dd-audit-security-investigation

Search and analyze Audit Trail security events by user, resource, and time window.

150|23|Updated Feb 3, 2026
One-click install
npx skills add https://github.com/datadog-labs/agent-skills --skill dd-audit-security-investigation
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: dd-audit-security-investigation
Source: https://github.com/datadog-labs/agent-skills/tree/main/dd-audit/security-investigation
Command: npx skills add https://github.com/datadog-labs/agent-skills --skill dd-audit-security-investigation

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides efficient tools for analyzing security events logged in Audit Trail, simplifying investigations of deletions, configuration changes, login activities, and permission modifications.

Core Features & Use Cases

  • Audit Trail Querying: Access detailed logs of actions like deletions, modifications, and logins.
  • User and Resource Tracking: Identify who made changes and to which resources.
  • Geographical and Anomaly Detection: Pinpoint unusual activities by location and timing.
  • Use Case: Quickly respond to a security alert by querying specific users, resource types, or timeframes for evidence.

Quick Start

Query security events in the Audit Trail related to the deletion of specific resources within the last week.

Frequently Asked Questions about dd-audit-security-investigation

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I investigate Audit Trail events for user activity and security incidents?

You investigate Audit Trail events by searching and analyzing logs for user actions such as deletions, configuration changes, logins, and permission alterations. This skill summarizes security events to support incident response and compliance audits.

How can I filter Audit Trail logs by user, resource, and time window for a compliance audit?

You filter Audit Trail logs by querying specific users, resource types, event types, and time windows. This allows you to isolate relevant security events and track exactly who made changes to which resources during the audit period.

Can I detect unusual user activity and geographical anomalies in Audit Trail logs?

You can detect unusual user activity by analyzing Audit Trail logs to pinpoint anomalies by geographical location and timing. This helps identify suspicious login activities or unauthorized modifications during a security investigation.

What is the best way to search Audit Trail logs for resource deletions within a specific timeframe?

The best way to search Audit Trail logs for resource deletions is to query security events filtered by the deletion event type and your target time window. This quickly surfaces evidence of destructive user actions for incident response.

Does this security investigation skill require any external dependencies to analyze audit logs?

No external dependencies are required to analyze audit logs with this skill. It operates independently using internal scripts and references to search, analyze, and summarize security events directly from the Audit Trail.

Can I track permission alterations and configuration changes using Audit Trail log analysis?

You can track permission alterations and configuration changes by querying the Audit Trail for these specific event types. The skill identifies who made the modifications and which resources were affected for your security investigation.

Related Skills