mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-08-02 00:57:42 +03:00
Add folder anatomy (scripts/agent.py + references/api-reference.md) for 648 cybersecurity skills
Complete skill folder anatomy across all cybersecurity skills: - scripts/agent.py: 80-150 line Python agents using real libraries (impacket, boto3, azure-mgmt-*, kubernetes, pefile, yara, scapy, shodan, stix2, etc.) - references/api-reference.md: real API documentation with method signatures - LICENSE: MIT license for all skill folders
This commit is contained in:
@@ -0,0 +1,54 @@
|
||||
# API Reference: Analyzing Azure Activity Logs for Threats
|
||||
|
||||
## azure-monitor-query
|
||||
|
||||
```python
|
||||
from azure.identity import DefaultAzureCredential
|
||||
from azure.monitor.query import LogsQueryClient, LogsQueryStatus
|
||||
from datetime import timedelta
|
||||
|
||||
credential = DefaultAzureCredential()
|
||||
client = LogsQueryClient(credential)
|
||||
|
||||
response = client.query_workspace(
|
||||
workspace_id="WORKSPACE_ID",
|
||||
query="AzureActivity | take 10",
|
||||
timespan=timedelta(hours=24),
|
||||
)
|
||||
if response.status == LogsQueryStatus.SUCCESS:
|
||||
for table in response.tables:
|
||||
columns = [col.name for col in table.columns]
|
||||
for row in table.rows:
|
||||
print(dict(zip(columns, row)))
|
||||
```
|
||||
|
||||
## Key Azure Log Tables
|
||||
|
||||
| Table | Content |
|
||||
|-------|---------|
|
||||
| `AzureActivity` | Control plane operations (ARM) |
|
||||
| `SigninLogs` | Azure AD sign-in events |
|
||||
| `AuditLogs` | Azure AD audit trail |
|
||||
| `AzureDiagnostics` | Resource diagnostics (Key Vault, NSG) |
|
||||
| `SecurityAlert` | Defender for Cloud alerts |
|
||||
|
||||
## Threat Detection KQL Patterns
|
||||
|
||||
```kql
|
||||
// Privilege escalation
|
||||
AzureActivity | where OperationNameValue has "ROLEASSIGNMENTS/WRITE"
|
||||
|
||||
// Impossible travel
|
||||
SigninLogs | where ResultType == 0
|
||||
| extend Distance = geo_distance_2points(...)
|
||||
|
||||
// Mass deletion
|
||||
AzureActivity | where OperationNameValue endswith "/DELETE"
|
||||
| summarize count() by Caller, bin(TimeGenerated, 1h)
|
||||
```
|
||||
|
||||
### References
|
||||
|
||||
- azure-monitor-query: https://pypi.org/project/azure-monitor-query/
|
||||
- KQL reference: https://learn.microsoft.com/en-us/azure/data-explorer/kusto/query/
|
||||
- Azure Activity Log schema: https://learn.microsoft.com/en-us/azure/azure-monitor/essentials/activity-log-schema
|
||||
Reference in New Issue
Block a user