logo

Generate Security Signals with Sumo Logic & AWS Cloudtrail

ID: 7c38748c-bbb2-501c-a1b7-fa60313a6b2b

STIX ID: report--7c38748c-bbb2-501c-a1b7-fa60313a6b2b

Feed Name: Expel Blog

Date Published: 2019-09-10

Date Updated: 2026-04-27

Author: Dan Whalen

...
...

**Executive summary:** This post describes how to use AWS CloudTrail data in a SIEM (example: Sumo Logic) to detect risky or malicious activity in cloud environments, providing concrete detection use cases (suspicious logins with missing MFA and anomalous geolocation, account enumeration signaled by bursts of AccessDenied errors, persistence via Lambda creating keys or modifying policies, and log-deletion/StopLogging actions), example queries, tuning advice, and operational recommendations for alert triage and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.