Log sources › AWS:CloudTrail
AWS:CloudTrail
Inverted view: what can be detected if this is the log you have. Containers, IaaS, Identity Provider, SaaS, Windows
106
channels
92
analytics
89
techniques
119
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
AWS ConsoleLogin, StartSession |
DC0067 Logon Session Creation | AN0753 | 1 |
AWS IAM: ListUsers, ListRoles |
DC0002 User Account Authentication | AN1088 | 1 |
AssumeRole |
DC0013 User Account Metadata | AN0417 AN0958 AN0960 AN1328 | 3 |
AssumeRole or ConsoleLogin with repeated MFA failures followed by repeated MFA requests |
DC0002 User Account Authentication | AN0450 | 1 |
AssumeRole, GetFederationToken API calls by unusual or new entities |
DC0006 Web Credential Creation | AN0717 | 1 |
AssumeRole, GetFederationToken, GetSessionToken |
DC0007 Web Credential Usage | AN0526 | 1 |
AssumeRole,AssumeRoleWithSAML,AssumeRoleWithWebIdentity |
DC0067 Logon Session Creation | AN1348 | 1 |
AssumeRole: Discovery actions tied to assumed identities outside of normal context |
DC0013 User Account Metadata | AN1127 | 1 |
AssumeRoleWithSAML |
DC0007 Web Credential Usage | AN0419 | 1 |
AssumeRoleWithWebIdentity |
DC0002 User Account Authentication | AN0530 | 1 |
AttachUserPolicy |
DC0010 User Account Modification | AN0900 AN1608 | 2 |
AttachUserPolicy, CreatePolicyVersion, PutRolePolicy |
DC0010 User Account Modification | AN0771 | 1 |
AuthorizeSecurityGroupIngress |
DC0051 Firewall Rule Modification | AN0492 AN2041 | 2 |
ConsoleLogin |
DC0067 Logon Session Creation | AN0201 AN0808 | 2 |
ConsoleLogin or AssumeRole |
DC0002 User Account Authentication | AN1285 | 1 |
ConsoleLogin, AssumeRole, ListAccessKeys, CreateUser |
DC0002 User Account Authentication | AN1504 | 1 |
ConsoleLogin, AssumeRole, ListResources |
DC0067 Logon Session Creation | AN0017 | 1 |
ConsoleLogin: If IdP backed by cloud provider, Console login from new IP/agent after correlated endpoint compromise |
DC0067 Logon Session Creation | AN0501 | 1 |
CopySnapshot |
DC0062 Snapshot Metadata | AN1580 | 1 |
Create egress rule allowing UDP to port 53, 123, 11211 |
DC0051 Firewall Rule Modification | AN1143 | 1 |
CreateAccessKey, ImportKeyPair, CreateLoginProfile, CreateKeyPair |
DC0087 Active Directory Object Creation | AN1470 | 1 |
CreateBucket |
DC0024 Cloud Storage Creation | AN0690 | 1 |
CreateFunction |
DC0069 Cloud Service Modification | AN0027 | 1 |
CreateFunction / UpdateFunctionConfiguration: Function creation, role assignment, or configuration change events |
DC0069 Cloud Service Modification | AN1053 | 1 |
CreatePod: Programmatic creation of new pod resources using container images not seen before in the environment |
DC0019 Pod Creation | AN0233 | 1 |
CreateSnapshot |
DC0057 Snapshot Creation | AN0861 AN1187 AN1580 | 3 |
CreateTrafficMirrorSession / ModifyTrafficMirrorTarget |
DC0069 Cloud Service Modification | AN0878 | 1 |
CreateTrafficMirrorSession or ModifyTrafficMirrorTarget |
DC0078 Network Traffic Flow | AN1131 | 1 |
CreateUser |
DC0014 User Account Creation | AN0900 AN1608 | 2 |
CreateUser|AttachRolePolicy|CreateAccessKey|UpdateAssumeRolePolicy|CreateLoginProfile |
DC0038 Application Log Content | AN1348 | 1 |
CreateVolume |
DC0097 Volume Creation | AN0861 | 1 |
Decrypt |
DC0021 OS API Execution | AN1201 | 1 |
Delete* / Stop*: DeleteAlarms, StopLogging, or DisableMonitoring API calls |
DC0069 Cloud Service Modification | AN1372 | 1 |
DeleteBucket, DeleteDBCluster, DeleteSnapshot, TerminateInstances |
DC0022 Cloud Storage Deletion | AN0414 AN0937 | 2 |
DeleteSnapshot |
DC0049 Snapshot Deletion | AN0861 AN0937 | 2 |
DeleteVolume, ModifyVolume |
DC0098 Volume Deletion | AN0861 | 1 |
Describe* or List* API calls |
DC0021 OS API Execution | AN0908 | 1 |
DescribeDBInstances |
DC0075 Instance Enumeration | AN0481 | 1 |
DescribeInstances |
DC0086 Instance Metadata | AN0234 AN0481 AN1242 | 3 |
DescribeInstances, DescribeServices, ListFunctions: High frequency enumeration calls or unusual user agents performing discovery |
DC0083 Cloud Service Enumeration | AN1127 | 1 |
DescribeInstances, GetConsoleOutput, DescribeImages |
DC0075 Instance Enumeration | AN1456 | 1 |
DescribeSnapshots |
DC0062 Snapshot Metadata | AN1187 | 1 |
DescribeUsers / ListUsers / GetUser |
DC0083 Cloud Service Enumeration | AN1615 | 1 |
GetAccountPasswordPolicy |
DC0013 User Account Metadata | AN0458 | 1 |
GetCallerIdentity |
DC0007 Web Credential Usage | AN0960 | 1 |
GetInstanceIdentityDocument |
DC0070 Cloud Service Metadata | AN0001 | 1 |
GetInstanceIdentityDocument or IMDSv2 token requests |
DC0083 Cloud Service Enumeration | AN1424 | 1 |
GetLogEvents: High frequency log exports from CloudWatch or equivalent services |
DC0064 Command Execution | AN0708 | 1 |
GetMetadata, DescribeInstanceIdentity |
DC0021 OS API Execution | AN0122 | 1 |
GetObject, CopyObject |
DC0025 Cloud Storage Access | AN0043 AN0198 AN0370 AN0666 AN1328 AN1594 AN1625 | 7 |
GetSecretValue |
DC0070 Cloud Service Metadata DC0083 Cloud Service Enumeration |
AN0366 AN1157 AN1201 | 3 |
GetSessionToken, AssumeRoleWithWebIdentity |
DC0007 Web Credential Usage | AN0483 | 1 |
Ingress rule creation or modification for security group |
DC0051 Firewall Rule Modification | AN1188 | 1 |
InvokeFunction |
DC0064 Command Execution DC0070 Cloud Service Metadata |
AN0027 AN1168 | 2 |
InvokeFunction: Unexpected or repeated invocation of functions not tied to known workflows |
DC0038 Application Log Content | AN1053 | 1 |
LeaveOrganization: API calls severing accounts from AWS Organizations |
DC0069 Cloud Service Modification | AN0442 | 1 |
ListBuckets |
DC0017 Cloud Storage Enumeration | AN0481 AN1625 | 2 |
ListGroups, ListAttachedRolePolicies |
DC0099 Group Enumeration | AN0695 | 1 |
ListObjectsV2 |
DC0017 Cloud Storage Enumeration | AN1594 | 1 |
ModifyImageAttribute |
DC0036 Image Modification | AN0947 | 1 |
ModifyInstanceAttribute |
DC0073 Instance Modification | AN2041 | 1 |
ModifySnapshotAttribute |
DC0058 Snapshot Modification | AN0861 AN1580 | 2 |
ModifyVolume |
DC0092 Volume Modification | AN0861 | 1 |
PassRole |
DC0013 User Account Metadata | AN1105 | 1 |
Post-authentication metadata enumeration from GUI session |
DC0027 Cloud Storage Metadata | AN0808 | 1 |
PutBucketLifecycle, PutLifecycleConfiguration, SetBucketLifecycle, storage.buckets.update |
DC0023 Cloud Storage Modification | AN0117 | 1 |
PutBucketPolicy |
DC0023 Cloud Storage Modification | AN1580 | 1 |
PutIdentityPolicy |
DC0069 Cloud Service Modification | AN0417 | 1 |
PutObject |
DC0039 File Creation | AN1625 | 1 |
PutObject (with SSE-C), UploadPart (SSE-C) |
DC0023 Cloud Storage Modification | AN0606 | 1 |
PutObject: S3 writes with .sql/.csv extension by same identity or within 5 min of DB access |
DC0025 Cloud Storage Access | AN0679 | 1 |
PutUserPolicy, PutGroupPolicy, PutRolePolicy, CreatePolicyVersion |
DC0069 Cloud Service Modification | AN0087 | 1 |
RegisterImage |
DC0015 Image Creation | AN0947 | 1 |
Removal of restrictive egress rules from a security group |
DC0043 Firewall Disable | AN1188 | 1 |
RequestServiceQuotaIncrease |
DC0069 Cloud Service Modification | AN1356 | 1 |
RevertSnapshot |
DC0073 Instance Modification | AN0953 | 1 |
RunInstances |
DC0080 Instance Start | AN0690 AN0692 AN0744 AN0861 AN0947 AN1242 AN1493 | 7 |
RunInstances,CreateImage |
DC0076 Instance Creation | AN1318 | 1 |
SSM RunCommand |
DC0064 Command Execution | AN0626 | 1 |
SendCommand, StartSession, ExecuteCommand: Unexpected AWS Systems Manager command execution targeting EC2 instances |
DC0064 Command Execution | AN1502 | 1 |
SendEmail |
DC0038 Application Log Content | AN0417 | 1 |
SendSSHPublicKey, StartSession (SSM), EC2InstanceConnect |
DC0067 Logon Session Creation | AN0594 | 1 |
SessionToken used without preceding MFA or login event |
DC0007 Web Credential Usage | AN0201 | 1 |
StartInstances |
DC0080 Instance Start | AN0084 AN0587 AN0953 AN1318 | 4 |
Stop logging for an existing CloudTrail |
DC0090 Cloud Service Disable | AN0801 | 1 |
StopInstances |
DC0089 Instance Stop | AN0953 | 1 |
StopLogging, DeleteTrail, UpdateTrail: API calls that disable or modify logging services |
DC0038 Application Log Content | AN1636 | 1 |
StopLogging, DeleteTrail, or DisableSecurityService |
DC0090 Cloud Service Disable | AN0891 AN2041 | 1 |
Temporary security credentials used to authenticate into management console or APIs |
DC0067 Logon Session Creation | AN0717 | 1 |
TerminateInstances |
DC0089 Instance Stop | AN0234 AN0853 AN0861 | 3 |
UpdateAccountPasswordPolicy |
DC0069 Cloud Service Modification | AN0291 | 1 |
UpdateFederationSettings or RegisterHybridConnector |
DC0069 Cloud Service Modification | AN0816 | 1 |
UpdateIdentityPolicy or DisableMFA |
DC0069 Cloud Service Modification | AN0545 | 1 |
UpdateLoginProfile |
DC0010 User Account Modification | AN0291 | 1 |
Use of temporary credentials issued from IMDS access |
DC0069 Cloud Service Modification | AN1424 | 1 |
Web console logins using session cookies without corresponding MFA event |
DC0067 Logon Session Creation | AN0483 | 1 |
command-line execution invoking credential enumeration |
DC0064 Command Execution | AN0860 | 1 |
cross-account or unexpected assume role |
DC0034 Process Metadata | AN0979 | 1 |
eventName: RunInstances, CreateUser, PutRolePolicy, InvokeCommand |
DC0064 Command Execution | AN0215 | 1 |
eventName=ConsoleLogin | eventType=AwsConsoleSignIn |
DC0002 User Account Authentication | AN1270 | 1 |
rds:ExecuteStatement: Large data access via RDS or Aurora with unknown session context |
DC0070 Cloud Service Metadata | AN0679 | 1 |
role privilege expansion detected |
DC0010 User Account Modification | AN0979 | 1 |
ssm:GetCommandInvocation |
DC0064 Command Execution | AN1103 | 1 |
ssm:ListInventoryEntries |
DC0083 Cloud Service Enumeration | AN1103 | 1 |
sts:GetFederationToken |
DC0002 User Account Authentication | AN0526 | 1 |
sudden role assumption after credential file access |
DC0067 Logon Session Creation | AN0860 | 1 |
Techniques detectable from this source
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2009-3960 | Adobe BlazeDS | T1486 | Mapped |
| CVE-2010-0188 | Adobe Reader and Acrobat | T1189 | Mapped |
| CVE-2010-1297 | Adobe Flash Player | T1189 | Mapped |
| CVE-2012-2034 | Adobe Flash Player | T1189 | Mapped |
| CVE-2012-5054 | Adobe Flash Player | T1189 | Mapped |
| CVE-2013-0641 | Adobe Reader | T1048 | Mapped |
| CVE-2014-8439 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-0310 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-0313 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-3043 | Adobe Flash Player | T1189 T1499.004 | Mapped |
| CVE-2015-8651 | Adobe Flash Player | T1189 T1486 | Mapped |
| CVE-2016-1019 | Adobe Flash Player | T1189 T1486 | Mapped |
| CVE-2016-7855 | Adobe Flash Player | T1189 | Mapped |
| CVE-2017-12637 | SAP NetWeaver | T1555 | Mapped |
| CVE-2017-6742 | Cisco IOS and IOS XE Software | T1048 | Mapped |
| CVE-2017-9822 | DotNetNuke (DNN) DotNetNuke (DNN) | T1496 | Mapped |
| CVE-2018-11776 | Apache Struts | T1496 | Mapped |
| CVE-2018-15961 | Adobe ColdFusion | T1491.002 | Mapped |
| CVE-2018-7600 | Drupal Drupal Core | T1485 T1496 | Mapped |
| CVE-2019-11510 | Ivanti Pulse Connect Secure | T1552.001 | Mapped |
| CVE-2019-11634 | Citrix Workspace Application and Receiver for Windows | T1486 | Mapped |
| CVE-2019-1653 | Cisco Small Business RV320 and RV325 Routers | T1082 | Mapped |
| CVE-2019-18935 | Progress Telerik UI for ASP.NET AJAX | T1496 | Mapped |
| CVE-2020-12812 | Fortinet FortiOS | T1556 | Mapped |
| CVE-2020-1472 | Microsoft Netlogon | T1021 T1486 | Mapped |
| CVE-2020-5735 | Amcrest Cameras and Network Video Recorder (NVR) | T1499 | Mapped |
| CVE-2020-5902 | F5 BIG-IP | T1552 | Stale |
