Get a Demo
Under Attack?
Diagram featuring colorful, dotted paths connecting cloud and security icons, including AWS. The upwind logo is in the top left corner. The background is white.

How Upwind Leverages AWS CloudTrail for Enhanced Threat Detection Capabilities

Denise Ashur December 11, 2024

How Upwind Leverages AWS CloudTrail for Enhanced Threat Detection Capabilities

As a part of Upwind’s runtime-powered threat detection capabilities, the Upwind Platform integrates seamlessly with AWS CloudTrail to provide real-time monitoring and detection of cloud logs. By leveraging AWS CloudTrail Logs generated at runtime, Upwind is able to provide deep runtime context and automatically alert you to suspicious or malicious log events.

What is CloudTrail?

AWS CloudTrail is a service that enables monitoring and logging of activities across your AWS infrastructure. CloudTrail logs provide detailed records of API calls and user activities, including the initiator (who made the call), involved services and resources, as well as the time and location of each activity. These logs are crucial for security auditing, compliance, and troubleshooting. 

AWS-CloudTrail-1--1024x557

CloudTrail logs events from actions performed by users, roles, and AWS services. These events can include:

  • Creating or deleting Amazon Simple Storage Service (S3) buckets
  • Reading or writing an Amazon S3 object
  • Actions made using VPC endpoints
  • API calls that were denied access 

In addition to capturing detailed event data, CloudTrail helps organizations maintain transparency by providing a history of AWS account activity. This is particularly useful for tracking changes made by various users, roles, and services within the AWS environment. CloudTrail supports multiple log formats, including Apache ORC, which is optimized for performance and query efficiency when analyzing large datasets.

How Upwind Leverages CloudTrail 

Upwind’s CloudTrail integration uses CloudTrail logs to identify and analyze potential security threats, enhancing our comprehensive threat detection capabilities

AWS-CloudTrail-2-1024x636

Using CloudTrail logs, Upwind monitors for suspicious activities that may indicate security incidents, such as unauthorized access attempts, data exfiltration, or policy violations.

Screenshot-2024-11-11-at-6.50.03%E2%80%AFAM-1024x634

Using CloudTrail Logs, Upwind provides numerous detections that center around unusual behaviors, focusing on:

  • Unauthorized Access Attempts: CloudTrail logs can reveal attempts to access AWS resources from unauthorized users or unexpected locations.
  • Suspicious API Activity: Analyze the “What” and “Where” of API calls (actions and resources) to identify specific API calls that are sensitive or indicative of malicious activities.

Upwind’s CloudTrail event analysis detects attempts or successful executions of specific actions, indicating the initiator and on which resource the action was performed. For example, you can easily identify actions like the following:

  • S3 Bucket Made Public
  • Security Group Modification
  • Lambda Function Deletion
  • Deactivation of MFA on an IAM User

By monitoring for all of these events at runtime, Upwind is able to alert you the second suspicious or malicious events occur.

How to Deploy the CloudTrail Integration


Deploying Upwind’s CloudTrail integration is straightforward, requiring only a provided CloudFormation or Terraform template. Within minutes, you begin receiving new detections and enriched information.

AWS-CloudTrail-3-1024x577

Learn More

To learn more about Upwind’s use of AWS CloudTrail for real-time threat detections, visit the Upwind Documentation Center (login required), or schedule a demo.

Contents

Further Reading

Yuval_ArgoCD Research

ArgoCD repoURL XSS: How a Missing Scheme Check Becomes Cluster Takeover 

Executive Summary  This stored cross-site scripting (XSS) vulnerability in ArgoCD [versions <= 3.4.4] allows an attacker who can create or modify an Application to persist a malicious repoURL, which is subsequently executed in an administrator's browser within the Argo CD origin. Because the payload executes in the context of the administrator's authenticated session, and because…
Custom-Reporting-Hero

Security Reporting Built Around Your Program

We've all been there: it's 3:00 PM on a Friday, and you get that "quick" request for a specific security status report. Suddenly, your afternoon is gone as you juggle filters, export CSVs, and try to explain to someone outside the security team why these numbers actually matter. Reporting shouldn't feel like a fire drill…
Blue-agent-blog

Introducing the Upwind Blue Agent: Autonomous Threat Investigation for the SOC

We’re excited to announce that the Upwind Blue Agent is now available in Beta. Blue is an AI-powered SOC investigator that autonomously investigates Upwind Threat Stories end to end. It gathers and correlates security context across the customer environment, evaluates the available evidence, and delivers one of three clear verdicts: Each verdict includes supporting reasoning…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS