Skip to content

feat: cloud audit logs as a second witness, cloud destruction rules and guardrails - #67

Merged
efij merged 1 commit into
mainfrom
feat/cloud-witness
Sep 29, 2026
Merged

efij merged 1 commit into
mainfrom
feat/cloud-witness

Conversation

@efij

@efij efij commented Sep 29, 2026

Copy link
Copy Markdown
Owner

Why

Microsoft's Storm-3168, Sysdig's JADEPUFFER and Sygnia's AI-assisted intrusion show agent-driven attacks going through cloud control planes: lock and backup removal, bulk resource deletion, key listing. The ground truth sat in cloud audit logs, which AgentDFIR could not read.

What

  • Cloud audit logs as a second witness. --endpoint sniffs and reads AWS CloudTrail, Azure Activity Log and GCP Cloud Audit Log exports (JSON, array, JSONL, and the Records/value/records wrappers). Agent az/aws/gcloud commands are CORROBORATED when the control plane recorded the same operation within ±2 min, matched on resource name when the command gives one. Refused calls are noted with the error. Cloud records never contradict and never count as host coverage. Files only.
  • CLOUD_DESTRUCTIVE_BURST (HIGH, from the cloud log): one identity, 10+ distinct deletes in 10 min. Refused calls do not count.
  • Rules: CLOUD_RESOURCE_DELETION (HIGH), CLOUD_RECOVERY_PROTECTION_REMOVED (CRITICAL). CLOUD_CREDENTIAL_EXPORT also covers storage and Cosmos key listing.
  • Guardrail pack cloud-destructive (ask, friction 1) for Claude Code and Codex.
  • hunt: incident storm-3168-jadepuffer; package indicators gain below_version (Langflow < 1.3.0, CVE-2025-3248, low confidence).
  • Authority-claim phrases count as injection on tool content only (tool/MCP results, instruction files, tool definitions, MCP configs, repo files), never on the person's own prompts.
  • Secret formats ALIBABA_ACCESS_KEY, TENCENT_SECRET_ID (tests build key-shaped values at run time, so push protection stays happy).
  • Fix: correlation notes no longer stack when the same log is re-analysed.

Dropped from the plan after checking the code: a tempo verifier over transcripts (every agent retries in seconds, so it would flag everything) and reading GitHub issue edit history (network calls break the local-only design). The latter became guidance in the Protect steps.

Verified

  • go test ./... and go vet ./... green; race on correlate/endpoint.
  • Corpus: new attack reproduction fires all four expected rules; new benign pen-tester session stays at 0 false positives. A mutation check confirmed the benign case fails if the phrase leaks into the user-prompt list.
  • Real binary end to end: collected the reproduction, analyzed with an Azure Activity Log. 3/3 agent commands CORROBORATED, 1 refused noted, 1 burst, re-run keeps one note.
  • hunt --incident storm-3168-jadepuffer --path flags a langflow==1.2.0 pin.
  • mitigate --select cloud-destructive --apply --yes on a scratch home writes 36 Claude ask rules + a Codex rules file; --revert-all restores both byte-exact.

Docs: CHANGELOG, README, site (index.html), llms.txt, endpoint-corroboration, hunt, mitigate, regenerated detection-coverage. No version bump.

Generated with Claude Code

…nd guardrails

Lessons from Microsoft's Storm-3168, Sysdig's JADEPUFFER and Sygnia's
AI-assisted cloud intrusion, built as defender-side capabilities:

- --endpoint reads AWS CloudTrail, Azure Activity Log and GCP Cloud Audit
  Log exports (sniffed). Agent az/aws/gcloud commands are CORROBORATED
  against the control plane's record, refused calls are noted, and a
  cloud log never contradicts a command or counts as host telemetry.
- CLOUD_DESTRUCTIVE_BURST: one identity deleting 10+ resources in 10 min.
- CLOUD_RESOURCE_DELETION and CLOUD_RECOVERY_PROTECTION_REMOVED rules;
  CLOUD_CREDENTIAL_EXPORT covers storage/Cosmos key listing.
- Guardrail pack cloud-destructive (ask, friction 1).
- hunt incident storm-3168-jadepuffer; package indicators gain
  below_version for vulnerable-version ranges.
- Authority-claim phrases match tool content only, never user prompts.
- ALIBABA_ACCESS_KEY and TENCENT_SECRET_ID secret formats.
- Correlation notes no longer stack on re-analysis.

Corpus: one attack reproduction, one benign pen-tester session; false
positives stay at zero.

Co-Authored-By: Claude <noreply@anthropic.com>
@efij
efij merged commit 00dafbe into main Sep 29, 2026
6 checks passed
@efij
efij deleted the feat/cloud-witness branch September 29, 2026 19:04
@efij efij mentioned this pull request Oct 1, 2026
efij added a commit that referenced this pull request Oct 1, 2026
Cloud audit logs as a second witness (#67), delta runs with signed and
proven rounds (#68), and the Cmd/Ctrl+K command palette (#69).

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant