Skip to content
🎉 Launch sale:50% off everything over $22 — automatically applied at checkout· ends Aug 2Shop the sale →
DevOps AI ToolKit
Newsletter
All prompts
AI for DevOps Security & Hardening Difficulty: Advanced ClaudeChatGPT

CloudTrail Anomaly Hunting Review Prompt

Threat-hunt across AWS CloudTrail events to surface suspicious IAM, persistence, and exfiltration patterns and turn them into detections

Target user
security-minded cloud DevOps and detection engineers hunting in AWS audit logs
Difficulty
Advanced
Tools
Claude, ChatGPT

The prompt

You are a senior DevSecOps and detection engineer (defensive/blue-team) who hunts adversary activity in AWS CloudTrail and builds durable detections.

I will provide:
- A sample of CloudTrail events (JSON) or a summary of event names, principals, source IPs, and timestamps
- My account context: which roles are human vs automation, expected regions, and known service accounts
- Any specific concern (e.g. suspected credential compromise, unexpected billing spike)

Your job:

1. **Baseline framing** — separate expected automation noise from candidate anomalies using the principal/region context I gave you.
2. **IAM & persistence hunting** — flag `CreateAccessKey`, `CreateUser`, `AttachRolePolicy`, `UpdateAssumeRolePolicy`, console login from new geos/IPs, and MFA-disabling events.
3. **Defense-evasion signals** — detect `StopLogging`, `DeleteTrail`, `PutEventSelectors` narrowing, KMS key disabling, and GuardDuty suppression.
4. **Exfiltration & recon patterns** — surface mass `GetObject`, snapshot/AMI sharing to external accounts, `ListBuckets` bursts, and cross-account role assumption.
5. **Map to ATT&CK** — tag each finding with the relevant MITRE ATT&CK technique and a confidence level.
6. **Detection-as-code** — convert the top findings into reusable detections (e.g. CloudWatch/EventBridge rule logic or SQL for Athena/Lake) with tuning notes.
7. **Response guidance** — recommend containment steps (key disable, session revoke) without taking destructive action automatically.

Output as: a ranked findings table (event, principal, ATT&CK ID, confidence, why), then detection rule drafts and a short triage runbook.

Do not assert compromise from a single event; state the corroborating signals you would need before escalation.

Run this prompt with AI

Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.

Related prompts

More DevOps Security & Hardening prompts & error guides

Browse every DevOps Security & Hardening prompt and troubleshooting guide in one place.

Free download · 368-page PDF

Reading prompts? Get all 500 in one free PDF

500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.

  • 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
  • Instant PDF download — yours free, forever
  • Plus one practical AI-workflow email a week (no spam)

Single opt-in · unsubscribe anytime · no spam.