormal access in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics for after-hours bulk downloads, new-IP access, and API-call spikes (e.g. GetObject) via statistical baselines and time-series anomaly detection. Use when investigating suspected cloud data exfiltration or building related detection rules.
domain
cybersecurity
subdomain
cloud-security
tags
cloud-security, aws-s3, gcs, azure-blob-storage, cloudtrail, data-access-anomaly, exfiltration-detection
version
1.0
author
mahipal
license
Apache-2.0
atlas_techniques
AML.T0024, AML.T0056
nist_ai_rmf
MEASURE-2.7, MAP-5.1, MANAGE-2.4
nist_csf
PR.IR-01, ID.AM-08, GV.SC-06, DE.CM-01
mitre_attack
T1530, T1567.002, T1619, T1078.004, T1048

Analyzing Cloud Storage Access Patterns

When to Use

  • When investigating security incidents that require analyzing cloud storage access patterns
  • When building detection rules or threat hunting queries for this domain
  • When SOC analysts need structured procedures for this analysis type
  • When validating security monitoring coverage for related attack techniques

Prerequisites

  • Familiarity with cloud security concepts and tools
  • Access to a test or lab environment for safe execution
  • Python 3.8+ with required dependencies installed
  • Appropriate authorization for any testing activities

Instructions

  1. Install dependencies: pip install boto3 requests
  2. Query CloudTrail for S3 Data Events using AWS CLI or boto3.
  3. Build access baselines: hourly request volume, per-user object counts, source IP history.
  4. Detect anomalies:
    • After-hours access (outside 8am-6pm local time)
    • Bulk downloads: >100 GetObject calls from single principal in 1 hour
    • New source IPs not seen in the prior 30 days
    • ListBucket enumeration spikes (reconnaissance indicator)
  5. Generate prioritized findings report.
bash
python scripts/agent.py --bucket my-sensitive-data --hours-back 24 --output s3_access_report.json

Examples

CloudTrail S3 Data Event
json
{"eventName": "GetObject", "requestParameters": {"bucketName": "sensitive-data", "key": "financials/q4.xlsx"},
 "sourceIPAddress": "203.0.113.50", "userIdentity": {"arn": "arn:aws:iam::123456789012:user/analyst"}}

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/analyzing-cloud-storage-access-patterns of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Analyzing Cloud Storage Access Patterns next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Analyzing Cloud Storage Access Patterns compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Analyzing Cloud Storage Access Patterns this skillmukul975/Anthropic-Cybersecurity-Skills34k—~599Automated safety check: PassApache-2.0
Kqlmicrosoft/fabric-rti-mcp131—~6.2kAutomated safety check: PassMIT
Azure AI Anomalydetector Javamicrosoft/skills3.1k6 repos~2.3kAutomated safety check: PassMIT
Azure Kustomicrosoft/GitHub-Copilot-for-Azure2551 repos~2.2kAutomated safety check: PassMIT
Kqlmicrosoft/skills3.1k—~4.7kAutomated safety check: PassMIT
Apex Azure Kustojonathan-vella/apex217—~984Automated safety check: PassMIT

Similar skills

  • Kql

    microsoft/fabric-rti-mcp

    Official

    KQL language expertise for writing correct, efficient Kusto queries using the Fabric RTI MCP tools.

    131 GitHub stars~6.2k tokensUpdated 6 days ago
    Data & AnalyticsAuto-check passed
  • Official

    Build anomaly detection applications with Azure AI Anomaly Detector SDK for Java.

    3.1k GitHub starsUsed in 6 repos~2.3k tokens
    Data & AnalyticsAuto-check passed
  • Azure Kusto

    microsoft/GitHub-Copilot-for-Azure

    Official

    Query and analyze data in Azure Data Explorer (Kusto/ADX) using KQL for log analytics, telemetry, and time series analysis.

    255 GitHub starsUsed in 1 repo~2.2k tokens
    Data & AnalyticsAuto-check passed
  • Kql

    microsoft/skills

    Official

    KQL language expertise for writing correct, efficient Kusto Query Language queries.

    3.1k GitHub stars~4.7k tokensUpdated today
    Data & AnalyticsAuto-check passed
  • Apex Azure Kusto

    jonathan-vella/apex

    ANALYSIS SKILL — Query and analyze data in Azure Data Explorer (Kusto/ADX) using KQL.

    217 GitHub stars~984 tokensUpdated today
    Data & AnalyticsAuto-check passed
  • TimesFM Forecasting

    google-research/timesfm

    Forecasts any univariate time series zero-shot with Google's TimesFM model, returning point forecasts and calibrated prediction intervals without training.

    34k GitHub stars~4.7k tokensUpdated 7 days ago
    Data & AnalyticsAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 639 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Analyzing Cloud Storage Access Patterns

What does Analyzing Cloud Storage Access Patterns do?

Detect abnormal access in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics for after-hours bulk downloads, new-IP access, and…. Analyzing Cloud Storage Access Patterns is an agent skill from mukul975/Anthropic-Cybersecurity-Skills.g.

When should I use Analyzing Cloud Storage Access Patterns?

Analyzing Cloud Storage Access Patterns fits situations like: investigating suspected cloud data exfiltration; building related detection rules.

How do I install Analyzing Cloud Storage Access Patterns in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill analyzing-cloud-storage-access-patterns -a claude-code`. Or copy the skill folder (skills/analyzing-cloud-storage-access-patterns in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/analyzing-cloud-storage-access-patterns in your project. Claude Code loads it when a task matches its description.

How do I install Analyzing Cloud Storage Access Patterns in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill analyzing-cloud-storage-access-patterns -a codex`. Or copy the skill folder (skills/analyzing-cloud-storage-access-patterns in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/analyzing-cloud-storage-access-patterns in your project. Codex loads it when a task matches its description.

Can I use Analyzing Cloud Storage Access Patterns in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill analyzing-cloud-storage-access-patterns -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/analyzing-cloud-storage-access-patterns, .gemini/skills/analyzing-cloud-storage-access-patterns, .github/skills/analyzing-cloud-storage-access-patterns and .opencode/skills/analyzing-cloud-storage-access-patterns in your project.

What does Analyzing Cloud Storage Access Patterns need to run?

Going by SKILL.md and its folder, Analyzing Cloud Storage Access Patterns needs Python for the scripts in its folder and the command-line tools its instructions call (python and pip). Our summary lists: Python 3.

Does Analyzing Cloud Storage Access Patterns access the network?

SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Analyzing Cloud Storage Access Patterns safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Analyzing Cloud Storage Access Patterns use?

Analyzing Cloud Storage Access Patterns is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Analyzing Cloud Storage Access Patterns use?

About 599 tokens (SKILL.md is roughly 2.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 385 tokens, read only when the agent opens those files.

What are the alternatives to Analyzing Cloud Storage Access Patterns?

Skills that share tags, products or a category with Analyzing Cloud Storage Access Patterns: Kql (microsoft/fabric-rti-mcp, 131 stars), Azure AI Anomalydetector Java (microsoft/skills, 3.1k stars), Azure Kusto (microsoft/GitHub-Copilot-for-Azure, 255 stars) and Kql (microsoft/skills, 3.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Analyzing Cloud Storage Access Patterns?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,870 GitHub stars. The repository holds 639 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.