Blog
A leaked AWS access key: deactivate it, then use CloudTrail to find where it was used, what it enumerated, what it created and which data it could reach.
Export CloudTrail logs from the trail bucket, event history or CloudTrail Lake, plus VPC Flow Logs, S3 access logs, GuardDuty findings and IAM reports.
AWS account compromised? What to do first, which logs to secure, how to scope the attack in CloudTrail and how to contain it without destroying evidence.