cloudtrail_find_anomalies
Detect security anomalies in CloudTrail logs by identifying non-AWS IP addresses, unusual API calls, role assumptions, and data exfiltration indicators through automated log analysis.
Instructions
Find anomalies in CloudTrail logs: non-AWS IPs, unusual API calls, role assumptions.
Returns: {"non_aws_ips": [str], "unusual_events": [str], "role_assumptions": [str], "data_exfil_indicators": [str]}.
Side effects: Read-only file analysis.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| log_dir | Yes | Directory containing CloudTrail JSON log files |