Ak Cloud Deploy
yaalalabs/agent-kernel
Deploy an Agent Kernel project to AWS, Azure, or GCP using Terraform modules, or to any Kubernetes cluster (on-prem, baremetal, EKS) using the official Helm chart.
Agent skill
Collect and analyze cloud forensic evidence using AWS CLI, Azure CLI, or gcloud to snapshot volumes, capture instance metadata and security group configurations, and preserve cloud-native logs…
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-cloud-forensics-investigation -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-cloud-forensics-investigation --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/performing-cloud-forensics-investigation .claude/skills/performing-cloud-forensics-investigation && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "performing-cloud-forensics-investigation" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-cloud-forensics-investigation into .claude/skills/performing-cloud-forensics-investigation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-cloud-forensics-investigation", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-cloud-forensics-investigationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-cloud-forensics-investigation -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-cloud-forensics-investigation --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/performing-cloud-forensics-investigation .agents/skills/performing-cloud-forensics-investigation && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "performing-cloud-forensics-investigation" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-cloud-forensics-investigation into .agents/skills/performing-cloud-forensics-investigation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-cloud-forensics-investigation", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-cloud-forensics-investigation -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-cloud-forensics-investigation --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/performing-cloud-forensics-investigation .cursor/skills/performing-cloud-forensics-investigation && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "performing-cloud-forensics-investigation" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-cloud-forensics-investigation into .cursor/skills/performing-cloud-forensics-investigation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-cloud-forensics-investigation", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git --path skills/performing-cloud-forensics-investigation--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-cloud-forensics-investigation -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-cloud-forensics-investigation --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/performing-cloud-forensics-investigation .gemini/skills/performing-cloud-forensics-investigation && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "performing-cloud-forensics-investigation" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-cloud-forensics-investigation into .gemini/skills/performing-cloud-forensics-investigation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-cloud-forensics-investigation", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-cloud-forensics-investigationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-cloud-forensics-investigation -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/performing-cloud-forensics-investigation .github/skills/performing-cloud-forensics-investigation && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "performing-cloud-forensics-investigation" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-cloud-forensics-investigation into .github/skills/performing-cloud-forensics-investigation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-cloud-forensics-investigation", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-cloud-forensics-investigation -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-cloud-forensics-investigation --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/performing-cloud-forensics-investigation .opencode/skills/performing-cloud-forensics-investigation && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "performing-cloud-forensics-investigation" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-cloud-forensics-investigation into .opencode/skills/performing-cloud-forensics-investigation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-cloud-forensics-investigation", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
performing-cloud-forensics-investigationCollect and analyze cloud forensic evidence using AWS CLI, Azure CLI, or gcloud to snapshot volumes, capture instance metadata and security group configurations, and preserve cloud-native logs…
Performing Cloud Forensics Investigation is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Collect and analyze cloud forensic evidence using AWS CLI, Azure CLI, or gcloud to snapshot volumes, capture instance metadata and security group configurations, and preserve cloud-native logs (CloudTrail, Activity Log, Audit Log). Use when investigating a suspected breach in AWS, Azure, or GCP, tracing unauthorized access through API logs, or analyzing a compromised VM, container, or serverless function.
Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).
It sits in Backend & APIs, covering Serverless and Digital forensics. It works with Amazon Web Services, Google Cloud and Microsoft Azure. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
awsazgcloudpython3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use aws, az and gcloud, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Performing Cloud Forensics Investigation loads about 3.4k tokens when it runs, and up to ~4.1k if it reads all its reference files. Until then it costs about 112 tokens; SKILL.md has 486 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
sudo mount -o ro /dev/xvdf1 /mnt/evidenceAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 486 words, ~3,438 tokens.
.claude/skills/performing-cloud-forensics-investigation/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.# === AWS Evidence Preservation ===
# Snapshot compromised EC2 instance volumes
INSTANCE_ID="i-0abc123def456789"
VOLUME_IDS=$(aws ec2 describe-instances --instance-ids $INSTANCE_ID \
--query 'Reservations[].Instances[].BlockDeviceMappings[].Ebs.VolumeId' --output text)
for vol in $VOLUME_IDS; do
aws ec2 create-snapshot --volume-id $vol \
--description "Forensic snapshot - Case 2024-001 - $(date -u)" \
--tag-specifications "ResourceType=snapshot,Tags=[{Key=Case,Value=2024-001},{Key=Evidence,Value=true}]"
done
# Capture instance metadata
aws ec2 describe-instances --instance-ids $INSTANCE_ID \
> /cases/case-2024-001/cloud/instance_metadata.json
# Capture security group rules
aws ec2 describe-security-groups --group-ids $(aws ec2 describe-instances \
--instance-ids $INSTANCE_ID --query 'Reservations[].Instances[].SecurityGroups[].GroupId' --output text) \
> /cases/case-2024-001/cloud/security_groups.json
# Capture network interfaces
aws ec2 describe-network-interfaces --filters "Name=attachment.instance-id,Values=$INSTANCE_ID" \
> /cases/case-2024-001/cloud/network_interfaces.json
# Isolate the instance (replace security group with forensic isolation SG)
aws ec2 modify-instance-attribute --instance-id $INSTANCE_ID \
--groups sg-forensic-isolation
# === Azure Evidence Preservation ===
# Snapshot a compromised VM disk
az snapshot create --resource-group forensics-rg \
--name "case-2024-001-osdisk-snapshot" \
--source "/subscriptions/SUB_ID/resourceGroups/RG/providers/Microsoft.Compute/disks/vm-osdisk"
# === GCP Evidence Preservation ===
gcloud compute disks snapshot compromised-disk \
--snapshot-names="case-2024-001-forensic" \
--zone=us-central1-a# === AWS CloudTrail Logs ===
# Download CloudTrail events for the investigation period
aws cloudtrail lookup-events \
--start-time "2024-01-15T00:00:00Z" \
--end-time "2024-01-20T23:59:59Z" \
--max-results 1000 \
> /cases/case-2024-001/cloud/cloudtrail_events.json
# Filter for specific user activity
aws cloudtrail lookup-events \
--lookup-attributes AttributeKey=Username,AttributeValue=compromised-user \
--start-time "2024-01-15T00:00:00Z" \
> /cases/case-2024-001/cloud/user_activity.json
# Download S3 access logs
aws s3 sync s3://my-cloudtrail-bucket/AWSLogs/ /cases/case-2024-001/cloud/cloudtrail_s3/
# Query CloudTrail with Athena for large-scale analysis
aws athena start-query-execution \
--query-string "SELECT eventTime, eventName, userIdentity.arn, sourceIPAddress, errorCode
FROM cloudtrail_logs
WHERE eventTime BETWEEN '2024-01-15' AND '2024-01-20'
AND sourceIPAddress NOT IN ('10.0.0.0/8')
ORDER BY eventTime" \
--result-configuration OutputLocation=s3://forensics-bucket/athena-results/
# === AWS VPC Flow Logs ===
aws logs filter-log-events \
--log-group-name "vpc-flow-logs" \
--start-time $(date -d "2024-01-15" +%s000) \
--end-time $(date -d "2024-01-20" +%s000) \
--filter-pattern "ACCEPT" \
> /cases/case-2024-001/cloud/vpc_flow_logs.json
# === Azure Activity Log ===
az monitor activity-log list \
--start-time "2024-01-15T00:00:00Z" \
--end-time "2024-01-20T23:59:59Z" \
--output json > /cases/case-2024-001/cloud/azure_activity.json
# === GCP Audit Logs ===
gcloud logging read 'logName="projects/PROJECT_ID/logs/cloudaudit.googleapis.com%2Factivity"
AND timestamp>="2024-01-15T00:00:00Z"
AND timestamp<="2024-01-20T23:59:59Z"' \
--format=json > /cases/case-2024-001/cloud/gcp_audit.json# Analyze compromised credentials usage
python3 << 'PYEOF'
import json
from collections import defaultdict
with open('/cases/case-2024-001/cloud/cloudtrail_events.json') as f:
data = json.load(f)
# Analyze by source IP
ip_events = defaultdict(list)
error_events = []
critical_actions = []
for event in data.get('Events', []):
ct = json.loads(event.get('CloudTrailEvent', '{}'))
source_ip = ct.get('sourceIPAddress', 'Unknown')
event_name = ct.get('eventName', 'Unknown')
user_arn = ct.get('userIdentity', {}).get('arn', 'Unknown')
error = ct.get('errorCode')
timestamp = ct.get('eventTime', '')
ip_events[source_ip].append(event_name)
if error:
error_events.append({'time': timestamp, 'action': event_name, 'error': error, 'ip': source_ip})
# Flag critical actions
critical = ['CreateUser', 'CreateAccessKey', 'AttachUserPolicy', 'CreateRole',
'PutBucketPolicy', 'StopLogging', 'DeleteTrail', 'CreateKeyPair',
'RunInstances', 'AuthorizeSecurityGroupIngress']
if event_name in critical:
critical_actions.append({'time': timestamp, 'action': event_name, 'user': user_arn, 'ip': source_ip})
print("=== SOURCE IP ANALYSIS ===")
for ip, events in sorted(ip_events.items(), key=lambda x: len(x[1]), reverse=True):
print(f" {ip}: {len(events)} events ({len(set(events))} unique actions)")
print(f"\n=== ACCESS ERRORS ({len(error_events)} total) ===")
for e in error_events[:10]:
print(f" [{e['time']}] {e['action']} -> {e['error']} from {e['ip']}")
print(f"\n=== CRITICAL ACTIONS ({len(critical_actions)} total) ===")
for a in critical_actions:
print(f" [{a['time']}] {a['action']} by {a['user']} from {a['ip']}")
PYEOF# Create a forensic analysis instance from the snapshot
SNAPSHOT_ID="snap-0abc123def456789"
# Create volume from snapshot in isolated forensic VPC
FORENSIC_VOL=$(aws ec2 create-volume --snapshot-id $SNAPSHOT_ID \
--availability-zone us-east-1a \
--tag-specifications "ResourceType=volume,Tags=[{Key=Case,Value=2024-001}]" \
--query 'VolumeId' --output text)
# Attach to forensic analysis instance (read-only mount)
aws ec2 attach-volume --volume-id $FORENSIC_VOL \
--instance-id i-forensic-workstation \
--device /dev/xvdf
# On the forensic instance, mount read-only
sudo mount -o ro /dev/xvdf1 /mnt/evidence
# Perform standard disk forensics on the mounted volume
# Extract logs, analyze file system, check for persistence
ls /mnt/evidence/var/log/
cp -r /mnt/evidence/var/log/ /cases/case-2024-001/cloud/vm_logs/
cp -r /mnt/evidence/etc/crontab /cases/case-2024-001/cloud/persistence/
cp -r /mnt/evidence/home/*/.ssh/ /cases/case-2024-001/cloud/ssh_keys/
cp -r /mnt/evidence/home/*/.bash_history /cases/case-2024-001/cloud/bash_history/# Compile findings into structured report
python3 << 'PYEOF'
report = """
CLOUD FORENSICS INVESTIGATION REPORT
======================================
Case: 2024-001
Cloud Provider: AWS (Account: 123456789012)
Region: us-east-1
Investigation Period: 2024-01-15 to 2024-01-20
EVIDENCE PRESERVED:
- EC2 Instance Snapshot: snap-0abc123def456789 (i-0abc123def456789)
- CloudTrail Logs: 2024-01-15 to 2024-01-20
- VPC Flow Logs: 2024-01-15 to 2024-01-20
- Instance Metadata: captured and hashed
- Security Group Configuration: captured at time of isolation
FINDINGS:
1. Initial Access:
- Compromised IAM access key AKIA... used from IP 203.0.113.45
- First unauthorized API call: 2024-01-15 14:32:00 UTC
- IP geolocation: Foreign jurisdiction (not company IP range)
2. Persistence:
- New IAM user 'backup-admin' created with AdministratorAccess
- New access key pair generated for backup-admin
- SSH key added to EC2 instance authorized_keys
3. Lateral Movement:
- S3 bucket policies modified to allow public access
- Security group rules modified to allow SSH from 0.0.0.0/0
- 3 additional EC2 instances launched for crypto-mining
4. Data Exfiltration:
- S3 bucket 'company-confidential' accessed 234 times
- 12 GB of data downloaded via GetObject API calls
- Data transferred to external IP 185.x.x.x
5. Anti-Forensics:
- CloudTrail logging disabled at 2024-01-18 03:00 UTC
- CloudWatch log groups deleted
RECOMMENDATIONS:
- Rotate all IAM credentials immediately
- Enable MFA on all accounts
- Restore CloudTrail logging
