orca-investigate

Trace actor activity from cloud audit logs into session timelines with MITRE ATT&CK mappings.

47|7|Updated May 3, 2026
One-click install
npx skills add https://github.com/orcasecurity/orca-skills --skill orca-investigate
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: orca-investigate
Source: https://github.com/orcasecurity/orca-skills/tree/main/skills/orca-investigate
Command: npx skills add https://github.com/orcasecurity/orca-skills --skill orca-investigate

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Traces actor activity from cloud audit logs to support incident investigations and forensics, delivering a clear narrative of event sequences and potential attacker techniques.

Core Features & Use Cases

  • Build session timelines from CloudTrail/audit logs to answer what happened, who did it, and how far they went.
  • Map observed actions to MITRE ATT&CK for Cloud techniques and assess blast radius across one or more cloud accounts.
  • Correlate related events, identify cross-account activity, and provide actionable containment recommendations.

Quick Start

Analyze an incident right away by running an investigation on an actor or account to generate a prioritized timeline and risk assessment.

Frequently Asked Questions about orca-investigate

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I investigate a cloud security incident using CloudTrail logs?

Trace actor activity from CloudTrail logs to build session timelines, map actions to MITRE ATT&CK techniques, and assess blast radius across accounts. This produces a risk verdict with cross-account context and actionable containment recommendations.

What is blast radius assessment in cloud forensics?

Blast radius assessment in cloud forensics maps how far an attacker went across one or more cloud accounts. It correlates related audit log events to identify cross-account activity and measure the full scope of a security incident.

How do I map suspicious cloud activity to MITRE ATT&CK techniques?

Map suspicious cloud activity to MITRE ATT&CK techniques by analyzing actor sessions built from cloud audit logs. The investigation correlates observed actions to specific MITRE ATT&CK for Cloud techniques, providing a clear narrative of event sequences.

Can I trace cross-account activity during a cloud security investigation?

Yes, you can trace cross-account activity during a cloud security investigation. The analysis correlates related events from CloudTrail and audit logs across multiple cloud accounts to identify lateral movement and provide a comprehensive blast radius assessment.

Do I need Orca CDR to run a forensic investigation on cloud audit logs?

Yes, you need Orca CDR integration to collect events and run a forensic investigation on cloud audit logs. The integration gathers CloudTrail and audit log data to build sessions, map MITRE ATT&CK techniques, and produce a risk verdict.

What is the best way to build a session timeline for a cloud security incident?

The best way to build a session timeline for a cloud security incident is to run an investigation on an actor or account. This generates a prioritized timeline from audit logs that answers what happened, who did it, and how far they went.