< ciso
brief />
Tag Banner

All news with #aws cloudtrail tag

61 articles

AWS Private CA adds detailed issuance logs

📜 The new AWS Private CA CloudTrail IssueCertificateDetails event records full certificate content, issuing CA data, requester identity, and signing status for every issuance. It captures the complete TBS certificate with X.509 fields and convenience fields like subject, issuer, serial, validity, template, and algorithm. Events include both successful and failed issuances and identify the requester (account/IAM principal or service principal). Delivered automatically as a CloudTrail management event in supported Regions, it can be consumed in real time via EventBridge or queried with Athena at standard CloudTrail cost.
read more →

Transfer Family adds custom CloudWatch log groups

📘 AWS Transfer Family now lets you select a custom Amazon CloudWatch Logs group for managed workflow execution logs. You can assign a distinct log destination per workflow or consolidate logs from multiple workflows into a shared group for unified metrics and dashboards. Workflow logs remain structured JSON and queryable with CloudWatch Logs Insights, and the feature is available in all Regions offering Transfer Family managed workflows.
read more →

CloudTrail Event Coverage for Data Plane Logging

🔍 AWS CloudTrail has launched Event Coverage, a console feature that displays data plane event logging coverage across accounts and organizations. It highlights which services and resource types have data event logging enabled and which do not, helping teams identify logging gaps without manual scans. The dashboard consolidates supported data event sources and lets users subscribe to data events directly to close coverage gaps quickly.
read more →

Amazon Connect Customer adds APIs for custom metrics

📈 Amazon Connect Customer now supports programmatic creation, management, and search of custom metrics through seven new API operations. These include CreateMetric, DeleteMetric, DescribeMetric, ListMetrics, SearchMetrics, UpdateMetricContent, and UpdateMetricMetadata. Changes are logged in AWS CloudTrail and the feature is available in all Regions where Amazon Connect Customer is offered.
read more →

AWS STS enforces unified 4,096-byte session limit

🔒 AWS Security Token Service (STS) now enforces a single 4,096-byte size limit for session tokens, replacing separate limits for tokens and passed-in parameters. This change lets you combine larger session policies and session tags more flexibly. STS also returns token size and percentage utilization in responses, logs those values to AWS CloudTrail, and publishes metrics to Amazon CloudWatch. An optional API parameter lets you request larger tokens for testing, and the features are available in all commercial, GovCloud (US), and European Sovereign Cloud Regions.
read more →

CloudTrail now integrates with Amazon Q Console

🔍 AWS CloudTrail now integrates with Amazon Q Console to let you investigate account activity using natural language queries. You can ask about CloudTrail configuration, search logged events for security investigations, and troubleshoot operational issues without writing queries. The integration queries CloudTrail trails, CloudWatch log groups, and event data stores to provide answers grounded in your account activity. It is available in all AWS commercial regions where Amazon Q Console is supported.
read more →

AWS enhances regional resiliency for root sign-ins

🔒 AWS now serves root user sign-in across US East (N. Virginia), US East (Ohio), and US West (Oregon), distributing traffic across these Regions to reduce dependency on a single Region and improve resiliency during disruptions. Sign-in routing is automatic and requires no action from customers. CloudTrail records ConsoleLogin events in the Region that processed the sign-in; update monitoring and alerts to include all three Regions. This change is available now for all AWS accounts.
read more →

Behavioral Clustering to Map Cloud Identities

🔍 This Unit 42 report describes a behavioral clustering model that maps functional cloud identities by extracting activity patterns from audit logs. The authors analyzed over 40,000 identities across 125 cloud environments to identify roles such as administrators, DevOps, backup services and security tooling. Using unsupervised techniques like UMAP and HDBSCAN, the model generates a behavioral map that aids scalable detection and SQ L-based heuristics for continuous visibility. The methodology is demonstrated on AWS CloudTrail and is extensible to other cloud and SaaS environments.
read more →

AWS HealthOmics adds real-time run metrics

📊 AWS HealthOmics now publishes real-time run metrics to Amazon CloudWatch, providing live visibility into workflow resource utilization as runs execute. The 14 new metrics cover CPU and GPU usage, memory, file system usage and I/O, network throughput, and ephemeral storage. Emitted using the Amazon CloudWatch OpenTelemetry standard, these metrics support native dashboards, alarms, and integration with third-party observability tools. Real-time metrics are available in multiple US, Europe, and Asia Pacific Regions, and CloudWatch ingestion charges apply.
read more →

CloudTrail incident response: multi‑Region Bedrock attack

🔍 This post examines a multi‑stage attack that begins with a web application SSRF vulnerability on an EC2 instance, leads to IMDSv1 credential harvesting for an attached webdev role, and culminates in unauthorized access to Amazon Bedrock across Regions. It walks through four CloudTrail events—failed CreateUser, console sign‑in without MFA, ListFoundationModels in another Region, and a Converse call invoking Amazon Nova Pro—and shows which log fields reveal attribution, intent, and cross‑Region pivots. The article also provides containment, remediation, and hardening recommendations.
read more →

Incident response guide for AWS CloudTrail

🔍 This guide from the AWS Security Incident Response Team explains how to analyze AWS CloudTrail events to investigate cross-account unauthorized access, cryptocurrency mining deployments, and AI service abuse. It walks through real-world scenarios showing which CloudTrail fields matter, how to interpret session metadata, and investigative techniques for reconstructing activity timelines and assessing blast radius. The guide emphasizes practical steps to prioritize containment, identify misconfigurations such as overbroad cross-account roles or missing MFA, and extract evidentiary details from CloudTrail and related logs.
read more →

Amazon MWAA adds integrated CloudWatch monitoring

🛠️ Amazon Managed Workflows for Apache Airflow (MWAA) now includes a built-in monitoring experience on the environment detail page in the AWS Management Console. A new metrics dashboard consolidates key Amazon CloudWatch metrics with optional toggles to overlay suggested warning ranges to highlight potential issues. The page also lists associated CloudWatch alarms and offers a one-click Create Recommended Alarms action to provision alarms from an AWS-managed template. This capability is available for MWAA Provisioned environments in all supported regions; standard CloudWatch pricing applies.
read more →

CloudWatch alarms gain configurable warm-up period

🔔 Amazon CloudWatch now supports a configurable warm-up period for metric and log alarms to delay alarm evaluation after creation. This reduces noise from missing data when new resources or services start up and begin publishing metrics. You set the warm-up via the WarmUpConfiguration parameter for 1–2,880 minutes, and by default evaluation can start early once sufficient data exists. Warm-up periods are available in all AWS Regions at no extra cost beyond standard CloudWatch alarm pricing.
read more →

Detecting Multi‑Stage Attacks on AWS with Correlation

🔍 This post explains how correlating signals across AWS services and your business context reveals multi-stage attacks that single alerts miss. It outlines five attack phases and the three primary log sources—CloudTrail, VPC Flow Logs, and Route 53 Resolver logs—used to surface each phase. The guide emphasizes enabling and tuning AWS detection services such as Amazon GuardDuty, then layering custom queries that encode your environment-specific knowledge. It includes CloudWatch Logs Insights queries and operational guidance for thresholds, multi-account setups, and automating detection pipelines.
read more →

SageMaker MLflow Adds Support for Customer Keys

🔐 SageMaker MLflow now supports customer-managed keys (CMK) via AWS Key Management Service (KMS). This enhancement lets organizations with strict security or compliance needs manage encryption keys themselves and gain enhanced control and auditing through AWS CloudTrail. Customer-managed keys must be symmetric and created in the same AWS account and region as the MLflow App. The feature is generally available in all Regions where MLflow App is offered.
read more →

Amazon Quick adds approval policies for asset sharing

🔒 Amazon Quick introduces approval policies that give administrators governance over how assets are shared within an organization. Administrators can require designated approvers to review and approve share requests before access is granted, ensuring sharing of sensitive assets is deliberate, compliant, and auditable. Policies can be scoped to asset types like knowledge bases, spaces, and custom chat agents, and events are recorded in AWS CloudTrail for auditability.
read more →

Amazon Quick introduces approval policies for sharing

🔒 Administrators can now enforce approval policies in Amazon Quick to govern how assets are shared across their organization. Policies can be scoped to asset types such as knowledge bases, spaces, and custom chat agents, routing share requests to designated approver groups. Approvers can inspect assets (including full dependency packages for custom agents) and approve or deny requests, while all actions are logged to AWS CloudTrail for auditability. The capability is available on Professional and Enterprise plans in Regions that support Amazon Quick agentic features.
read more →

Amazon MSK adds Authorizer Log Delivery for clusters

🔒 Amazon Managed Streaming for Apache Kafka (MSK) now supports Authorizer Log Delivery for Provisioned clusters, including Standard and Express brokers, at no additional cost. This feature captures denied authorization requests with client IP and attempted API, helping identify client authorization issues and satisfy security requirements. Logs can be delivered to Amazon CloudWatch Logs, Amazon S3, or Amazon Data Firehose, and can be enabled via the MSK console or AWS CLI. Authorizer Log Delivery is available for new and existing Provisioned clusters in all supported Regions except the AWS European Sovereign Cloud (eusc-de-east-1).
read more →

Accelerating Network Firewall Troubleshooting with DevOps Agent

🛡️ This post shows how AWS DevOps Agent accelerates root-cause analysis for AWS Network Firewall issues by correlating CloudWatch alarms, firewall logs, route tables, and CloudTrail events. It walks through three reproducible failure scenarios—domain deny list, stateless rule priority inversion, and asymmetric cross-AZ routing—deployed via an AWS CDK app. The CDK stack includes a sample workload, test endpoint, status page, and a webhook pipeline so alarms trigger investigations and the agent returns mitigation plans for operator review.
read more →

AWS Lambda Managed Instances now publishes logs

📣 AWS Lambda now sends logs for Lambda Managed Instances (LMI) capacity providers to Amazon CloudWatch Logs, providing visibility into scaling activity and instance lifecycle operations. LMI lets you run Lambda functions on Amazon EC2 instances while keeping serverless operational simplicity. Capacity provider logs capture structured JSON lifecycle events like launches, terminations, and health checks to help monitor, troubleshoot, and optimize managed EC2 resources. Logs are enabled by default across supported AWS Commercial Regions and incur standard CloudWatch Logs charges.
read more →