orca-investigate

Trace actor activity from cloud audit logs into session timelines with MITRE ATT&CK mappings.

47|7|Updated May 3, 2026
One-click install
npx skills add https://github.com/orcasecurity/orca-skills --skill orca-investigate
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: orca-investigate
Source: https://github.com/orcasecurity/orca-skills/tree/main/skills/orca-investigate
Command: npx skills add https://github.com/orcasecurity/orca-skills --skill orca-investigate

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Traces actor activity from cloud audit logs to support incident investigations and forensics, delivering a clear narrative of event sequences and potential attacker techniques.

Core Features & Use Cases

  • Build session timelines from CloudTrail/audit logs to answer what happened, who did it, and how far they went.
  • Map observed actions to MITRE ATT&CK for Cloud techniques and assess blast radius across one or more cloud accounts.
  • Correlate related events, identify cross-account activity, and provide actionable containment recommendations.

Quick Start

Analyze an incident right away by running an investigation on an actor or account to generate a prioritized timeline and risk assessment.

Frequently Asked Questions about orca-investigate

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I investigate a cloud security incident using CloudTrail logs?▼

Trace actor activity from CloudTrail logs to build session timelines, map actions to MITRE ATT&CK techniques, and assess blast radius across accounts. This produces a risk verdict with cross-account context and actionable containment recommendations.

What is blast radius assessment in cloud forensics?▼

Blast radius assessment in cloud forensics maps how far an attacker went across one or more cloud accounts. It correlates related audit log events to identify cross-account activity and measure the full scope of a security incident.

How do I map suspicious cloud activity to MITRE ATT&CK techniques?▼

Map suspicious cloud activity to MITRE ATT&CK techniques by analyzing actor sessions built from cloud audit logs. The investigation correlates observed actions to specific MITRE ATT&CK for Cloud techniques, providing a clear narrative of event sequences.

Can I trace cross-account activity during a cloud security investigation?▼

Yes, you can trace cross-account activity during a cloud security investigation. The analysis correlates related events from CloudTrail and audit logs across multiple cloud accounts to identify lateral movement and provide a comprehensive blast radius assessment.

Do I need Orca CDR to run a forensic investigation on cloud audit logs?▼

Yes, you need Orca CDR integration to collect events and run a forensic investigation on cloud audit logs. The integration gathers CloudTrail and audit log data to build sessions, map MITRE ATT&CK techniques, and produce a risk verdict.

What is the best way to build a session timeline for a cloud security incident?▼

The best way to build a session timeline for a cloud security incident is to run an investigation on an actor or account. This generates a prioritized timeline from audit logs that answers what happened, who did it, and how far they went.