guardduty-alert

Community

Triage AWS GuardDuty findings fast

Authorafoxnyc3
Version1.0.0
Installs0

System Documentation

What problem does it solve?

It helps security and IT teams quickly interpret AWS GuardDuty alerts by turning raw findings into actionable triage output, reducing time spent guessing whether activity is benign or malicious.

Core Features & Use Cases

  • Finding Retrieval & Filtering: Fetches specific findings by ID or filters by severity to focus triage effort where it matters most.
  • Detector-Aware Enrichment: Enumerates GuardDuty detectors and gathers complete finding details for accurate context (resource, timing, and counts).
  • Severity-Based Escalation & Remediation Guidance: Classifies findings into attack categories and provides prioritized next steps, including immediate escalation for HIGH/CRITICAL.

Quick Start

Use the guardduty-alert skill to triage an incident by running it for region-scoped active findings at HIGH severity or higher.

Dependency Matrix

Required Modules

None required

Components

Standard package

💻 Claude Code Installation

Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.

Please help me install this Skill:
Name: guardduty-alert
Download link: https://github.com/afoxnyc3/chelsea-piers-itops/archive/main.zip#guardduty-alert

Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
View Source Repository

Agent Skills Search Helper

Install a tiny helper to your Agent, search and equip skill from 471,000+ vetted skills library on demand.