Defender For Cloud Hardening
vinayaklatthe/microsoft-security-skills
Guidance for Microsoft Defender for Cloud — cloud security posture management (CSPM) and cloud workload protection (CWPP) across Azure, AWS, and GCP.
Agent skill
Implements security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection to detect threats, enforce compliance, and respond to security events across cloud…
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-security-monitoring-with-datadog -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-security-monitoring-with-datadog --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-security-monitoring-with-datadog .claude/skills/implementing-security-monitoring-with-datadog && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "implementing-security-monitoring-with-datadog" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-security-monitoring-with-datadog into .claude/skills/implementing-security-monitoring-with-datadog/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-security-monitoring-with-datadog", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-security-monitoring-with-datadogType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-security-monitoring-with-datadog -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-security-monitoring-with-datadog --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/implementing-security-monitoring-with-datadog .agents/skills/implementing-security-monitoring-with-datadog && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "implementing-security-monitoring-with-datadog" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-security-monitoring-with-datadog into .agents/skills/implementing-security-monitoring-with-datadog/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-security-monitoring-with-datadog", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-security-monitoring-with-datadog -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-security-monitoring-with-datadog --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/implementing-security-monitoring-with-datadog .cursor/skills/implementing-security-monitoring-with-datadog && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "implementing-security-monitoring-with-datadog" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-security-monitoring-with-datadog into .cursor/skills/implementing-security-monitoring-with-datadog/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-security-monitoring-with-datadog", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git --path skills/implementing-security-monitoring-with-datadog--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-security-monitoring-with-datadog -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-security-monitoring-with-datadog --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/implementing-security-monitoring-with-datadog .gemini/skills/implementing-security-monitoring-with-datadog && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "implementing-security-monitoring-with-datadog" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-security-monitoring-with-datadog into .gemini/skills/implementing-security-monitoring-with-datadog/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-security-monitoring-with-datadog", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-security-monitoring-with-datadogInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-security-monitoring-with-datadog -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/implementing-security-monitoring-with-datadog .github/skills/implementing-security-monitoring-with-datadog && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "implementing-security-monitoring-with-datadog" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-security-monitoring-with-datadog into .github/skills/implementing-security-monitoring-with-datadog/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-security-monitoring-with-datadog", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-security-monitoring-with-datadog -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-security-monitoring-with-datadog --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/implementing-security-monitoring-with-datadog .opencode/skills/implementing-security-monitoring-with-datadog && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "implementing-security-monitoring-with-datadog" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-security-monitoring-with-datadog into .opencode/skills/implementing-security-monitoring-with-datadog/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-security-monitoring-with-datadog", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
implementing-security-monitoring-with-datadogImplements security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection to detect threats, enforce compliance, and respond to security events across cloud…
Implementing Security Monitoring With Datadog is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Implements security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection to detect threats, enforce compliance, and respond to security events across cloud and hybrid infrastructure. Covers Agent deployment, log source ingestion, detection rule creation, security dashboards, and automated notification workflows. Activates for requests involving Datadog security setup, Cloud SIEM configuration, CSM threat detection, or security monitoring dashboards.
Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).
It sits in Security, covering Security operations, Cloud security and Monitoring and alerting. It works with Datadog and Amazon Web Services. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
awssshFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use aws and ssh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
DD_API_KEYDD_APP_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Implementing Security Monitoring With Datadog loads about 3.7k tokens when it runs, and up to ~4.5k if it reads all its reference files. Until then it costs about 135 tokens; SKILL.md has 664 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
sudo systemctl restart datadog-agentsudo datadog-agent status | grep -A5 "Security Agent"Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 664 words, ~3,667 tokens.
.claude/skills/implementing-security-monitoring-with-datadog/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Do not use for endpoint-only monitoring without cloud infrastructure; use a dedicated EDR solution for purely on-premises endpoint detection.
datadog-api-client library for programmatic rule managementInstall the Datadog Agent and enable security-related features in datadog.yaml:
# /etc/datadog-agent/datadog.yaml
api_key: <YOUR_DATADOG_API_KEY>
site: datadoghq.com # or datadoghq.eu, us3.datadoghq.com, etc.
