Agent skill

Implementing Security Monitoring With Datadog

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Implements security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection to detect threats, enforce compliance, and respond to security events across cloud…

Apache-2.0Auto-check: notesSecurity

Install Implementing Security Monitoring With Datadog

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-security-monitoring-with-datadog -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-security-monitoring-with-datadog --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-security-monitoring-with-datadog .claude/skills/implementing-security-monitoring-with-datadog && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
implementing-security-monitoring-with-datadog
GitHub stars
34k
Token cost
~3.7k tokens
SKILL.md length
664 words
Files
4 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Implements security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection to detect threats, enforce compliance, and respond to security events across cloud…

  • Works in 7 steps: Deploy and Configure the Datadog Agent… → Configure Cloud Log Sources for SIEM → Enable and Customize Detection Rules → …
  • Tasks that involve Security operations
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 1 more section
  • Runs Python scripts from its folder; calls aws and ssh; needs DD_API_KEY and DD_APP_KEY

What it does

Implementing Security Monitoring With Datadog is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Implements security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection to detect threats, enforce compliance, and respond to security events across cloud and hybrid infrastructure. Covers Agent deployment, log source ingestion, detection rule creation, security dashboards, and automated notification workflows. Activates for requests involving Datadog security setup, Cloud SIEM configuration, CSM threat detection, or security monitoring dashboards.

Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Security, covering Security operations, Cloud security and Monitoring and alerting. It works with Datadog and Amazon Web Services. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Security operations
  • Tasks that involve Cloud security
  • Tasks that involve Monitoring and alerting

Example prompts

  • “Use the implementing-security-monitoring-with-datadog skill to implement security monitoring using Datadog Cloud SIEM, Cloud Security Management…”
  • “/implementing-security-monitoring-with-datadog”

Requirements

  • Python 3
  • A credential in YOUR_DATADOG_API_KEY
  • A credential in DD_API_KEY

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Deploy and Configure the Datadog Agent for Security
  2. Configure Cloud Log Sources for SIEM
  3. Enable and Customize Detection Rules
  4. Configure Workload Protection (CSM Threats)
  5. Build Security Dashboards
  6. Configure Notification Workflows
  7. Validate and Tune Detection Coverage

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • aws
    • ssh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use aws and ssh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • DD_API_KEY
    • DD_APP_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Implementing Security Monitoring With Datadog loads about 3.7k tokens when it runs, and up to ~4.5k if it reads all its reference files. Until then it costs about 135 tokens; SKILL.md has 664 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~135
When it runs · the whole SKILL.md, loaded when a task matches
~3.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:143
    sudo systemctl restart datadog-agent
  • NoteRuns commands with sudoSKILL.md:144
    sudo datadog-agent status | grep -A5 "Security Agent"

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 664 words, ~3,667 tokens.

Download SKILL.mdSave it as .claude/skills/implementing-security-monitoring-with-datadog/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
implementing-security-monitoring-with-datadog
description
Implements security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection to detect threats, enforce compliance, and respond to security events across cloud and hybrid infrastructure. Covers Agent deployment, log source ingestion, detection rule creation, security dashboards, and automated notification workflows. Activates for requests involving Datadog security setup, Cloud SIEM configuration, CSM threat detection, or security monitoring dashboards.
domain
cybersecurity
subdomain
security-operations
tags
siem, security-monitoring, datadog, cloud-security, log-analysis, detection-rules, CSM, workload-protection
version
1.0.0
author
mahipal
license
Apache-2.0
nist_ai_rmf
GOVERN-1.1, MEASURE-2.7, MANAGE-3.1, GOVERN-4.2, MAP-2.3
d3fend_techniques
Restore Access, Password Authentication, Biometric Authentication, Strong Password Policy, Restore User Account Access
nist_csf
DE.CM-01, RS.MA-01, GV.OV-01, DE.AE-02
mitre_attack
T1078, T1190, T1059, T1685.002, T1685.005

Implementing Security Monitoring with Datadog

When to Use

  • Deploying Cloud SIEM to detect real-time threats across cloud infrastructure (AWS, Azure, GCP)
  • Creating custom detection rules for attacker techniques, credential abuse, or anomalous behavior
  • Enabling Workload Protection (CSM Threats) to monitor file, process, and network activity on hosts and containers
  • Meeting compliance requirements (PCI-DSS, SOC 2, HIPAA) that mandate centralized log monitoring and alerting
  • Building security dashboards to provide SOC visibility into threat signals, investigation context, and response metrics

Do not use for endpoint-only monitoring without cloud infrastructure; use a dedicated EDR solution for purely on-premises endpoint detection.

