Evidence search
Search
Search titles, summaries, topics, providers, authors, and the full open-access corpus.
Results for “CloudTrail”
22 publicationsMap cloud incident response to NIST SP 800-61 Revision 3
Revision 3 turned NIST's incident handling guide into a CSF 2.0 profile. Translate its rows into provider contracts, cloud evidence, containment authority and recovery ownership, and fix the log defaults first.
Detection & response · NIST / Amazon Web Services / Microsoft Azure / Google Cloud · By Cloud Security DeskGive Kubernetes pods cloud credentials without static keys
EKS Pod Identity, IRSA, AKS Workload ID and Workload Identity Federation for GKE all swap a projected token for short-lived credentials. What leaks if you stop there is the node's own identity.
Identity & access · Amazon Web Services / Microsoft Azure / Google Cloud / Kubernetes · By Cloud Security DeskStop S3 ransomware that encrypts objects with customer-provided keys
SSE-C ransomware rewrites S3 objects under a key only the attacker holds. AWS now blocks SSE-C by default on most buckets; this guide covers what that default misses and the controls that close the gap.
Detection & response · Amazon Web Services · By Cloud Security DeskInvestigate a CI supply chain compromise from workflow logs to rotated secrets
When an action or package in your pipeline turns out to be malicious, scope the response by exposure window and by what each affected job could reach, then revoke together and hunt for use.
Detection & response · GitHub / AWS / npm · By Cloud Security DeskMove cloud logs to cheaper tiers without losing detection coverage
CloudWatch Infrequent Access, the Sentinel data lake and Cloud Logging exclusions all cut ingestion cost by removing real-time detection hooks. Place each source by the rules that read it, then prove the replacements fire.
Detection & response · AWS / Microsoft Azure / Google Cloud · By Cloud Security DeskKnow where cloud AI services process your prompts
Bedrock inference profiles, Foundry deployment types and Agent Platform endpoints each decide where a prompt is processed, separately from where data rests. Compare what each provider commits to and how to enforce it.
AI systems · Amazon Web Services / Microsoft Azure / Google Cloud · By Cloud Security DeskLet AWS workloads call external services with IAM-issued tokens
IAM outbound identity federation lets an AWS role trade its credentials for a signed JWT instead of storing a vendor API key. AWS controls issuance; the receiving service's claim checks decide what the token is worth.
Identity & access · Amazon Web Services / AWS IAM / AWS STS / Microsoft Entra · By Cloud Security DeskNormalize cloud security logs with OCSF before writing detections
OCSF puts CloudTrail, Azure Activity Log and Google audit records into the same API Activity fields. Detections still depend on the mapping, the schema version and provider semantics that normalization does not erase.
Detection & response · Open Cybersecurity Schema Framework / Amazon Web Services / Microsoft Azure / Google Cloud · By Cloud Security DeskBuild a cryptographic inventory for the post-quantum transition
Record where public-key cryptography protects long-lived data and which library, service or vendor must change it. Then rank entries by function and data lifetime, not by how many RSA keys a scanner found.
Workload security · NIST / CISA / Office of Management and Budget / Amazon Web Services / Google Cloud / Microsoft Azure · By Cloud Security DeskDefend cloud admin accounts against help desk social engineering
Attackers who talk a help desk into resetting MFA inherit every cloud console behind single sign-on. Verify callers properly, shrink what a reset hands over, and alert on the events it leaves.
Detection & response · Microsoft Entra / Okta / Amazon Web Services / CISA / Mandiant · By Cloud Security DeskGive AI agents their own identity instead of borrowed user tokens
An agent that replays a user's token is invisible in logs and cannot be revoked on its own. Give it a principal, delegate narrowly through token exchange, and use what Entra, AgentCore and Google now provide.
Identity & access · Microsoft Entra / Amazon Web Services / Google Cloud / IETF / Model Context Protocol · By Cloud Security DeskProtect and recover your AWS root account
Protect AWS root access with MFA, current recovery contacts, separate daily administration, and a clear plan for Organizations member accounts.
Identity & access · AWS · By Cloud Security DeskChoose and verify CloudWatch Logs retention
Choose CloudWatch Logs retention from supported values, verify the saved setting, and account for delayed deletion, archives, and log-group ownership.
Detection & response · AWS · By Cloud Security DeskRemove public SSH access from an EC2 security group
Remove internet-wide EC2 SSH rules after testing Session Manager or restricted SSH. Check all groups, IPv6, fresh sessions, and recovery access.
Workload security · AWS · By Cloud Security DeskRead VPC Flow Logs without overclaiming network evidence
Interpret aggregation, address translation, skipped records and delivery clocks before turning a VPC flow record into an incident conclusion.
Detection & response · AWS · By Cloud Security DeskDesign RDS IAM authentication around the connection pool
Generate IAM database tokens for the physical connections that need them, and keep token validity separate from the lifetime of an already-established SQL session.
Workload security · AWS · By Cloud Security DeskInvestigate denied access at an AWS VPC endpoint
Use CloudTrail network activity evidence to distinguish endpoint-policy violations from routing failures and downstream authorization problems.
Detection & response · AWS · By Cloud Security DeskWhat cloud snapshots cannot preserve
Separate live execution, persisted disk and provider records before an authorized containment decision destroys evidence that a snapshot cannot recover.
Detection & response · AWS / NIST · By Cloud Security DeskCloud detection coverage after the ATT&CK data model change
Connect current ATT&CK strategies and analytics to available events, implemented rules and test evidence, while keeping taxonomy counts separate from protection.
Detection & response · MITRE · By Cloud Security DeskKnow when AWS KMS encryption needs an envelope
KMS Encrypt has small plaintext limits. Follow the data key and encrypted-message format when an application needs to protect larger payloads.
Workload security · AWS · By Cloud Security DeskVerify the CloudTrail files behind an incident timeline
Digest delivery and successful validation are different evidence states. Preserve the files, metadata and validation result needed to distinguish them.
Detection & response · AWS · By Cloud Security DeskChoose the S3 object events your investigation will need
CloudTrail event history is not an object-access ledger. Build selectors around the questions an investigation must answer, then test the exclusions.
Detection & response · AWS · By Cloud Security Desk