cloud-defense
Maps attacker post-compromise stages to detection signals and preventive security controls for major cloud providers.
Install
mkdir -p .claude/skills/cloud-defense && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/19505" && unzip -o skill.zip -d .claude/skills/cloud-defense && rm skill.zipInstalls to .claude/skills/cloud-defense
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Detect and break the cloud post-compromise attack chain (AWS / Azure / GCP) — per-stage CloudTrail / Activity-Log / Audit-Log detection signals and the preventive controls that close each step. Use for cloud detection engineering, hardening, remediation write-ups, or blue-team posture review of the lateral-movement -> privilege-escalation -> exfiltration -> evasion chain.Key capabilities
- →Map cloud attack stages to detection signals
- →Identify preventive controls for cloud hardening
- →Draft remediation steps for security reports
- →Review cloud account posture against attack chains
How it works
It maps specific attacker stages like lateral movement or privilege escalation to corresponding cloud audit log events and provides the specific preventive control required to break that stage.
Inputs & outputs
When to use cloud-defense
- →Review cloud account security posture
- →Identify audit log signals for lateral movement
- →Apply hardening controls to AWS/Azure/GCP
- →Draft remediation reports for pentests
About this skill
Cloud Defense
The blue-team counterpart to cloud-containers. For each attacker move — lateral movement, privilege escalation, data exfiltration, defense evasion — this skill gives the log event to alert on and the single control that removes the technique. Use it to turn an offensive cloud finding into a concrete detection and remediation.
When to use
- Writing the remediation / hardening section of a cloud pentest report.
- Cloud detection engineering: deciding which control-plane events to alert on.
- Reviewing an AWS / Azure / GCP account's posture against the post-compromise chain.
Workflow
- Confirm the logging prerequisites are in place (org-wide trail, data events, threat detection on) — without them the signals below are invisible.
- Map each attacker stage to its detection signal — see reference/detection-signals.md.
- Apply the preventive control that breaks each stage — see reference/hardening-controls.md.
- Re-run the matching offensive technique from
cloud-containersto confirm the control holds or the alert fires.
References
- reference/INDEX.md — router
- reference/detection-signals.md — per-stage log signals + logging prerequisites
- reference/hardening-controls.md — the control that breaks each stage
When not to use it
- →When logging prerequisites like org-wide trails are missing
- →When the environment is not AWS, Azure, or GCP
Prerequisites
Limitations
- →Signals are invisible without logging prerequisites
- →Limited to AWS, Azure, and GCP
How it compares
This skill provides a direct mapping between offensive cloud techniques and specific defensive controls, rather than generic security advice.
Compared to similar skills
cloud-defense side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| cloud-defense (this skill) | 0 | 21d | No flags | Intermediate |
| cloud-penetration-testing | 3 | 6mo | Review | Advanced |
| building-cloud-siem-with-sentinel | 0 | 1mo | Review | Advanced |
| azure-cloud-security-review | 0 | 3mo | Review | Advanced |
Try saying
Example prompts that trigger this skill in your AI assistant.
You might also like
cloud-penetration-testing
davila7
This skill should be used when the user asks to "perform cloud penetration testing", "assess Azure or AWS or GCP security", "enumerate cloud resources", "exploit cloud misconfigurations", "test O365 security", "extract secrets from cloud environments", or "audit cloud infrastructure". It provides comprehensive techniques for security assessment across major cloud platforms.
building-cloud-siem-with-sentinel
26zl
This skill covers deploying Microsoft Sentinel as a cloud-native SIEM
azure-cloud-security-review
shyamagu-ms
>
cloud-iam-deep
elementalsouls
Cloud IAM red-team attack chain across AWS, Azure, GCP — focused on EXTERNAL exploitation paths and post-credential-discovery privilege analysis. Covers IAM enumeration (aws iam, az role, gcloud iam), STS/AssumeRole chaining, Azure Managed Identity abuse (via SSRF/leak), GCP service account JSON abu
cloud-security-audit
Ed1s0nZ
云安全审计的专业技能和方法论
performing-cloud-forensics-investigation
yanacuti1121
Conduct forensic investigations in cloud environments by collecting and