investigating-aws-incidents

investigating-aws-incidents is a skill for Claude Code, Codex from EvilFreelancer/secs. It costs 101 tokens per session (1,538 once invoked), scanned A, original, Apache-2.0.

An investigation of a suspected compromise in Amazon Web Services (AWS), a cloud platform, using records of actions made through its control plane. It reconstructs events from CloudTrail, GuardDuty, network-flow, and CloudWatch data.

In plain words
What is it for?
Use it to trace stolen identities and role assumptions, investigate access to storage and other services, find persistence or log tampering, and build an incident timeline.
Why use it?
Cloud activity such as role use, data access, persistence, and changes to logging often appears in API records rather than on a local disk. Preserving those records first helps reveal what happened and whether an attacker altered logging.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one. Also seen: installed under .agents/ (shared by several agents); mentions AGENTS.md.

Good fit Use it to trace stolen identities and role assumptions, investigate access to storage and other services, find persistence or log tampering, and build an incident timeline.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/evilfreelancer/secs/investigating-aws-incidents
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add EvilFreelancer/secs --skill investigating-aws-incidents
Clone the repo
git clone --depth 1 https://github.com/EvilFreelancer/secs

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for investigating-aws-incidents

README.md
[![agentmods](https://agentmods.dev/badge/skills/evilfreelancer/secs/investigating-aws-incidents/github.svg)](https://agentmods.dev/skills/evilfreelancer/secs/investigating-aws-incidents)
Your own site
<a href="https://agentmods.dev/skills/evilfreelancer/secs/investigating-aws-incidents"><img src="https://agentmods.dev/badge/skills/evilfreelancer/secs/investigating-aws-incidents/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for investigating-aws-incidents

Your own site · 80×15
<a href="https://agentmods.dev/skills/evilfreelancer/secs/investigating-aws-incidents"><img src="https://agentmods.dev/badge/skills/evilfreelancer/secs/investigating-aws-incidents.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 101 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,538 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00101 $0.01538
Opus 5 $0.00051 $0.00769
Sonnet 5 $0.00020 $0.00308
Haiku 4.5 $0.00010 $0.00154

Measured 12d ago against content hash b18adde550bc, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade A, and why

investigating-aws-incidents scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.agents/skills/investigating-aws-incidents/SKILL.md · 114 lines

How it starts

The opening of the file, as written. The whole thing — 114 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Investigating AWS Incidents

In AWS the crime scene is the API log, not the disk. Almost every action — assuming a role, minting an access key, reading a bucket, turning off the trail — is a CloudTrail event with an identity, a source IP, a user agent, and a timestamp. The investigator reconstructs the intrusion from that record. The urgency is that the record is itself a target: an attacker who reaches the logging configuration can stop the trail or shorten retention, so preservation comes before analysis.

Confirm the account is in scope per AGENTS.md, and treat findings as sensitive cloud data kept in the engagement store. This skill is read-only investigation; containment actions (revoking keys, isolating a role) are the operator's call and belong to the wider incident.

When to Use

  • A suspected AWS compromise where the evidence is control-plane logs
  • Tracing IAM/STS abuse: AssumeRole chains, new users/keys, console logins
  • Confirming data access or exfiltration from S3 and other services
  • Finding cloud persistence (new principals, trust-policy edits) and log tampering
  • Building an AWS attack timeline for an incident

When NOT to Use

  • On-host artifacts of an EC2 instance — use investigating-windows-endpoints (or acquire the disk/memory); this skill is the control plane
  • Azure or GCP — use investigating-azure-incidents or investigating-gcp-incidents
  • Proactive search with no incident yet — use hunting-threats
  • Offensive cloud testing — use exploiting-cloud-platforms
  • Proactive hardening — use hardening-cloud-posture
  • Running the whole incident — use responding-to-incidents
  • Packaging IOCs into a product — use producing-threat-intelligence

Preserve First

Copy the relevant CloudTrail logs out of the account (or into a forensics/logging account) and snapshot affected EBS volumes before anything can be altered. Confirm whether CloudTrail log-file validation is on. If a StopLogging or DeleteTrail appears in the timeline, note the gap it created — absence of events after that point is evidence, not all-clear.

Read the full file on GitHub · 114 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 12d ago First seen · 114 lines · 101 tokens per session scan A b18adde550bc

Subscribe to this mod's changes

investigating-aws-incidents is a skill published in the GitHub repository EvilFreelancer/secs (10 stars, last pushed 1mo ago), licensed Apache-2.0. It adds 101 tokens to every session and 1,538 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

auditing-gcp-iam-permissions

Auditing Google Cloud Platform IAM permissions to identify overly permissive bindings, primitive role usage, service account key proliferation, and cross-project access risks using gcloud CLI, Policy Analyzer, and IAM Recommender.

26zl/cybersec-toolkit · 51 tokens

configuring-identity-aware-proxy-with-google-iap

Configuring Google Cloud Identity-Aware Proxy (IAP) to enforce per-request identity verification for Compute Engine, App Engine, Cloud Run, and GKE services using access levels, context-aware policies, and programmatic access with service accounts.

26zl/cybersec-toolkit · 60 tokens

building-red-team-c2-infrastructure-with-havoc

Deploy and configure the Havoc C2 framework with teamserver, HTTPS listeners, redirectors, and Demon agents for authorized red team operations.

26zl/cybersec-toolkit · 40 tokens

configuring-pfsense-firewall-rules

Configures pfSense firewall rules, NAT policies, VPN tunnels, and traffic shaping to enforce network segmentation, control traffic flow, and protect internal network zones in enterprise and small-to-medium business environments.

26zl/cybersec-toolkit · 49 tokens

deploying-palo-alto-prisma-access-zero-trust

Deploying Palo Alto Networks Prisma Access for SASE-based zero trust network access using GlobalProtect agents, ZTNA Connectors, security policy enforcement, and integration with Strata Cloud Manager for unified security management.

26zl/cybersec-toolkit · 55 tokens

conducting-cloud-penetration-testing

This skill outlines methodologies for performing authorized penetration testing against AWS, Azure, and GCP cloud environments. It covers understanding the shared responsibility model for testing scope, leveraging cloud-specific attack tools like Pacu and ScoutSuite, exploiting IAM misconfigurations, testing for SSRF…

26zl/cybersec-toolkit · 79 tokens