AWS CloudTrail Overview

AWS CloudTrail is a service that enables governance, compliance, operational auditing, and risk auditing of your AWS account.

With CloudTrail, you can log, continuously monitor, and retain events related to API calls across your AWS infrastructure. CloudTrail provides a history of AWS API calls for your account, including API calls made through the AWS Management Console, AWS SDKs, command line tools, and other AWS services. This history simplifies security analysis, resource change tracking, and troubleshooting.

 

Benefits Summary (based on AWS docs)

  1. Simplified Compliance

    1. Simplify your compliance audits by automatically recording and storing activity logs for actions made within your AWS account.

    2. Integration with Amazon CloudWatch Logs provides a convenient way to search through log data, identify out-of-compliance events, accelerate incident investigations, and expedite responses to auditor requests.

  2. Visibility Into User and Resource Activity

    1. CloudTrail increases visibility into your user and resource activity by recording AWS API calls. Can identify which users and accounts called AWS, the source IP address and time.

  3. Security Analysis and Troubleshooting

    1. CloudTrail help you discover and troubleshoot security and operational issues by capturing a comprehensive history of changes that occurred in your AWS account within a specified period of time.

  4. Security Automation

    1. CloudTrail allows you track and automatically respond to API activity threatening the security of your AWS resources.

    2. With Amazon CloudWatch Events integration, you can define workflows that execute when events that can result in security vulnerabilities are detected.

 

Use Cases Summary (based on AWS docs)

  1. Compliance Aid

    1. Ensure compliance with internal policies and regulatory standards.

  2. Security Analysis

    1. Perform security analysis and detect user behavior patterns.

  3. Data Exfiltration

    1. Detect data exfiltration by collecting activity data on S3 objects through object-level API events recorded in CloudTrail.

  4. Operational Issue Troubleshooting

    1. Troubleshoot operational issues by leveraging the AWS API call history.

References (Deprecated): 

Learn Serverless from Serverless Programming Cookbook

Contact

Please first use the contact form or facebook page messaging to connect.

Offline Contact
We currently connect locally for discussions and sessions at Bangalore, India. Please follow us on our facebook page for details.
WhatsApp (Primary): (+91) 7411174113
Phone (Escalations): (+91) 7411174114

Business newsletter

Complete the form below, and we'll send you an e-mail every now and again with all the latest news.

About

CloudMaterials is my blog to share notes and learning materials on Cloud and Data Analytics. My current focus is on Microsoft Azure and Amazon Web Services (AWS).

I like to write and I try to document what I learn to share with others. I believe that knowledge is useless unless you share it; the more you share, the more you learn.

Recent comments

Photo Stream