Produce a complete inventory of the AWS services and resources in a scanned account, with counts and extent, using the CloudLedger server. Use when the user asks what services an account uses, how many of a resource there are, what is running in an account, or wants a resource inventory or service-usage breakdown of…
Analyse plausible attack paths to compromise a scanned AWS account and explain them against the MITRE ATT&CK framework, using the CloudLedger server. Use when the user wants an attack-path analysis, threat modelling, MITRE ATT&CK mapping, adversary/red-team perspective, "how could this account be compromised", or the…
Analyse AWS spend for scanned accounts — cost breakdown by service and account, trends over time, and a forward forecast — using the CloudLedger server. Use when the user asks what an account costs, which services or accounts drive spend, how costs are trending, or wants a cost breakdown, cost report, or spend…
Produce a scored security assessment report of a scanned AWS account using the CloudLedger server. Use when the user wants to assess, score, grade, or report on the security posture of an AWS account that has been scanned, or asks for a security assessment, security report, or exposure review of scan data. Requires…
Perform a complete review of every security group in a scanned AWS account and explain each group's exposure and implications, using the CloudLedger server. Use when the user wants a security group audit, a firewall review, to understand what a security group allows or exposes, which groups are overly permissive, or…
Guide to choosing the right CloudLedger tools and task skills for a given question. Use when unsure which of the scanner's many tools to call, when a question spans several tools, or to route a request to the correct specialised skill (assessment, inventory, cost, security groups, attack paths). Requires the…