云境护盾

原名:conducting-cloud-incident-response

响应 AWS、Azure 和 GCP 安全事件,通过身份隔离、云原生日志分析、资源隔离及针对临时云基础设施的取证证据获取。适用于 CSPM 告警或审计日志显示云凭证被入侵、未授权 IAM 变更或跨云服务入侵的情况。

分类
开发提效
版本
v1.0.0
作者
弈韬(@ra1nzzz)
下载
1
收藏
0
发布
2026-08-18
更新
2026-08-25
TRACE 评分
3.6 / 5

内容概览

- Cloud security posture management (CSPM) alerts on unauthorized resource changes - CloudTrail, Azure Activity Logs, or GCP Audit Logs show suspicious API calls - Cloud access keys or service principal credentials are suspected compromised - Unauthorized compute instances, storage buckets, or IAM changes are detected - A cloud-hosted application is breached and attacker activity spans cloud services Do not use for on-premises-only incidents with no cloud component; use standard enterprise IR procedures. - Cloud-native logging enabled and centralized: AWS CloudTrail (all regions), Azure Activity/Sign-in Logs, GCP Cloud Audit Logs - IR-specific cloud IAM roles pre-provisioned with read-only forensic access - Isolated forensic account/subscription/project for evidence preservation - Cloud incident response runbooks specific to each cloud provider - Cloud-native security tools: AWS GuardDut…

查看 SKILL 详情