deploying-cloud-deception-with-decoy-resources
bfoxhound/Anthropic-Cybersecurity-SkillsDeploy cloud-native deception across AWS, Azure, and GCP using decoy (honey) resources whose only purpose is to generate a high-fidelity alert the instant an…
Scores out of 100 · grade B+
2026-08-23Works
40% of the score100/100
- Loads cleanly: valid frontmatter, required fields present, no dangling references.
Maintained
25% of the score100/100
- no commits in the last 12 weeks
- repo is less than two weeks old
Adopted
20% of the score0/100
- No install or star signal yet.
Documented
15% of the score100/100
- 1,338 words with worked examples.
- Ships 4 bundled files.
Install
npx skills add bfoxhound/Anthropic-Cybersecurity-Skills/deploying-cloud-deception-with-decoy-resourcesWhat it says it does
Deploy cloud-native deception across AWS, Azure, and GCP using decoy (honey) resources whose only purpose is to generate a high-fidelity alert the instant an attacker touches them: canary IAM access keys, permission-less decoy users/roles/service principals, honey object-storage buckets, and decoy secrets in Secrets Manager / Key Vault / Secret Manager. Wires detection through CloudTrail + EventBridge, Azure Sentinel honeytoken watchlists + Defender, and GCP Cloud Audit Logs, so any use of a decoy is routed to the SOC with near-zero false positives. Use when protecting cloud accounts and data stores, when an org has only on-prem honeypots and needs cloud coverage, when seeding fake AWS keys to catch credential theft and code-leak exposure, or when detecting cloud reconnaissance and lateral movement. Keywords: cloud deception, canary token AWS, honey S3 bucket, decoy IAM credentials, CloudTrail alert, GuardDuty, Sentinel honeytoken, decoy secret, honey service account, cloud honeypot, breach detection.
Also in bfoxhound/Anthropic-Cybersecurity-Skills
| Artifact | Score | What the check found | Type | Reach | Last commit |
|---|---|---|---|---|---|
| abusing-dpapi-for-credential-accessbfoxhound/Anthropic-Cybersecurity-Skills | clean | Skill | no signal | today | |
| abusing-shadow-credentials-for-privescbfoxhound/Anthropic-Cybersecurity-Skills | clean | Skill | no signal | today | |
| acquiring-disk-image-with-dd-and-dcflddbfoxhound/Anthropic-Cybersecurity-Skills | clean | Skill | no signal | today | |
| analyzing-apt-group-with-mitre-navigatorbfoxhound/Anthropic-Cybersecurity-Skills | clean | Skill | no signal | today | |
| analyzing-browser-forensics-with-hindsightbfoxhound/Anthropic-Cybersecurity-Skills | clean | Skill | no signal | today | |
| analyzing-disk-image-with-autopsybfoxhound/Anthropic-Cybersecurity-Skills | clean | Skill | no signal | today |
Other devops & infra skills
Browse all| Artifact | Score | What the check found | Category | Reach | Last commit |
|---|---|---|---|---|---|
| deploy-to-vercelvercel-labs/agent-skills | No license | DevOps & infra | 112,099 installs | yesterday | |
| azure-quotasmicrosoft/azure-skills | clean | DevOps & infra | 407,232 installs | yesterday | |
| vercel-cli-with-tokensvercel-labs/agent-skills | No license | DevOps & infra | 85,416 installs | yesterday | |
| azure-reliabilitymicrosoft/azure-skills | clean | DevOps & infra | 219,390 installs | yesterday | |
| azure-validatemicrosoft/azure-skills | clean | DevOps & infra | 538,603 installs | yesterday | |
| azure-kustomicrosoft/azure-skills | clean | DevOps & infra | 537,195 installs | yesterday |
Put this measurement in your README
A badge carrying how many listings this index holds from the repository and how many pass every static structural check. It reads from this index every time somebody loads your page, so it changes when the measurement changes and there is nothing to keep up to date. Free, no account, and the value is not something you or we can set by hand.
[](https://skillworks.kynth.studio/?q=bfoxhound%2FAnthropic-Cybersecurity-Skills)Would rather not hotlink us? Every badge is also served in shields.io’s endpoint schema, so shields renders the image and your readers never talk to our domain:
Published by Toolproof, the masthead over this index and eight others. The method behind the number is at toolproof.kynth.studio/methodology, and the whole thing is readable as JSON with no key at /api.
