AWS Detection Engineering: Logs Sources & Events Guide
ID: 3c41b433-51cd-5893-821a-6fa90efcdea7
STIX ID: report--3c41b433-51cd-5893-821a-6fa90efcdea7
Feed Name: Sekoia.com
This blog-style guide explains AWS detection engineering best practices: which log sources to collect (CloudTrail, Flow Logs, GuardDuty), detection approaches for each, and specific CloudTrail events and TTPs to monitor across the attack lifecycle (initial access, persistence, defense evasion, discovery, exfiltration, impact). It provides concrete event names (e.g., AttachUserPolicy/AWSCompromisedKeyQuarantineV2, CreateKeyPair, DeleteTrail, CreateInstanceExportTask, RunInstances/UserData) and recommends how to prioritize alerts and use CTI to match Flow Logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
