Skip to content

This tool is not affiliated with, endorsed by or sponsored by Amazon Web Services, Inc. or Amazon.com, Inc. AWS, Amazon Web Services, CloudTrail and GuardDuty are trademarks of Amazon.com, Inc. or its affiliates. Other names are trademarks of their respective owners.

Series

CloudTrail investigation

6 posts in this series. Read them in order or jump to any one.

  1. How to export CloudTrail, VPC Flow and S3 logs for forensics

    Export CloudTrail logs from the trail bucket, event history or CloudTrail Lake, plus VPC Flow Logs, S3 access logs, GuardDuty findings and IAM reports.

  2. CloudTrail log analysis: a step-by-step guide

    CloudTrail log analysis in your browser: load the exports, read the verdict and findings, pivot on keys and IPs, build the timeline, then remediate.

  3. CloudTrail events to monitor, mapped to MITRE ATT&CK

    The CloudTrail events every AWS responder should know, from recon to impact, with the fields that carry the evidence and their MITRE ATT&CK technique ids.

  4. IAM privilege escalation and persistence in CloudTrail

    How attackers keep access to AWS through IAM: backdoor users, extra keys, admin policies, role trust and identity providers, and how CloudTrail shows it.

  5. Detecting StopLogging and GuardDuty disabled in CloudTrail

    Defense evasion on AWS: StopLogging, DeleteTrail, event selectors, GuardDuty detectors deleted, Config and Flow Logs removed, and what CloudTrail keeps.

  6. VPC Flow Logs analysis for exfiltration and mining

    Reading VPC Flow Logs in an investigation: key fields, egress volume per destination, mining-pool ports, what flow logs never record and the data traps.

All posts in this series

Export CloudTrail logs from the trail bucket, event history or CloudTrail Lake, plus VPC Flow Logs, S3 access logs, GuardDuty findings and IAM reports.
CloudTrail log analysis in your browser: load the exports, read the verdict and findings, pivot on keys and IPs, build the timeline, then remediate.
The CloudTrail events every AWS responder should know, from recon to impact, with the fields that carry the evidence and their MITRE ATT&CK technique ids.
How attackers keep access to AWS through IAM: backdoor users, extra keys, admin policies, role trust and identity providers, and how CloudTrail shows it.
Defense evasion on AWS: StopLogging, DeleteTrail, event selectors, GuardDuty detectors deleted, Config and Flow Logs removed, and what CloudTrail keeps.
Reading VPC Flow Logs in an investigation: key fields, egress volume per destination, mining-pool ports, what flow logs never record and the data traps.

This tool is not affiliated with, endorsed by or sponsored by Amazon Web Services, Inc. or Amazon.com, Inc. AWS, Amazon Web Services, CloudTrail and GuardDuty are trademarks of Amazon.com, Inc. or its affiliates. Other names are trademarks of their respective owners.