ingest-cloudtrail-ocsf

Installation
SKILL.md

ingest-cloudtrail-ocsf

Thin, single-purpose ingestion skill: raw CloudTrail JSON in → canonical event projection → OCSF 1.8 API Activity JSONL or native enriched JSONL out. No detection logic, no side effects, no AWS API calls. Reads files or stdin; writes JSONL or stdout.

Wire contract

Reads either of the two CloudTrail layouts that are emitted by the AWS service:

  1. Single event — one JSON object per line (NDJSON, e.g. EventBridge → Kinesis Firehose to S3)
  2. CloudTrail digest — top-level {"Records": [...]} wrapping an array of events (the format aws s3 cp retrieves directly from the CloudTrail bucket)

The skill auto-detects which shape it's looking at and unwraps Records if present.

By default it writes OCSF 1.8 API Activity (class_uid: 6003, category_uid: 6). See ../OCSF_CONTRACT.md for the field-level pinning that every OCSF event matches.

When --output-format native is selected, it emits the same event in the repo's native enriched shape with stable event_uid, normalized provider/account/operation/status fields, and preserved actor/session/source context, but without the OCSF envelope fields.

Native output format

Installs
1
GitHub Stars
3
First Seen
Apr 20, 2026
ingest-cloudtrail-ocsf — msaad00/cloud-ai-security-skills