AuthenticationwindowsPro
AWS CloudTrail
The control plane record for an AWS account: who called which API, from where, with which credential. It is the single most important artifact in a cloud incident and it has a gap most people discover during one.
What members see here
- Every path this artifact lives at, and which builds each applies to.
- What it proves, and what it does not prove, which is the part that matters.
- How to parse it, and the tooling that reads it correctly.
- Hunting queries for Splunk, Sentinel and Elastic, with their false-positive notes.