feat: cloud audit logs as a second witness, cloud destruction rules and guardrails - #67
Merged
Merged
Conversation
…nd guardrails Lessons from Microsoft's Storm-3168, Sysdig's JADEPUFFER and Sygnia's AI-assisted cloud intrusion, built as defender-side capabilities: - --endpoint reads AWS CloudTrail, Azure Activity Log and GCP Cloud Audit Log exports (sniffed). Agent az/aws/gcloud commands are CORROBORATED against the control plane's record, refused calls are noted, and a cloud log never contradicts a command or counts as host telemetry. - CLOUD_DESTRUCTIVE_BURST: one identity deleting 10+ resources in 10 min. - CLOUD_RESOURCE_DELETION and CLOUD_RECOVERY_PROTECTION_REMOVED rules; CLOUD_CREDENTIAL_EXPORT covers storage/Cosmos key listing. - Guardrail pack cloud-destructive (ask, friction 1). - hunt incident storm-3168-jadepuffer; package indicators gain below_version for vulnerable-version ranges. - Authority-claim phrases match tool content only, never user prompts. - ALIBABA_ACCESS_KEY and TENCENT_SECRET_ID secret formats. - Correlation notes no longer stack on re-analysis. Corpus: one attack reproduction, one benign pen-tester session; false positives stay at zero. Co-Authored-By: Claude <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Microsoft's Storm-3168, Sysdig's JADEPUFFER and Sygnia's AI-assisted intrusion show agent-driven attacks going through cloud control planes: lock and backup removal, bulk resource deletion, key listing. The ground truth sat in cloud audit logs, which AgentDFIR could not read.
What
--endpointsniffs and reads AWS CloudTrail, Azure Activity Log and GCP Cloud Audit Log exports (JSON, array, JSONL, and the Records/value/records wrappers). Agentaz/aws/gcloudcommands are CORROBORATED when the control plane recorded the same operation within ±2 min, matched on resource name when the command gives one. Refused calls are noted with the error. Cloud records never contradict and never count as host coverage. Files only.CLOUD_DESTRUCTIVE_BURST(HIGH, from the cloud log): one identity, 10+ distinct deletes in 10 min. Refused calls do not count.CLOUD_RESOURCE_DELETION(HIGH),CLOUD_RECOVERY_PROTECTION_REMOVED(CRITICAL).CLOUD_CREDENTIAL_EXPORTalso covers storage and Cosmos key listing.cloud-destructive(ask, friction 1) for Claude Code and Codex.storm-3168-jadepuffer; package indicators gainbelow_version(Langflow < 1.3.0, CVE-2025-3248, low confidence).ALIBABA_ACCESS_KEY,TENCENT_SECRET_ID(tests build key-shaped values at run time, so push protection stays happy).Dropped from the plan after checking the code: a tempo verifier over transcripts (every agent retries in seconds, so it would flag everything) and reading GitHub issue edit history (network calls break the local-only design). The latter became guidance in the Protect steps.
Verified
go test ./...andgo vet ./...green; race on correlate/endpoint.hunt --incident storm-3168-jadepuffer --pathflags alangflow==1.2.0pin.mitigate --select cloud-destructive --apply --yeson a scratch home writes 36 Claude ask rules + a Codex rules file;--revert-allrestores both byte-exact.Docs: CHANGELOG, README, site (index.html), llms.txt, endpoint-corroboration, hunt, mitigate, regenerated detection-coverage. No version bump.
Generated with Claude Code