# Enable log collection for Cloud SIEM
logs_enabled: true
# Enable security features
runtime_security_config:
enabled: true # Workload Protection (CSM Threats)
activity_dump:
enabled: true # Record process activity for investigation
compliance_config:
enabled: true # CIS benchmark checks (CSM Misconfigurations)
host_benchmarks:
enabled: trueConfigure log sources for security-relevant files on Linux:
# /etc/datadog-agent/conf.d/auth.d/conf.yaml
logs:
- type: file
path: /var/log/auth.log
source: auth
service: linux-auth
tags:
- env:production
- security:authentication
- type: file
path: /var/log/syslog
source: syslog
service: linux-syslogFor Windows Security Event Logs:
# /etc/datadog-agent/conf.d/win32_event_log.d/conf.yaml
logs:
- type: windows_event
channel_path: Security
source: windows.events
service: windows-security
filters:
- id: [4624, 4625, 4648, 4672, 4688, 4720, 4726, 4740, 4767]Enable the system-probe for Workload Protection (CSM Threats):
# /etc/datadog-agent/system-probe.yaml
runtime_security_config:
enabled: true
fim_enabled: true # File Integrity Monitoring
network_enabled: true # Network activity monitoringRestart the Agent after configuration changes:
sudo systemctl restart datadog-agent
sudo datadog-agent status | grep -A5 "Security Agent"Set up AWS CloudTrail, VPC Flow Logs, and GuardDuty ingestion for Cloud SIEM:
Datadog App > Security > Cloud SIEM > Configuration > Content Packs
AWS Content Pack:
1. Enable the AWS integration in Datadog (Integrations > Amazon Web Services)
2. Configure CloudTrail log forwarding via the Datadog Forwarder Lambda
3. Enable VPC Flow Logs forwarding to Datadog
4. Enable GuardDuty findings forwarding
Required IAM permissions for the Datadog role:
- cloudtrail:LookupEvents
- logs:FilterLogEvents
- guardduty:ListDetectors, guardduty:GetFindings
- s3:GetObject (for CloudTrail S3 bucket)
Azure Content Pack:
1. Configure Azure Activity Logs via Event Hub to Datadog
2. Forward Azure AD Sign-in Logs and Audit Logs
3. Enable Microsoft Defender for Cloud alerts forwarding
GCP Content Pack:
1. Configure GCP Audit Logs export via Pub/Sub to Datadog
2. Forward Cloud Audit Logs (Admin Activity, Data Access)Verify log ingestion is working:
Datadog App > Logs > Search
Filter: source:(cloudtrail OR aws.guardduty OR azure.activitylogs)
Verify: Logs appearing with correct source tags and parsed attributesDatadog provides out-of-the-box detection rules that are automatically imported. Review and customize them:
Datadog App > Security > Detection Rules
Out-of-the-box rule categories:
- AWS: IAM policy changes, root account usage, S3 public access
- Azure: Suspicious sign-ins, resource group deletions
- GCP: IAM policy modifications, firewall rule changes
- Authentication: Brute force, impossible travel, credential stuffing
- Network: Port scanning, DNS tunneling, C2 beaconing
- Application: SQL injection attempts, XSS, SSRF patternsCreate a custom detection rule for brute force login detection:
Datadog App > Security > Detection Rules > New Rule
Rule Name: "Brute Force Login Detection - Custom"
Rule Type: Log Detection (Real-time)
Define Search Query:
source:auth status:error @evt.name:authentication @evt.outcome:failure
Group By: @usr.id
Set Rule Cases:
Case 1: When count > 10 in 5 minutes
Name: "High volume failed logins"
Severity: HIGH
Notification: @slack-security-alerts @pagerduty-soc
Case 2: When count > 50 in 5 minutes
Name: "Extreme brute force attempt"
Severity: CRITICAL
Notification: @slack-security-alerts @pagerduty-soc-critical
Signal Settings:
Keep signal alive for: 10 minutes
Maximum signal duration: 24 hours
Evaluation window: 5 minutesCreate a detection rule for AWS root account usage:
Rule Name: "AWS Root Account Console Login"
Rule Type: Log Detection
Query:
source:cloudtrail @evt.name:ConsoleLogin @userIdentity.type:Root
Severity: CRITICAL
Notification Message:
"AWS Root account console login detected from IP {{@network.client.ip}}.