| CVE-2020-8193 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1556 | Mapped |
| CVE-2020-8195 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1082 | Mapped |
| CVE-2020-8196 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1082 | Mapped |
| CVE-2020-8515 | DrayTek Multiple Vigor Routers | T1496 | Mapped |
| CVE-2021-22205 | GitLab Community and Enterprise Editions | T1496 | Mapped |
| CVE-2021-22986 | F5 BIG-IP and BIG-IQ Centralized Management | T1485 | Mapped |
| CVE-2021-26084 | Atlassian Confluence Server and Data Center | T1496 | Mapped |
| CVE-2021-32030 | ASUS Routers | T1040 | Mapped |
| CVE-2021-34473 | Microsoft Exchange Server | T1136 T1486 | Mapped |
| CVE-2021-35394 | Realtek Jungle Software Development Kit (SDK) | T1496 T1499 | Mapped |
| CVE-2021-39226 | Grafana Labs Grafana | T1485 | Mapped |
| CVE-2021-40449 | Microsoft Windows | T1082 | Mapped |
| CVE-2021-40539 | Zoho ManageEngine | T1136 | Mapped |
| CVE-2021-42258 | BQE BillQuick Web Suite | T1486 | Mapped |
| CVE-2021-44077 | Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | T1136 | Mapped |
| CVE-2021-44228 | Apache Log4j2 | T1486 T1496 | Mapped |
| CVE-2021-44515 | Zoho Desktop Central | T1087 | Mapped |
| CVE-2021-45046 | Apache Log4j2 | T1486 | Mapped |
| CVE-2021-45382 | D-Link Multiple Routers | T1499.002 | Mapped |
| CVE-2022-1040 | Sophos Firewall | T1040 | Mapped |
| CVE-2022-1388 | F5 BIG-IP | T1548 | Mapped |
| CVE-2022-21999 | Microsoft Windows | T1211 | Mapped |
| CVE-2022-22947 | VMware Spring Cloud Gateway | T1486 | Mapped |
| CVE-2022-23131 | Zabbix Frontend | T1548 | Mapped |
| CVE-2022-26138 | Atlassian Confluence | T1552.001 | Mapped |
| CVE-2022-26258 | D-Link DIR-820L | T1499.002 | Mapped |
| CVE-2022-26500 | Veeam Backup & Replication | T1048 | Mapped |
| CVE-2022-26501 | Veeam Backup & Replication | T1048 | Mapped |
| CVE-2022-29303 | SolarView Compact | T1496 | Mapped |
| CVE-2022-29464 | WSO2 Multiple Products | T1496 | Mapped |
| CVE-2022-41082 | Microsoft Exchange Server | T1087 | Mapped |
| CVE-2022-41328 | Fortinet FortiOS | T1049 | Mapped |
| CVE-2023-0669 | Fortra GoAnywhere MFT | T1486 | Mapped |
| CVE-2023-1389 | TP-Link Archer AX21 | T1496 | Mapped |
| CVE-2023-20109 | Cisco IOS and IOS XE | T1499 | Mapped |
| CVE-2023-20198 | Cisco IOS XE Web UI | T1136 | Mapped |
| CVE-2023-22515 | Atlassian Confluence Data Center and Server | T1136 | Mapped |
| CVE-2023-22527 | Atlassian Confluence Data Center and Server | T1496 | Mapped |
| CVE-2023-22952 | SugarCRM Multiple Products | T1530 | Stale |
| CVE-2023-27532 | Veeam Backup & Replication | T1087 T1486 T1555 | Mapped |
| CVE-2023-27997 | Fortinet FortiOS and FortiProxy SSL-VPN | T1136 | Mapped |
| CVE-2023-28252 | Microsoft Windows | T1021 T1136 T1486 | Mapped |
| CVE-2023-32315 | Ignite Realtime Openfire | T1496 | Mapped |
| CVE-2023-34362 | Progress MOVEit Transfer | T1082 T1136 | Mapped |
| CVE-2023-35078 | Ivanti Endpoint Manager Mobile (EPMM) | T1136 | Mapped |
