← All cheat sheets

AWS DETECTION (CLOUDTRAIL)

Plain-text reference · 5 KB. Read it, search it (Ctrl-F) or print it.

OVERVIEW#

CloudTrail records AWS API activity and is the primary detection
source for cloud attacks (privilege escalation, persistence,
exfiltration). This sheet covers CloudTrail queries (CLI + Athena),
GuardDuty, and high-value detection patterns mapped to attacker TTPs.

CLOUDTRAIL BASICS#

aws cloudtrail lookup-events --max-results 20
aws cloudtrail lookup-events \
  --lookup-attributes AttributeKey=EventName,AttributeValue=ConsoleLogin
aws cloudtrail lookup-events \
  --lookup-attributes AttributeKey=Username,AttributeValue=<user>
aws cloudtrail lookup-events \
  --start-time 2026-07-01 --end-time 2026-07-21
# Key fields: eventName, eventSource, userIdentity, sourceIPAddress,
# userAgent, errorCode, requestParameters, responseElements

KEY IDENTITY / RECON EVENTS#

# Reconnaissance (often precedes escalation):
#   GetCallerIdentity, ListUsers, ListRoles, ListPolicies,
#   GetAccountAuthorizationDetails, DescribeInstances, ListBuckets
# Credential access:
#   GetSecretValue, GetParameter, Decrypt, GetPasswordData,
#   GenerateDataKey, GetFederationToken

PRIVILEGE ESCALATION SIGNALS#

# Watch for these API calls (IAM abuse):
#   CreateAccessKey (on another user), CreateLoginProfile,
#   AttachUserPolicy / AttachRolePolicy (AdministratorAccess),
#   PutUserPolicy / PutRolePolicy, UpdateAssumeRolePolicy,
#   CreatePolicyVersion, PassRole + CreateFunction/RunInstances,
#   AddUserToGroup (privileged group)

PERSISTENCE SIGNALS#

#   CreateUser, CreateAccessKey, CreateLoginProfile,
#   CreateRole with broad trust policy, CreateFunction + trigger,
#   PutBucketPolicy (public), ModifyInstanceAttribute (userData),
#   CreateKeyPair, ImportKeyPair

DEFENSE EVASION SIGNALS#

#   StopLogging, DeleteTrail, UpdateTrail (disable logging),
#   PutEventSelectors (reduce coverage), DeleteFlowLogs,
#   DisassociateVpcCidrBlock, DeleteDetector (GuardDuty),
#   LeaveOrganization, DeleteConfigRule

ATHENA - QUERY CLOUDTRAIL AT SCALE#

-- Root account usage (should be near-zero)
SELECT eventtime, eventname, sourceipaddress, useragent
FROM cloudtrail_logs
WHERE useridentity.type = 'Root'
  AND eventtime > '2026-07-01'
ORDER BY eventtime DESC;

-- Logging disabled (evasion)
SELECT eventtime, useridentity.arn, eventname, sourceipaddress
FROM cloudtrail_logs
WHERE eventname IN ('StopLogging','DeleteTrail','UpdateTrail',
                    'DeleteDetector');

-- Access key created on another user (escalation/persistence)
SELECT eventtime, useridentity.arn AS actor,
       requestparameters
FROM cloudtrail_logs
WHERE eventname = 'CreateAccessKey';

-- Console logins without MFA
SELECT eventtime, useridentity.arn, sourceipaddress
FROM cloudtrail_logs
WHERE eventname = 'ConsoleLogin'
  AND json_extract_scalar(additionaleventdata,'$.MFAUsed') = 'No';

-- AssumeRole from an unusual external account
SELECT eventtime, useridentity.arn, requestparameters, sourceipaddress
FROM cloudtrail_logs
WHERE eventname = 'AssumeRole';

GUARDDUTY#

aws guardduty list-detectors
aws guardduty get-findings --detector-id <id> --finding-ids <ids>
aws guardduty list-findings --detector-id <id> \
  --finding-criteria '{"Criterion":{"severity":{"Gte":7}}}'
# GuardDuty flags: credential exfil, crypto-mining, recon,
# anomalous IAM, S3 exfiltration, EC2 C2 patterns

S3 / EXFIL SIGNALS#

# GetObject spikes, ListBuckets sweeps, PutBucketAcl (public),
# GetBucketPolicy, CopyObject cross-account, RestoreObject (glacier)
# Enable S3 data events in CloudTrail to see object-level access

EXAMPLES#

# Quick check: was CloudTrail logging ever stopped?
aws cloudtrail lookup-events \
  --lookup-attributes AttributeKey=EventName,AttributeValue=StopLogging

# Athena: privilege-escalation policy attachments in last 7 days
# SELECT eventtime, useridentity.arn, eventname, requestparameters
# FROM cloudtrail_logs
# WHERE eventname IN ('AttachUserPolicy','AttachRolePolicy',
#   'PutUserPolicy','CreatePolicyVersion')
# AND eventtime > date_add('day', -7, now());

# High-severity GuardDuty findings only
aws guardduty list-findings --detector-id <id> \
  --finding-criteria '{"Criterion":{"severity":{"Gte":7}}}'

NOTES#

- Enable CloudTrail in ALL regions + a dedicated logging account;
  turn on log file validation to detect tampering
- Management events are free; DATA events (S3/Lambda) cost extra but
  are essential for exfil detection
- Root usage, MFA-less console login, and StopLogging/DeleteTrail are
  top-priority alerts
- GuardDuty is the fastest managed baseline; complement with custom
  Athena/SIEM analytics for IAM escalation chains
- Ship CloudTrail to your SIEM (QRadar/Sentinel) for correlation with
  on-prem identity events
- For FS clients, cloud logging gaps are a DORA ICT third-party risk
  and CSSF cloud-outsourcing finding

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.