Account: {{@usr.account_id}}
Region: {{@cloud.region}}
MFA Used: {{@additionalEventData.MFAUsed}}"
Tags: attack:initial-access, mitre:T1078Set up runtime threat detection for hosts and containers:
Datadog App > Security > Cloud Security Management > Setup
Enable Workload Protection:
1. Verify Agent has runtime_security_config.enabled: true
2. Review default Agent rules (file integrity, process execution)
3. Customize rules for your environment
Default detection categories:
- Process Execution: Detect reverse shells, crypto miners, exploitation tools
- File Integrity: Monitor changes to /etc/passwd, /etc/shadow, SSH keys
- Network Activity: Detect unexpected outbound connections, DNS tunneling
- Container Escape: Detect privileged container breakout attempts
- Kernel Module: Detect rootkit or unauthorized kernel module loadingCreate a custom CSM Threats Agent rule to detect unauthorized SSH key modifications:
Datadog App > Security > CSM > Agent Rules > New Agent Rule
Rule Expression:
open.file.path == "/root/.ssh/authorized_keys" &&
open.flags & (O_WRONLY | O_RDWR | O_CREAT) > 0 &&
process.file.name != "sshd"
Rule Name: ssh_key_modification
Description: Detect non-sshd processes modifying root authorized_keys
Tags: attack:persistence, mitre:T1098.004Create a Cloud SIEM overview dashboard:
Datadog App > Dashboards > New Dashboard > "Security Operations Overview"
Widgets:
1. Signal Count Over Time (timeseries)
Query: count:security_signal by {signal.rule.name}
Display: Line chart, last 24 hours
2. Top Triggered Rules (top list)
Query: count:security_signal by {signal.rule.name}.as_count()
Display: Top 10
3. Critical Signals (query value)
Query: count:security_signal{severity:critical}
Conditional format: Red if > 0
4. Signals by Source (pie chart)
Query: count:security_signal by {source}
5. Geographic Threat Map (geomap)
Query: count:security_signal by {network.client.geoip.country.name}
6. Top Targeted Users (top list)
Query: count:security_signal by {usr.id}
7. Mean Time to Triage (query value)
Query: avg:security_signal.triage_time
8. Open Signals by Severity (table)
Query: count:security_signal{status:open} by {severity}Set up automated notification and response workflows:
Datadog App > Security > Notification Rules
Rule 1: Critical Signal Escalation
Condition: severity:critical
Recipients: @pagerduty-soc-critical @slack-security-incidents
Message: "CRITICAL security signal: {{signal.rule.name}}
Source: {{signal.attributes.network.client.ip}}
Target: {{signal.attributes.usr.id}}
Details: {{signal.message}}"
Rule 2: High Signal SOC Alert
Condition: severity:high
Recipients: @slack-security-alerts
Suppress: After first notification, suppress for 15 minutes
Rule 3: Compliance Violation
Condition: rule_type:compliance
Recipients: @slack-compliance-team @jira-compliance-board
Workflow Automation (Datadog Workflows):
Trigger: Security signal with severity:critical
Steps:
1. Enrich signal with threat intelligence lookup
2. Create Jira incident ticket
3. Send Slack notification with investigation context
4. If source is AWS: Trigger Lambda to isolate resourceTest detection rules and tune false positives:
# Generate a test security event (failed SSH login)
ssh -o StrictHostKeyChecking=no invalid_user@localhost 2>/dev/null
# Verify the event appears in Datadog Logs
# Datadog App > Logs > source:auth status:error
# Check that a security signal was generated
# Datadog App > Security > Signals > Filter by rule name
# Tune noisy rules by adding suppression queries:
# Datadog App > Security > Detection Rules > [Rule] > Edit
# Add suppression: Suppress signal when @usr.id:service-account-*Use the Security Signals API to validate programmatically:
from datadog_api_client import Configuration, ApiClient
from datadog_api_client.v2.api.security_monitoring_api import SecurityMonitoringApi
configuration = Configuration()
# Reads DD_API_KEY and DD_APP_KEY from environment
with ApiClient(configuration) as api_client:
api = SecurityMonitoringApi(api_client)
signals = api.search_security_monitoring_signals(
body={
"filter": {
"query": "status:open severity:critical",
"from": "now-24h",
"to": "now",
},
"sort": {"field": "timestamp", "order": "desc"},
"page": {"limit": 25},
}
)
for signal in signals.data:
attrs = signal.attributes
print(f"[{attrs.severity}] {attrs.title}")
print(f" Rule: {attrs.custom.get('rule', {}).get('name', 'N/A')}")
print(f" Time: {attrs.timestamp}")| Term | Definition |
|---|---|
| Cloud SIEM | Datadog's security information and event management service that analyzes ingested logs in real-time to detect threats using detection rules |
| Security Signal | An alert generated when a detection rule matches incoming log data; signals have severity, status (open/triage/closed), and investigation context |
| Detection Rule | A query-based rule that evaluates logs or events against conditions (threshold, anomaly, new value, impossible travel) to generate security signals |
| CSM (Cloud Security Management) | Datadog platform for infrastructure security including Misconfigurations (compliance benchmarks), Threats (runtime detection), and Vulnerabilities |
| Workload Protection | CSM Threats component that monitors file, process, and network activity on hosts and containers using eBPF-based Agent rules |
| Content Pack | Pre-built collection of detection rules, dashboards, and log parsers for a specific integration (AWS, Azure, GCP, Okta, etc.) |
| Agent Rule | A kernel-level rule evaluated by the Datadog Agent on the host to collect security-relevant events before sending to Datadog for threat detection |
| Suppression Query | A filter applied to a detection rule to prevent signals from being generated for known-good activity (reduces false positives) |
datadog-agent status shows security agent running)© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (scripts, references) in skills/implementing-security-monitoring-with-datadog of mukul975/Anthropic-Cybersecurity-Skills.