| CVE-2023-36884 | Microsoft Windows | T1486 T1490 | Stale |
| CVE-2023-38035 | Ivanti Sentry | T1496 | Mapped |
| CVE-2023-38831 | RARLAB WinRAR | T1204 T1486 | Mapped |
| CVE-2023-43770 | Roundcube Webmail | T1082 T1189 | Mapped |
| CVE-2023-44221 | SonicWall SMA100 Appliances | T1548 | Mapped |
| CVE-2023-44487 | IETF HTTP/2 | T1499 | Mapped |
| CVE-2023-46805 | Ivanti Connect Secure and Policy Secure | T1555 | Mapped |
| CVE-2023-47565 | QNAP VioStor NVR | T1496 | Mapped |
| CVE-2023-49103 | ownCloud ownCloud graphapi | T1552 | Mapped |
| CVE-2023-49897 | FXC AE1021, AE1021PE | T1496 | Mapped |
| CVE-2023-6549 | Citrix NetScaler ADC and NetScaler Gateway | T1499 | Mapped |
| CVE-2023-7024 | Google Chromium WebRTC | T1189 | Mapped |
| CVE-2024-13159 | Ivanti Endpoint Manager (EPM) | T1087 | Mapped |
| CVE-2024-13160 | Ivanti Endpoint Manager (EPM) | T1087 | Mapped |
| CVE-2024-13161 | Ivanti Endpoint Manager (EPM) | T1087 | Mapped |
| CVE-2024-20439 | Cisco Smart Licensing Utility | T1552 | Mapped |
| CVE-2024-21887 | Ivanti Connect Secure and Policy Secure | T1552 | Mapped |
| CVE-2024-21893 | Ivanti Connect Secure, Policy Secure, and Neurons | T1555 | Mapped |
| CVE-2024-23692 | Rejetto HTTP File Server | T1082 T1496 | Mapped |
| CVE-2024-38112 | Microsoft Windows | T1189 | Mapped |
| CVE-2024-38475 | Apache HTTP Server | T1528 | Mapped |
| CVE-2024-4671 | Google Chromium | T1189 | Mapped |
| CVE-2024-49035 | Microsoft Partner Center | T1530 | Mapped |
| CVE-2024-4947 | Google Chromium V8 | T1189 | Mapped |
| CVE-2024-5274 | Google Chromium V8 | T1189 | Mapped |
| CVE-2024-53704 | SonicWall SonicOS | T1078.004 T1199 | Mapped |
| CVE-2024-54085 | AMI MegaRAC SPx | T1499 | Mapped |
| CVE-2024-55591 | Fortinet FortiOS and FortiProxy | T1021 T1555 | Mapped |
| CVE-2024-57727 | SimpleHelp SimpleHelp | T1552.001 | Mapped |
| CVE-2025-21391 | Microsoft Windows | T1485 T1490 | Mapped |
| CVE-2025-24054 | Microsoft Windows | T1555 | Mapped |
| CVE-2025-24201 | Apple Multiple Products | T1189 | Mapped |
| CVE-2025-24993 | Microsoft Windows | T1204 | Mapped |
| CVE-2025-25181 | Advantive VeraCore | T1485 | Mapped |
| CVE-2025-25257 | Fortinet FortiWeb | T1485 | Mapped |
| CVE-2025-27363 | FreeType FreeType | T1499.004 | Mapped |
| CVE-2025-2783 | Google Chromium Mojo | T1548 | Mapped |
| CVE-2025-31161 | CrushFTP CrushFTP | T1136 | Mapped |
| CVE-2025-42599 | Qualitia Active! Mail | T1499 | Mapped |
| CVE-2025-4632 | Samsung MagicINFO 9 Server | T1496 | Mapped |
| CVE-2025-48927 | TeleMessage TM SGNL | T1555 | Mapped |
| CVE-2025-48928 | TeleMessage TM SGNL | T1555 | Mapped |
| CVE-2025-5419 | Google Chromium V8 | T1189 | Mapped |
| CVE-2025-54309 | CrushFTP CrushFTP | T1021 | Mapped |
| CVE-2025-5777 | Citrix NetScaler ADC and Gateway | T1555 | Mapped |
| CVE-2025-6554 | Google Chromium V8 | T1189 | Mapped |
| CVE-2025-6558 | Google Chromium | T1189 | Mapped |