Skip to content
Cloud Security DeskSearch
Menu

Evidence search

Search

Search titles, summaries, topics, providers, authors, and the full open-access corpus.

Results for “CloudTrail”

22 publications
Technical guideSource-based analysis

Map cloud incident response to NIST SP 800-61 Revision 3

Revision 3 turned NIST's incident handling guide into a CSF 2.0 profile. Translate its rows into provider contracts, cloud evidence, containment authority and recovery ownership, and fix the log defaults first.

Detection & response · NIST / Amazon Web Services / Microsoft Azure / Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Give Kubernetes pods cloud credentials without static keys

EKS Pod Identity, IRSA, AKS Workload ID and Workload Identity Federation for GKE all swap a projected token for short-lived credentials. What leaks if you stop there is the node's own identity.

Identity & access · Amazon Web Services / Microsoft Azure / Google Cloud / Kubernetes · By Cloud Security Desk
Technical guideSource-based analysis

Stop S3 ransomware that encrypts objects with customer-provided keys

SSE-C ransomware rewrites S3 objects under a key only the attacker holds. AWS now blocks SSE-C by default on most buckets; this guide covers what that default misses and the controls that close the gap.

Detection & response · Amazon Web Services · By Cloud Security Desk
Technical guideSource-based analysis

Investigate a CI supply chain compromise from workflow logs to rotated secrets

When an action or package in your pipeline turns out to be malicious, scope the response by exposure window and by what each affected job could reach, then revoke together and hunt for use.

Detection & response · GitHub / AWS / npm · By Cloud Security Desk
Technical guideSource-based analysis

Move cloud logs to cheaper tiers without losing detection coverage

CloudWatch Infrequent Access, the Sentinel data lake and Cloud Logging exclusions all cut ingestion cost by removing real-time detection hooks. Place each source by the rules that read it, then prove the replacements fire.

Detection & response · AWS / Microsoft Azure / Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Know where cloud AI services process your prompts

Bedrock inference profiles, Foundry deployment types and Agent Platform endpoints each decide where a prompt is processed, separately from where data rests. Compare what each provider commits to and how to enforce it.

AI systems · Amazon Web Services / Microsoft Azure / Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Let AWS workloads call external services with IAM-issued tokens

IAM outbound identity federation lets an AWS role trade its credentials for a signed JWT instead of storing a vendor API key. AWS controls issuance; the receiving service's claim checks decide what the token is worth.

Identity & access · Amazon Web Services / AWS IAM / AWS STS / Microsoft Entra · By Cloud Security Desk
Technical guideSource-based analysis

Normalize cloud security logs with OCSF before writing detections

OCSF puts CloudTrail, Azure Activity Log and Google audit records into the same API Activity fields. Detections still depend on the mapping, the schema version and provider semantics that normalization does not erase.

Detection & response · Open Cybersecurity Schema Framework / Amazon Web Services / Microsoft Azure / Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Build a cryptographic inventory for the post-quantum transition

Record where public-key cryptography protects long-lived data and which library, service or vendor must change it. Then rank entries by function and data lifetime, not by how many RSA keys a scanner found.

Workload security · NIST / CISA / Office of Management and Budget / Amazon Web Services / Google Cloud / Microsoft Azure · By Cloud Security Desk
Technical guideSource-based analysis

Defend cloud admin accounts against help desk social engineering

Attackers who talk a help desk into resetting MFA inherit every cloud console behind single sign-on. Verify callers properly, shrink what a reset hands over, and alert on the events it leaves.

Detection & response · Microsoft Entra / Okta / Amazon Web Services / CISA / Mandiant · By Cloud Security Desk
Technical guideSource-based analysis

Give AI agents their own identity instead of borrowed user tokens

An agent that replays a user's token is invisible in logs and cannot be revoked on its own. Give it a principal, delegate narrowly through token exchange, and use what Entra, AgentCore and Google now provide.

Identity & access · Microsoft Entra / Amazon Web Services / Google Cloud / IETF / Model Context Protocol · By Cloud Security Desk
Technical guideSource-based analysis

Protect and recover your AWS root account

Protect AWS root access with MFA, current recovery contacts, separate daily administration, and a clear plan for Organizations member accounts.

Identity & access · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Choose and verify CloudWatch Logs retention

Choose CloudWatch Logs retention from supported values, verify the saved setting, and account for delayed deletion, archives, and log-group ownership.

Detection & response · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Remove public SSH access from an EC2 security group

Remove internet-wide EC2 SSH rules after testing Session Manager or restricted SSH. Check all groups, IPv6, fresh sessions, and recovery access.

Workload security · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Read VPC Flow Logs without overclaiming network evidence

Interpret aggregation, address translation, skipped records and delivery clocks before turning a VPC flow record into an incident conclusion.

Detection & response · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Design RDS IAM authentication around the connection pool

Generate IAM database tokens for the physical connections that need them, and keep token validity separate from the lifetime of an already-established SQL session.

Workload security · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Investigate denied access at an AWS VPC endpoint

Use CloudTrail network activity evidence to distinguish endpoint-policy violations from routing failures and downstream authorization problems.

Detection & response · AWS · By Cloud Security Desk
Technical guideSource-based analysis

What cloud snapshots cannot preserve

Separate live execution, persisted disk and provider records before an authorized containment decision destroys evidence that a snapshot cannot recover.

Detection & response · AWS / NIST · By Cloud Security Desk
Technical guideSource-based analysis

Cloud detection coverage after the ATT&CK data model change

Connect current ATT&CK strategies and analytics to available events, implemented rules and test evidence, while keeping taxonomy counts separate from protection.

Detection & response · MITRE · By Cloud Security Desk
Technical guideSource-based analysis

Know when AWS KMS encryption needs an envelope

KMS Encrypt has small plaintext limits. Follow the data key and encrypted-message format when an application needs to protect larger payloads.

Workload security · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Verify the CloudTrail files behind an incident timeline

Digest delivery and successful validation are different evidence states. Preserve the files, metadata and validation result needed to distinguish them.

Detection & response · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Choose the S3 object events your investigation will need

CloudTrail event history is not an object-access ledger. Build selectors around the questions an investigation must answer, then test the exclusions.

Detection & response · AWS · By Cloud Security Desk