AWS DETECTION (CLOUDTRAIL)
OVERVIEW#
CloudTrail records AWS API activity and is the primary detection source for cloud attacks (privilege escalation, persistence, exfiltration). This sheet covers CloudTrail queries (CLI + Athena), GuardDuty, and high-value detection patterns mapped to attacker TTPs.
CLOUDTRAIL BASICS#
aws cloudtrail lookup-events --max-results 20 aws cloudtrail lookup-events \ --lookup-attributes AttributeKey=EventName,AttributeValue=ConsoleLogin aws cloudtrail lookup-events \ --lookup-attributes AttributeKey=Username,AttributeValue=<user> aws cloudtrail lookup-events \ --start-time 2026-07-01 --end-time 2026-07-21 # Key fields: eventName, eventSource, userIdentity, sourceIPAddress, # userAgent, errorCode, requestParameters, responseElements
KEY IDENTITY / RECON EVENTS#
# Reconnaissance (often precedes escalation): # GetCallerIdentity, ListUsers, ListRoles, ListPolicies, # GetAccountAuthorizationDetails, DescribeInstances, ListBuckets # Credential access: # GetSecretValue, GetParameter, Decrypt, GetPasswordData, # GenerateDataKey, GetFederationToken
PRIVILEGE ESCALATION SIGNALS#
# Watch for these API calls (IAM abuse): # CreateAccessKey (on another user), CreateLoginProfile, # AttachUserPolicy / AttachRolePolicy (AdministratorAccess), # PutUserPolicy / PutRolePolicy, UpdateAssumeRolePolicy, # CreatePolicyVersion, PassRole + CreateFunction/RunInstances, # AddUserToGroup (privileged group)
PERSISTENCE SIGNALS#
# CreateUser, CreateAccessKey, CreateLoginProfile, # CreateRole with broad trust policy, CreateFunction + trigger, # PutBucketPolicy (public), ModifyInstanceAttribute (userData), # CreateKeyPair, ImportKeyPair
DEFENSE EVASION SIGNALS#
# StopLogging, DeleteTrail, UpdateTrail (disable logging), # PutEventSelectors (reduce coverage), DeleteFlowLogs, # DisassociateVpcCidrBlock, DeleteDetector (GuardDuty), # LeaveOrganization, DeleteConfigRule
ATHENA - QUERY CLOUDTRAIL AT SCALE#
-- Root account usage (should be near-zero)
SELECT eventtime, eventname, sourceipaddress, useragent
FROM cloudtrail_logs
WHERE useridentity.type = 'Root'
AND eventtime > '2026-07-01'
ORDER BY eventtime DESC;
-- Logging disabled (evasion)
SELECT eventtime, useridentity.arn, eventname, sourceipaddress
FROM cloudtrail_logs
WHERE eventname IN ('StopLogging','DeleteTrail','UpdateTrail',
'DeleteDetector');
-- Access key created on another user (escalation/persistence)
SELECT eventtime, useridentity.arn AS actor,
requestparameters
FROM cloudtrail_logs
WHERE eventname = 'CreateAccessKey';
-- Console logins without MFA
SELECT eventtime, useridentity.arn, sourceipaddress
FROM cloudtrail_logs
WHERE eventname = 'ConsoleLogin'
AND json_extract_scalar(additionaleventdata,'$.MFAUsed') = 'No';
-- AssumeRole from an unusual external account
SELECT eventtime, useridentity.arn, requestparameters, sourceipaddress
FROM cloudtrail_logs
WHERE eventname = 'AssumeRole';
GUARDDUTY#
aws guardduty list-detectors
aws guardduty get-findings --detector-id <id> --finding-ids <ids>
aws guardduty list-findings --detector-id <id> \
--finding-criteria '{"Criterion":{"severity":{"Gte":7}}}'
# GuardDuty flags: credential exfil, crypto-mining, recon,
# anomalous IAM, S3 exfiltration, EC2 C2 patterns
S3 / EXFIL SIGNALS#
# GetObject spikes, ListBuckets sweeps, PutBucketAcl (public), # GetBucketPolicy, CopyObject cross-account, RestoreObject (glacier) # Enable S3 data events in CloudTrail to see object-level access
EXAMPLES#
# Quick check: was CloudTrail logging ever stopped?
aws cloudtrail lookup-events \
--lookup-attributes AttributeKey=EventName,AttributeValue=StopLogging
# Athena: privilege-escalation policy attachments in last 7 days
# SELECT eventtime, useridentity.arn, eventname, requestparameters
# FROM cloudtrail_logs
# WHERE eventname IN ('AttachUserPolicy','AttachRolePolicy',
# 'PutUserPolicy','CreatePolicyVersion')
# AND eventtime > date_add('day', -7, now());
# High-severity GuardDuty findings only
aws guardduty list-findings --detector-id <id> \
--finding-criteria '{"Criterion":{"severity":{"Gte":7}}}'
NOTES#
- Enable CloudTrail in ALL regions + a dedicated logging account; turn on log file validation to detect tampering - Management events are free; DATA events (S3/Lambda) cost extra but are essential for exfil detection - Root usage, MFA-less console login, and StopLogging/DeleteTrail are top-priority alerts - GuardDuty is the fastest managed baseline; complement with custom Athena/SIEM analytics for IAM escalation chains - Ship CloudTrail to your SIEM (QRadar/Sentinel) for correlation with on-prem identity events - For FS clients, cloud logging gaps are a DORA ICT third-party risk and CSSF cloud-outsourcing finding
AWS DETECTION (CLOUDTRAIL) CHEATSHEET
=====================================
Source: https://cheatsheet.johlem.net
OVERVIEW
--------
CloudTrail records AWS API activity and is the primary detection
source for cloud attacks (privilege escalation, persistence,
exfiltration). This sheet covers CloudTrail queries (CLI + Athena),
GuardDuty, and high-value detection patterns mapped to attacker TTPs.