- Review and restrict S3 bucket policies
- Implement GuardDuty for continuous monitoring
"""
with open('/cases/case-2024-001/cloud/cloud_forensics_report.txt', 'w') as f:
f.write(report)
print(report)
PYEOF| Concept | Description |
|---|---|
| Cloud API logging | Service logs recording all API calls (CloudTrail, Activity Log, Audit Log) |
| Volume snapshots | Point-in-time copies of cloud disk volumes for forensic preservation |
| VPC Flow Logs | Network traffic metadata logs showing source, destination, and action |
| IAM credential compromise | Unauthorized use of access keys, tokens, or assumed roles |
| Instance metadata | EC2/VM configuration data including network, storage, and security settings |
| Shared responsibility | Cloud provider secures infrastructure; customer secures data and access |
| Evidence volatility | Cloud resources can be terminated; evidence must be preserved quickly |
| Multi-region artifacts | Attacks may span regions requiring cross-region log collection |
| Tool | Purpose |
|---|---|
| AWS CLI | Command-line interface for AWS service interaction and log collection |
| CloudTrail | AWS API call logging service for investigation and auditing |
| Azure Monitor | Azure logging and diagnostics platform |
| GCP Cloud Logging | Google Cloud audit and access logging service |
| Athena | AWS serverless SQL query service for analyzing CloudTrail logs at scale |
| Prowler | Open-source AWS security assessment and forensic collection tool |
| ScoutSuite | Multi-cloud security auditing tool |
| CADO Response | Cloud-native digital forensics and incident response platform |
Scenario 1: Compromised IAM Access Keys Identify the compromised key in CloudTrail, trace all API calls made with the key, determine the source IPs and actions taken, check for persistence mechanisms (new users, roles, keys), revoke the compromised credentials, assess data access scope.
Scenario 2: Cryptojacking on EC2 Instances Detect unauthorized instance launches in CloudTrail, snapshot the mining instances for analysis, examine security group changes that allowed C2 communication, identify the initial access vector (stolen keys, SSRF), calculate resource costs incurred.
Scenario 3: S3 Data Breach Analyze S3 access logs and CloudTrail for GetObject/PutBucketPolicy events, identify who modified bucket policies to allow public access, determine the scope of data exposure, check for data downloads from unauthorized IPs, assess regulatory reporting requirements.
Scenario 4: Container Escape in EKS/AKS/GKE Collect Kubernetes audit logs and cloud provider logs, analyze pod creation events for privilege escalation attempts, examine node-level logs for container escape evidence, check for unauthorized access to cloud metadata service (169.254.169.254), trace lateral movement to cloud APIs.
Cloud Forensics Summary:
Cloud: AWS (us-east-1) Account: 123456789012
Investigation: 2024-01-15 to 2024-01-20
Incident Type: IAM Credential Compromise + Data Exfiltration
Evidence Collected:
EBS Snapshots: 3 volumes preserved
CloudTrail Events: 12,456 (1,234 from attacker IP)
VPC Flow Logs: 45,678 records
S3 Access Logs: 2,345 entries
Attack Timeline:
2024-01-15 14:32 - Compromised access key first used from 203.0.113.45
2024-01-15 14:45 - New IAM user created with admin privileges
2024-01-16 02:00 - S3 bucket policy modified (public access enabled)
2024-01-16 03:00 - 12 GB downloaded from company-confidential bucket
2024-01-18 03:00 - CloudTrail logging disabled
Impact Assessment:
Data Exposed: 12 GB from 3 S3 buckets
Resources Created: 3 EC2 instances (crypto mining)
Estimated Cost: $4,500 in unauthorized compute© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (scripts, references) in skills/performing-cloud-forensics-investigation of mukul975/Anthropic-Cybersecurity-Skills.
Open the folder on GitHubat commit 54a7988
Performing Cloud Forensics Investigation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Performing Cloud Forensics Investigation this skillmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.4k | Automated safety check: Notes | Apache-2.0 | |
| Ak Cloud Deployyaalalabs/agent-kernel | 192 | — | ~14k | Automated safety check: Pass | Apache-2.0 | |
| Investigating GCP Incidentstrilwu/secskills | 157 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Cloud AuditCommonHuman-Lab/nyxstrike | 157 | — | ~1.1k | Automated safety check: Pass | Custom licence | |
| Cloud Auditbriiirussell/cybersecurity-skills | 413 | — | ~1.3k | Automated safety check: Notes | MIT | |
| Provider API Call Dedupmondoohq/mql | 412 | — | ~7.7k | Automated safety check: Pass | Custom licence |
yaalalabs/agent-kernel
Deploy an Agent Kernel project to AWS, Azure, or GCP using Terraform modules, or to any Kubernetes cluster (on-prem, baremetal, EKS) using the official Helm chart.
trilwu/secskills
Investigate a security incident in Google Cloud — establishing what audit logging exists before trusting a gap, reconstructing activity from Cloud Audit Logs, triaging service-account and OAuth…
CommonHuman-Lab/nyxstrike
Cloud and container security auditing workflow using prowler, trivy, kube-hunter, and docker-bench for AWS, GCP, Azure, Kubernetes, and container images
briiirussell/cybersecurity-skills
Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.
mondoohq/mql
A skill your agent uses when a provider scan is slow, times out, or trips rate limits (429, throttling, Retry-After), when the same request URL appears many times in a debug log, when an asset's…
criptogus/agent-evolve-network
Audits AWS, GCP and Azure environments (and matching IaC) for excessive permissions, public exposure, weak encryption defaults and missing logging.
mukul975/Anthropic-Cybersecurity-Skills
Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.
mukul975/Anthropic-Cybersecurity-Skills
Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.
mukul975/Anthropic-Cybersecurity-Skills
Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.
mukul975/Anthropic-Cybersecurity-Skills
Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.
mukul975/Anthropic-Cybersecurity-Skills
Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.
mukul975/Anthropic-Cybersecurity-Skills
Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.
Categories
Collect and analyze cloud forensic evidence using AWS CLI, Azure CLI, or gcloud to snapshot volumes, capture instance metadata and security group configurations, and preserve cloud-native logs…. Performing Cloud Forensics Investigation is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Collect and analyze cloud forensic evidence using AWS CLI, Azure CLI, or gcloud to snapshot volumes, capture instance metadata and security group configurations, and preserve cloud-native logs (CloudTrail, Activity Log, Audit Log).
Performing Cloud Forensics Investigation fits situations like: investigating a suspected breach in AWS; tracing unauthorized access through API logs; analyzing a compromised VM; serverless function.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-cloud-forensics-investigation -a claude-code`. Or copy the skill folder (skills/performing-cloud-forensics-investigation in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/performing-cloud-forensics-investigation in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-cloud-forensics-investigation -a codex`. Or copy the skill folder (skills/performing-cloud-forensics-investigation in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/performing-cloud-forensics-investigation in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-cloud-forensics-investigation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/performing-cloud-forensics-investigation, .gemini/skills/performing-cloud-forensics-investigation, .github/skills/performing-cloud-forensics-investigation and .opencode/skills/performing-cloud-forensics-investigation in your project.
Going by SKILL.md and its folder, Performing Cloud Forensics Investigation needs Python for the scripts in its folder and the command-line tools its instructions call (aws, az, gcloud and python3). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Performing Cloud Forensics Investigation is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 621 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Performing Cloud Forensics Investigation: Ak Cloud Deploy (yaalalabs/agent-kernel, 192 stars), Investigating GCP Incidents (trilwu/secskills, 157 stars), Cloud Audit (CommonHuman-Lab/nyxstrike, 157 stars) and Cloud Audit (briiirussell/cybersecurity-skills, 413 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,993 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.
Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.