All skills
datadog-labs avatar

/key-compromise

@0d12930 official

Investigate a potentially compromised Datadog API key — timeline of actions, geo/IP breakdown, endpoints called, anomaly flags, and remediation steps.

  • 1 file
  • 4.8 KB
  • Updated 5 months ago
  • GitHub

Use this Skill: https://skilld.dev/gh/datadog-labs/agent-skills/key-compromise

This session only. Nothing lands on disk.

SKILL.md

≈42 tokens always: the name and description. ≈1.1k when used: this file.

Audit Trail: API Key Compromise Investigation

Reconstruct what a Datadog API key did, where requests originated, and which resources were affected.

Prerequisites

pup auth login   # OAuth2 (recommended)
# or set DD_API_KEY + DD_APP_KEY with audit_logs_read scope

You need the key ID of the suspect key (not the key value). Find it in Datadog UI under Organization Settings > API Keys, or from context showing @metadata.api_key.id.

Investigation Workflow

Step 1 — Establish timeline

pup audit-logs search --query "@metadata.api_key.id:KEY_ID" --from 90d --limit 200 -o json \
  | jq '[.data[] | {
      timestamp: .attributes.timestamp,
      action: .attributes.attributes.action,
      event: .attributes.attributes.evt.name,
      resource_type: .attributes.attributes.asset.type,
      resource_id: .attributes.attributes.asset.id,
      endpoint: .attributes.attributes.http.url_details.path,
      method: .attributes.attributes.http.method,
      ip: .attributes.attributes.network.client.ip,
      city: .attributes.attributes.network.client.geoip.city.name,
      country: .attributes.attributes.network.client.geoip.country.name,
      asn: .attributes.attributes.network.client.geoip.as.name
    }]'

Step 2 — Geo/IP breakdown

pup audit-logs search --query "@metadata.api_key.id:KEY_ID" --from 90d --limit 500 -o json \
  | jq '[.data[] | {
      country: .attributes.attributes.network.client.geoip.country.name,
      asn: .attributes.attributes.network.client.geoip.as.name,
      ip: .attributes.attributes.network.client.ip
    }]
    | group_by(.country)
    | map({
        country: .[0].country,
        count: length,
        asns: [.[].asn] | unique,
        ips: [.[].ip] | unique
      })
    | sort_by(-.count)'

Step 3 — Endpoint breakdown

pup audit-logs search --query "@metadata.api_key.id:KEY_ID" --from 90d --limit 500 -o json \
  | jq '[.data[] | {
      method: .attributes.attributes.http.method,
      path: .attributes.attributes.http.url_details.path
    }]
    | group_by(.path)
    | map({path: .[0].path, methods: [.[].method] | unique, count: length})
    | sort_by(-.count)'

Step 4 — Destructive action check

pup audit-logs search --query "@metadata.api_key.id:KEY_ID @action:deleted" --from 90d -o json \
  | jq '[.data[] | {
      timestamp: .attributes.timestamp,
      resource_type: .attributes.attributes.asset.type,
      resource_id: .attributes.attributes.asset.id,
      ip: .attributes.attributes.network.client.ip,
      country: .attributes.attributes.network.client.geoip.country.name
    }]'

Step 5 — When was the key created and by whom?

pup audit-logs search --query "@asset.type:api_key @asset.id:KEY_ID @action:created" --from 90d -o json \
  | jq '[.data[] | {
      created_at: .attributes.timestamp,
      created_by: .attributes.attributes.usr.email,
      creator_ip: .attributes.attributes.network.client.ip,
      creator_country: .attributes.attributes.network.client.geoip.country.name
    }]'

Anomaly Flags

Signal Why it matters
Country not in org's normal baseline Possible exfiltration from unexpected region
ASN is a cloud/VPN provider (AWS, Cloudflare, NordVPN, etc.) Proxied traffic; obscured origin
DELETE actions on monitors, dashboards, or log pipelines Potential sabotage
Burst of activity in short window Automated scraping or bulk exfiltration
Activity outside business hours Off-hours access
Key used from multiple IPs simultaneously Key shared or stolen

Investigation Output Format

Key ID: <key_id>
Created: <timestamp> by <user_email>
Active period: <first_seen> to <last_seen>
Total events: <N>

Origins:
  - <Country> (<ASN>): <N> events — [NORMAL / FLAG: first-time origin]

Endpoints called (top 5):
  - <METHOD> <path>: <N> calls

Destructive actions: <N> deletions — [resource types affected]

Recommended actions:
  1. Revoke the key immediately if not already done
  2. Review affected resources: [list]
  3. Check if any deleted resources need restoration
  4. Audit who else had access to this key

Remediation

Revoke in Datadog UI: Organization Settings > API Keys > Revoke.

Or via API (requires manage_api_keys scope):

pup api-keys delete KEY_ID

References

Source: SKILL.md on GitHub

No third-party reports yet.

Signed by skilld at 0d12930. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 5 months ago
Other metadata
metadata
{
  "version": "0.1.0",
  "author": "datadog-labs",
  "repository": "https://github.com/datadog-labs/agent-skills",
  "tags": "datadog,audit,security,api-key,compromise,dd-audit",
  "alwaysApply": "false"
}
  • Security
  • datadog
  • audit
  • api-key
  • compromise
  • investigation
  • forensics
  • access-logs
  • incident-response

README badge

README badge for datadog-labs/agent-skills/key-compromise

Investigates a potentially compromised Datadog API key by querying audit logs for timeline, geographic/IP breakdown, endpoints called, and destructive actions. Uses the Datadog audit trail API to surface anomaly flags like off-hours access, cloud-provider proxies, and bulk deletions, then provides revocation steps.

Generated from the current SKILL.md.

What permissions do I need to use this skill?
You need OAuth2 authentication (via `pup auth login`) or DD_API_KEY + DD_APP_KEY with the `audit_logs_read` scope. Additionally, revoking a key requires the `manage_api_keys` scope.
How far back can I investigate a compromised key?
The skill queries audit logs with a default 90-day lookback window, which is Datadog's standard audit retention. You can adjust the `--from` parameter, but results are limited by your organization's audit log retention policy.
Do I need the actual API key value to investigate?
No. You only need the key ID, which you can find in Datadog UI under Organization Settings > API Keys or from audit log metadata.
Can this skill detect if a key was used to export sensitive data?
The skill shows which endpoints were called and can flag unusual patterns (burst activity, off-hours access, VPN/cloud origins), but it does not inspect the actual data payload of requests—only the method, path, IP, and geo information.
What does the skill flag as suspicious activity?
The skill flags unexpected geographic origins, cloud/VPN provider ASNs, DELETE actions on monitors or dashboards, activity bursts, off-hours access, and the same key used from multiple IPs simultaneously.

Generated from the current SKILL.md. These answers refresh after source changes.