Prerequisites

  • Datadog account with Security Monitoring (Cloud SIEM) and/or Cloud Security Management enabled
  • Datadog API Key and Application Key from Organization Settings > API Keys
  • Datadog Agent v7+ installed on hosts/containers that generate security-relevant logs
  • Log sources configured for ingestion: AWS CloudTrail, VPC Flow Logs, GuardDuty, Azure Activity Logs, GCP Audit Logs, or on-host logs (auth.log, syslog, Windows Security Events)
  • Python 3.9+ with datadog-api-client library for programmatic rule management
  • Network access from monitored hosts to Datadog intake endpoints (port 443)

Workflow

Step 1: Deploy and Configure the Datadog Agent for Security

Install the Datadog Agent and enable security-related features in datadog.yaml:

yaml
# /etc/datadog-agent/datadog.yaml

api_key: <YOUR_DATADOG_API_KEY>
site: datadoghq.com   # or datadoghq.eu, us3.datadoghq.com, etc.

# Enable log collection for Cloud SIEM
logs_enabled: true

# Enable security features
runtime_security_config:
  enabled: true          # Workload Protection (CSM Threats)
  activity_dump:
    enabled: true        # Record process activity for investigation

compliance_config:
  enabled: true          # CIS benchmark checks (CSM Misconfigurations)
  host_benchmarks:
    enabled: true

Configure log sources for security-relevant files on Linux:

yaml
# /etc/datadog-agent/conf.d/auth.d/conf.yaml
logs:
  - type: file
    path: /var/log/auth.log
    source: auth
    service: linux-auth
    tags:
      - env:production
      - security:authentication

  - type: file
    path: /var/log/syslog
    source: syslog
    service: linux-syslog

For Windows Security Event Logs:

yaml
# /etc/datadog-agent/conf.d/win32_event_log.d/conf.yaml
logs:
  - type: windows_event
    channel_path: Security
    source: windows.events
    service: windows-security
    filters:
      - id: [4624, 4625, 4648, 4672, 4688, 4720, 4726, 4740, 4767]

Enable the system-probe for Workload Protection (CSM Threats):

yaml
# /etc/datadog-agent/system-probe.yaml
runtime_security_config:
  enabled: true
  fim_enabled: true        # File Integrity Monitoring
  network_enabled: true    # Network activity monitoring

Restart the Agent after configuration changes:

bash
sudo systemctl restart datadog-agent
sudo datadog-agent status | grep -A5 "Security Agent"
Step 2: Configure Cloud Log Sources for SIEM

Set up AWS CloudTrail, VPC Flow Logs, and GuardDuty ingestion for Cloud SIEM:

Datadog App > Security > Cloud SIEM > Configuration > Content Packs

AWS Content Pack:
  1. Enable the AWS integration in Datadog (Integrations > Amazon Web Services)
  2. Configure CloudTrail log forwarding via the Datadog Forwarder Lambda
  3. Enable VPC Flow Logs forwarding to Datadog
  4. Enable GuardDuty findings forwarding

Required IAM permissions for the Datadog role:
  - cloudtrail:LookupEvents
  - logs:FilterLogEvents
  - guardduty:ListDetectors, guardduty:GetFindings
  - s3:GetObject (for CloudTrail S3 bucket)

Azure Content Pack:
  1. Configure Azure Activity Logs via Event Hub to Datadog
  2. Forward Azure AD Sign-in Logs and Audit Logs
  3. Enable Microsoft Defender for Cloud alerts forwarding

GCP Content Pack:
  1. Configure GCP Audit Logs export via Pub/Sub to Datadog
  2. Forward Cloud Audit Logs (Admin Activity, Data Access)

Verify log ingestion is working:

Datadog App > Logs > Search
  Filter: source:(cloudtrail OR aws.guardduty OR azure.activitylogs)
  Verify: Logs appearing with correct source tags and parsed attributes
Step 3: Enable and Customize Detection Rules

Datadog provides out-of-the-box detection rules that are automatically imported. Review and customize them:

Datadog App > Security > Detection Rules

Out-of-the-box rule categories:
  - AWS: IAM policy changes, root account usage, S3 public access
  - Azure: Suspicious sign-ins, resource group deletions
  - GCP: IAM policy modifications, firewall rule changes
  - Authentication: Brute force, impossible travel, credential stuffing
  - Network: Port scanning, DNS tunneling, C2 beaconing
  - Application: SQL injection attempts, XSS, SSRF patterns