Open the folder on GitHubat commit 54a7988
Implementing Security Monitoring With Datadog next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Implementing Security Monitoring With Datadog this skillmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.7k | Automated safety check: Notes | Apache-2.0 | |
| Defender For Cloud Hardeningvinayaklatthe/microsoft-security-skills | 175 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Dd AWS Integrationdatadog-labs/agent-skills | 177 | — | ~6.8k | Automated safety check: Notes | MIT | |
| Tsh Implementing ObservabilityTheSoftwareHouse/copilot-collections | 284 | — | ~2k | Automated safety check: Pass | MIT | |
| Cloud Auditbriiirussell/cybersecurity-skills | 413 | — | ~1.3k | Automated safety check: Notes | MIT | |
| Ecs Operation Reviewaws/tools-for-devops-agent | 103 | — | ~4.8k | Automated safety check: Pass | Apache-2.0 |
vinayaklatthe/microsoft-security-skills
Guidance for Microsoft Defender for Cloud — cloud security posture management (CSPM) and cloud workload protection (CWPP) across Azure, AWS, and GCP.
datadog-labs/agent-skills
Set up the Datadog AWS integration with Terraform - creates the cross-account IAM role Datadog assumes (external ID, no stored credentials), attaches the permission policies Datadog publishes, and…
TheSoftwareHouse/copilot-collections
Observability patterns for logging, monitoring, alerting, and distributed tracing.
briiirussell/cybersecurity-skills
Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.
aws/tools-for-devops-agent
Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs…
itsmostafa/aws-agent-skills
AWS Identity and Access Management for users, roles, policies, and permissions.
mukul975/Anthropic-Cybersecurity-Skills
Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.
mukul975/Anthropic-Cybersecurity-Skills
Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.
mukul975/Anthropic-Cybersecurity-Skills
Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.
mukul975/Anthropic-Cybersecurity-Skills
Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.
mukul975/Anthropic-Cybersecurity-Skills
Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.
mukul975/Anthropic-Cybersecurity-Skills
Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.
Works with
Categories
Implements security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection to detect threats, enforce compliance, and respond to security events across cloud…. Implementing Security Monitoring With Datadog is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Implements security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection to detect threats, enforce compliance, and respond to security events across cloud and hybrid infrastructure.
Implementing Security Monitoring With Datadog fits situations like: tasks that involve Security operations; tasks that involve Cloud security; tasks that involve Monitoring and alerting.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-security-monitoring-with-datadog -a claude-code`. Or copy the skill folder (skills/implementing-security-monitoring-with-datadog in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/implementing-security-monitoring-with-datadog in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-security-monitoring-with-datadog -a codex`. Or copy the skill folder (skills/implementing-security-monitoring-with-datadog in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/implementing-security-monitoring-with-datadog in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-security-monitoring-with-datadog -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-security-monitoring-with-datadog, .gemini/skills/implementing-security-monitoring-with-datadog, .github/skills/implementing-security-monitoring-with-datadog and .opencode/skills/implementing-security-monitoring-with-datadog in your project.
Going by SKILL.md and its folder, Implementing Security Monitoring With Datadog needs Python for the scripts in its folder, the command-line tools its instructions call (aws and ssh) and credentials named DD_API_KEY and DD_APP_KEY. Our summary lists: Python 3; A credential in YOUR_DATADOG_API_KEY; A credential in DD_API_KEY.
SKILL.md contains no URLs. Its commands use ssh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Implementing Security Monitoring With Datadog is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 869 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Implementing Security Monitoring With Datadog: Defender For Cloud Hardening (vinayaklatthe/microsoft-security-skills, 175 stars), Dd AWS Integration (datadog-labs/agent-skills, 177 stars), Tsh Implementing Observability (TheSoftwareHouse/copilot-collections, 284 stars) and Cloud Audit (briiirussell/cybersecurity-skills, 413 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.
Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.