logo

TrailShark: Understanding AWS API and Service Interactions

ID: 390b6a3a-9c4e-57e3-8d6e-259cdb71f512

STIX ID: report--390b6a3a-9c4e-57e3-8d6e-259cdb71f512

Feed Name: Aqua Security Blog

Threat Score
55/100

Date Published: 2024-08-09

Date Updated: 2026-04-26

...
...

This blog introduces TrailShark, an open-source tool that feeds AWS CloudTrail events into Wireshark for near-real-time analysis and custom event detection; the authors used it during "Bucket Monopoly" research to uncover six AWS vulnerabilities (ranging from RCE and service takeover to data exposure and DoS) and demonstrate how inner API call visibility can reveal hidden resource creation and suspicious behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.