Create a custom detection rule for brute force login detection:

Datadog App > Security > Detection Rules > New Rule

Rule Name: "Brute Force Login Detection - Custom"
Rule Type: Log Detection (Real-time)

Define Search Query:
  source:auth status:error @evt.name:authentication @evt.outcome:failure
  Group By: @usr.id

Set Rule Cases:
  Case 1: When count > 10 in 5 minutes
    Name: "High volume failed logins"
    Severity: HIGH
    Notification: @slack-security-alerts @pagerduty-soc

  Case 2: When count > 50 in 5 minutes
    Name: "Extreme brute force attempt"
    Severity: CRITICAL
    Notification: @slack-security-alerts @pagerduty-soc-critical

Signal Settings:
  Keep signal alive for: 10 minutes
  Maximum signal duration: 24 hours
  Evaluation window: 5 minutes

Create a detection rule for AWS root account usage:

Rule Name: "AWS Root Account Console Login"
Rule Type: Log Detection

Query:
  source:cloudtrail @evt.name:ConsoleLogin @userIdentity.type:Root

Severity: CRITICAL
Notification Message:
  "AWS Root account console login detected from IP {{@network.client.ip}}.
   Account: {{@usr.account_id}}
   Region: {{@cloud.region}}
   MFA Used: {{@additionalEventData.MFAUsed}}"

Tags: attack:initial-access, mitre:T1078
Step 4: Configure Workload Protection (CSM Threats)

Set up runtime threat detection for hosts and containers:

Datadog App > Security > Cloud Security Management > Setup

Enable Workload Protection:
  1. Verify Agent has runtime_security_config.enabled: true
  2. Review default Agent rules (file integrity, process execution)
  3. Customize rules for your environment

Default detection categories:
  - Process Execution: Detect reverse shells, crypto miners, exploitation tools
  - File Integrity: Monitor changes to /etc/passwd, /etc/shadow, SSH keys
  - Network Activity: Detect unexpected outbound connections, DNS tunneling
  - Container Escape: Detect privileged container breakout attempts
  - Kernel Module: Detect rootkit or unauthorized kernel module loading

Create a custom CSM Threats Agent rule to detect unauthorized SSH key modifications:

Datadog App > Security > CSM > Agent Rules > New Agent Rule

Rule Expression:
  open.file.path == "/root/.ssh/authorized_keys" &&
  open.flags & (O_WRONLY | O_RDWR | O_CREAT) > 0 &&
  process.file.name != "sshd"

Rule Name: ssh_key_modification
Description: Detect non-sshd processes modifying root authorized_keys
Tags: attack:persistence, mitre:T1098.004
Step 5: Build Security Dashboards

Create a Cloud SIEM overview dashboard:

Datadog App > Dashboards > New Dashboard > "Security Operations Overview"

Widgets:
  1. Signal Count Over Time (timeseries)
     Query: count:security_signal by {signal.rule.name}
     Display: Line chart, last 24 hours

  2. Top Triggered Rules (top list)
     Query: count:security_signal by {signal.rule.name}.as_count()
     Display: Top 10

  3. Critical Signals (query value)
     Query: count:security_signal{severity:critical}
     Conditional format: Red if > 0

  4. Signals by Source (pie chart)
     Query: count:security_signal by {source}

  5. Geographic Threat Map (geomap)
     Query: count:security_signal by {network.client.geoip.country.name}

  6. Top Targeted Users (top list)
     Query: count:security_signal by {usr.id}

  7. Mean Time to Triage (query value)
     Query: avg:security_signal.triage_time

  8. Open Signals by Severity (table)
     Query: count:security_signal{status:open} by {severity}
Step 6: Configure Notification Workflows

Set up automated notification and response workflows:

Datadog App > Security > Notification Rules

Rule 1: Critical Signal Escalation
  Condition: severity:critical
  Recipients: @pagerduty-soc-critical @slack-security-incidents
  Message: "CRITICAL security signal: {{signal.rule.name}}
            Source: {{signal.attributes.network.client.ip}}
            Target: {{signal.attributes.usr.id}}
            Details: {{signal.message}}"

Rule 2: High Signal SOC Alert
  Condition: severity:high
  Recipients: @slack-security-alerts
  Suppress: After first notification, suppress for 15 minutes