CLOUDTRAIL BASICS
-----------------
aws cloudtrail lookup-events --max-results 20
aws cloudtrail lookup-events \
--lookup-attributes AttributeKey=EventName,AttributeValue=ConsoleLogin
aws cloudtrail lookup-events \
--lookup-attributes AttributeKey=Username,AttributeValue=<user>
aws cloudtrail lookup-events \
--start-time 2026-07-01 --end-time 2026-07-21
# Key fields: eventName, eventSource, userIdentity, sourceIPAddress,
# userAgent, errorCode, requestParameters, responseElements
KEY IDENTITY / RECON EVENTS
---------------------------
# Reconnaissance (often precedes escalation):
# GetCallerIdentity, ListUsers, ListRoles, ListPolicies,
# GetAccountAuthorizationDetails, DescribeInstances, ListBuckets
# Credential access:
# GetSecretValue, GetParameter, Decrypt, GetPasswordData,
# GenerateDataKey, GetFederationToken
PRIVILEGE ESCALATION SIGNALS
----------------------------
# Watch for these API calls (IAM abuse):
# CreateAccessKey (on another user), CreateLoginProfile,
# AttachUserPolicy / AttachRolePolicy (AdministratorAccess),
# PutUserPolicy / PutRolePolicy, UpdateAssumeRolePolicy,
# CreatePolicyVersion, PassRole + CreateFunction/RunInstances,
# AddUserToGroup (privileged group)
PERSISTENCE SIGNALS
-------------------
# CreateUser, CreateAccessKey, CreateLoginProfile,
# CreateRole with broad trust policy, CreateFunction + trigger,
# PutBucketPolicy (public), ModifyInstanceAttribute (userData),
# CreateKeyPair, ImportKeyPair
DEFENSE EVASION SIGNALS
-----------------------
# StopLogging, DeleteTrail, UpdateTrail (disable logging),
# PutEventSelectors (reduce coverage), DeleteFlowLogs,
# DisassociateVpcCidrBlock, DeleteDetector (GuardDuty),
# LeaveOrganization, DeleteConfigRule
ATHENA - QUERY CLOUDTRAIL AT SCALE
----------------------------------
-- Root account usage (should be near-zero)
SELECT eventtime, eventname, sourceipaddress, useragent
FROM cloudtrail_logs
WHERE useridentity.type = 'Root'
AND eventtime > '2026-07-01'
ORDER BY eventtime DESC;
-- Logging disabled (evasion)
SELECT eventtime, useridentity.arn, eventname, sourceipaddress
FROM cloudtrail_logs
WHERE eventname IN ('StopLogging','DeleteTrail','UpdateTrail',
'DeleteDetector');
-- Access key created on another user (escalation/persistence)
SELECT eventtime, useridentity.arn AS actor,
requestparameters
FROM cloudtrail_logs
WHERE eventname = 'CreateAccessKey';
-- Console logins without MFA
SELECT eventtime, useridentity.arn, sourceipaddress
FROM cloudtrail_logs
WHERE eventname = 'ConsoleLogin'
AND json_extract_scalar(additionaleventdata,'$.MFAUsed') = 'No';
-- AssumeRole from an unusual external account
SELECT eventtime, useridentity.arn, requestparameters, sourceipaddress
FROM cloudtrail_logs
WHERE eventname = 'AssumeRole';
GUARDDUTY
---------
aws guardduty list-detectors
aws guardduty get-findings --detector-id <id> --finding-ids <ids>
aws guardduty list-findings --detector-id <id> \
--finding-criteria '{"Criterion":{"severity":{"Gte":7}}}'
# GuardDuty flags: credential exfil, crypto-mining, recon,
# anomalous IAM, S3 exfiltration, EC2 C2 patterns
S3 / EXFIL SIGNALS
------------------
# GetObject spikes, ListBuckets sweeps, PutBucketAcl (public),
# GetBucketPolicy, CopyObject cross-account, RestoreObject (glacier)
# Enable S3 data events in CloudTrail to see object-level access
EXAMPLES
--------
# Quick check: was CloudTrail logging ever stopped?
aws cloudtrail lookup-events \
--lookup-attributes AttributeKey=EventName,AttributeValue=StopLogging
# Athena: privilege-escalation policy attachments in last 7 days
# SELECT eventtime, useridentity.arn, eventname, requestparameters
# FROM cloudtrail_logs
# WHERE eventname IN ('AttachUserPolicy','AttachRolePolicy',
# 'PutUserPolicy','CreatePolicyVersion')
# AND eventtime > date_add('day', -7, now());
# High-severity GuardDuty findings only
aws guardduty list-findings --detector-id <id> \
--finding-criteria '{"Criterion":{"severity":{"Gte":7}}}'
NOTES
-----
- Enable CloudTrail in ALL regions + a dedicated logging account;
turn on log file validation to detect tampering
- Management events are free; DATA events (S3/Lambda) cost extra but
are essential for exfil detection
- Root usage, MFA-less console login, and StopLogging/DeleteTrail are
top-priority alerts
- GuardDuty is the fastest managed baseline; complement with custom
Athena/SIEM analytics for IAM escalation chains
- Ship CloudTrail to your SIEM (QRadar/Sentinel) for correlation with
on-prem identity events
- For FS clients, cloud logging gaps are a DORA ICT third-party risk
and CSSF cloud-outsourcing finding
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.