Rule 3: Compliance Violation
  Condition: rule_type:compliance
  Recipients: @slack-compliance-team @jira-compliance-board

Workflow Automation (Datadog Workflows):
  Trigger: Security signal with severity:critical
  Steps:
    1. Enrich signal with threat intelligence lookup
    2. Create Jira incident ticket
    3. Send Slack notification with investigation context
    4. If source is AWS: Trigger Lambda to isolate resource
Step 7: Validate and Tune Detection Coverage

Test detection rules and tune false positives:

bash
# Generate a test security event (failed SSH login)
ssh -o StrictHostKeyChecking=no invalid_user@localhost 2>/dev/null

# Verify the event appears in Datadog Logs
# Datadog App > Logs > source:auth status:error

# Check that a security signal was generated
# Datadog App > Security > Signals > Filter by rule name

# Tune noisy rules by adding suppression queries:
# Datadog App > Security > Detection Rules > [Rule] > Edit
# Add suppression: Suppress signal when @usr.id:service-account-*

Use the Security Signals API to validate programmatically:

python
from datadog_api_client import Configuration, ApiClient
from datadog_api_client.v2.api.security_monitoring_api import SecurityMonitoringApi

configuration = Configuration()
# Reads DD_API_KEY and DD_APP_KEY from environment

with ApiClient(configuration) as api_client:
    api = SecurityMonitoringApi(api_client)
    signals = api.search_security_monitoring_signals(
        body={
            "filter": {
                "query": "status:open severity:critical",
                "from": "now-24h",
                "to": "now",
            },
            "sort": {"field": "timestamp", "order": "desc"},
            "page": {"limit": 25},
        }
    )
    for signal in signals.data:
        attrs = signal.attributes
        print(f"[{attrs.severity}] {attrs.title}")
        print(f"  Rule: {attrs.custom.get('rule', {}).get('name', 'N/A')}")
        print(f"  Time: {attrs.timestamp}")
Show full SKILL.md (301 more words)Show less

Key Concepts

TermDefinition
Cloud SIEMDatadog's security information and event management service that analyzes ingested logs in real-time to detect threats using detection rules
Security SignalAn alert generated when a detection rule matches incoming log data; signals have severity, status (open/triage/closed), and investigation context
Detection RuleA query-based rule that evaluates logs or events against conditions (threshold, anomaly, new value, impossible travel) to generate security signals
CSM (Cloud Security Management)Datadog platform for infrastructure security including Misconfigurations (compliance benchmarks), Threats (runtime detection), and Vulnerabilities
Workload ProtectionCSM Threats component that monitors file, process, and network activity on hosts and containers using eBPF-based Agent rules
Content PackPre-built collection of detection rules, dashboards, and log parsers for a specific integration (AWS, Azure, GCP, Okta, etc.)
Agent RuleA kernel-level rule evaluated by the Datadog Agent on the host to collect security-relevant events before sending to Datadog for threat detection
Suppression QueryA filter applied to a detection rule to prevent signals from being generated for known-good activity (reduces false positives)

Verification

  • Datadog Agent is installed and reporting on all target hosts (datadog-agent status shows security agent running)
  • Security-relevant log sources are ingesting into Datadog (CloudTrail, auth.log, Windows Security Events visible in Log Explorer)
  • Cloud SIEM Content Packs are enabled for all cloud providers in use (AWS, Azure, GCP)
  • Out-of-the-box detection rules are active and generating signals for test events
  • Custom detection rules trigger correctly (test with a simulated failed login burst)
  • Workload Protection (CSM Threats) is enabled and Agent rules are evaluating on hosts
  • Security dashboard displays signal counts, top rules, severity breakdown, and geographic data
  • Notification workflows deliver alerts to Slack, PagerDuty, or Jira for critical and high signals
  • Suppression queries are configured to reduce false positives on noisy rules
  • Security Signals API returns results programmatically for automation integration

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/implementing-security-monitoring-with-datadog of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Implementing Security Monitoring With Datadog next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Implementing Security Monitoring With Datadog compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Implementing Security Monitoring With Datadog this skillmukul975/Anthropic-Cybersecurity-Skills34k—~3.7kAutomated safety check: NotesApache-2.0
Defender For Cloud Hardeningvinayaklatthe/microsoft-security-skills175—~1.9kAutomated safety check: PassMIT
Dd AWS Integrationdatadog-labs/agent-skills177—~6.8kAutomated safety check: NotesMIT
Tsh Implementing ObservabilityTheSoftwareHouse/copilot-collections284—~2kAutomated safety check: PassMIT
Cloud Auditbriiirussell/cybersecurity-skills413—~1.3kAutomated safety check: NotesMIT
Ecs Operation Reviewaws/tools-for-devops-agent103—~4.8kAutomated safety check: PassApache-2.0

Similar skills

  • Defender For Cloud Hardening

    vinayaklatthe/microsoft-security-skills

    Guidance for Microsoft Defender for Cloud — cloud security posture management (CSPM) and cloud workload protection (CWPP) across Azure, AWS, and GCP.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Dd AWS Integration

    datadog-labs/agent-skills

    Set up the Datadog AWS integration with Terraform - creates the cross-account IAM role Datadog assumes (external ID, no stored credentials), attaches the permission policies Datadog publishes, and…

    177 GitHub stars~6.8k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Tsh Implementing Observability

    TheSoftwareHouse/copilot-collections

    Observability patterns for logging, monitoring, alerting, and distributed tracing.

    284 GitHub stars~2k tokensUpdated 6 days ago
    DevOps & CloudAuto-check passed
  • Cloud Audit

    briiirussell/cybersecurity-skills

    Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.

    413 GitHub stars~1.3k tokensUpdated 4 mo ago
    SecurityAuto-check: notes
  • Ecs Operation Review

    aws/tools-for-devops-agent

    Official

    Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs…

    103 GitHub stars~4.8k tokensUpdated yesterday
    SecurityAuto-check passed
  • Iam

    itsmostafa/aws-agent-skills

    AWS Identity and Access Management for users, roles, policies, and permissions.

    1.2k GitHub stars~1.8k tokensUpdated 5 days ago
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Implementing Security Monitoring With Datadog

What does Implementing Security Monitoring With Datadog do?

Implements security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection to detect threats, enforce compliance, and respond to security events across cloud…. Implementing Security Monitoring With Datadog is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Implements security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection to detect threats, enforce compliance, and respond to security events across cloud and hybrid infrastructure.

When should I use Implementing Security Monitoring With Datadog?

Implementing Security Monitoring With Datadog fits situations like: tasks that involve Security operations; tasks that involve Cloud security; tasks that involve Monitoring and alerting.

How do I install Implementing Security Monitoring With Datadog in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-security-monitoring-with-datadog -a claude-code`. Or copy the skill folder (skills/implementing-security-monitoring-with-datadog in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/implementing-security-monitoring-with-datadog in your project. Claude Code loads it when a task matches its description.

How do I install Implementing Security Monitoring With Datadog in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-security-monitoring-with-datadog -a codex`. Or copy the skill folder (skills/implementing-security-monitoring-with-datadog in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/implementing-security-monitoring-with-datadog in your project. Codex loads it when a task matches its description.

Can I use Implementing Security Monitoring With Datadog in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-security-monitoring-with-datadog -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-security-monitoring-with-datadog, .gemini/skills/implementing-security-monitoring-with-datadog, .github/skills/implementing-security-monitoring-with-datadog and .opencode/skills/implementing-security-monitoring-with-datadog in your project.

What does Implementing Security Monitoring With Datadog need to run?

Going by SKILL.md and its folder, Implementing Security Monitoring With Datadog needs Python for the scripts in its folder, the command-line tools its instructions call (aws and ssh) and credentials named DD_API_KEY and DD_APP_KEY. Our summary lists: Python 3; A credential in YOUR_DATADOG_API_KEY; A credential in DD_API_KEY.

Does Implementing Security Monitoring With Datadog access the network?

SKILL.md contains no URLs. Its commands use ssh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Implementing Security Monitoring With Datadog safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Implementing Security Monitoring With Datadog use?

Implementing Security Monitoring With Datadog is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Implementing Security Monitoring With Datadog use?

About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 869 tokens, read only when the agent opens those files.

What are the alternatives to Implementing Security Monitoring With Datadog?

Skills that share tags, products or a category with Implementing Security Monitoring With Datadog: Defender For Cloud Hardening (vinayaklatthe/microsoft-security-skills, 175 stars), Dd AWS Integration (datadog-labs/agent-skills, 177 stars), Tsh Implementing Observability (TheSoftwareHouse/copilot-collections, 284 stars) and Cloud Audit (briiirussell/cybersecurity-skills, 413 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Implementing Security Monitoring With Datadog?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.