Get a Demo
Under Attack?
Diagram featuring colorful, dotted paths connecting cloud and security icons, including AWS. The upwind logo is in the top left corner. The background is white.

How Upwind Leverages AWS CloudTrail for Enhanced Threat Detection Capabilities

<br />
<b>Warning</b>:  Undefined variable $photo in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
<br />
<b>Warning</b>:  Trying to access array offset on value of type null in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
Denise Ashur December 11, 2024

How Upwind Leverages AWS CloudTrail for Enhanced Threat Detection Capabilities

As a part of Upwind’s runtime-powered threat detection capabilities, the Upwind Platform integrates seamlessly with AWS CloudTrail to provide real-time monitoring and detection of cloud logs. By leveraging AWS CloudTrail Logs generated at runtime, Upwind is able to provide deep runtime context and automatically alert you to suspicious or malicious log events.

What is CloudTrail?

AWS CloudTrail is a service that enables monitoring and logging of activities across your AWS infrastructure. CloudTrail logs provide detailed records of API calls and user activities, including the initiator (who made the call), involved services and resources, as well as the time and location of each activity. These logs are crucial for security auditing, compliance, and troubleshooting. 

AWS-CloudTrail-1--1024x557

CloudTrail logs events from actions performed by users, roles, and AWS services. These events can include:

  • Creating or deleting Amazon Simple Storage Service (S3) buckets
  • Reading or writing an Amazon S3 object
  • Actions made using VPC endpoints
  • API calls that were denied access 

In addition to capturing detailed event data, CloudTrail helps organizations maintain transparency by providing a history of AWS account activity. This is particularly useful for tracking changes made by various users, roles, and services within the AWS environment. CloudTrail supports multiple log formats, including Apache ORC, which is optimized for performance and query efficiency when analyzing large datasets.

How Upwind Leverages CloudTrail 

Upwind’s CloudTrail integration uses CloudTrail logs to identify and analyze potential security threats, enhancing our comprehensive threat detection capabilities

AWS-CloudTrail-2-1024x636

Using CloudTrail logs, Upwind monitors for suspicious activities that may indicate security incidents, such as unauthorized access attempts, data exfiltration, or policy violations.

Screenshot-2024-11-11-at-6.50.03%E2%80%AFAM-1024x634

Using CloudTrail Logs, Upwind provides numerous detections that center around unusual behaviors, focusing on:

  • Unauthorized Access Attempts: CloudTrail logs can reveal attempts to access AWS resources from unauthorized users or unexpected locations.
  • Suspicious API Activity: Analyze the “What” and “Where” of API calls (actions and resources) to identify specific API calls that are sensitive or indicative of malicious activities.

Upwind’s CloudTrail event analysis detects attempts or successful executions of specific actions, indicating the initiator and on which resource the action was performed. For example, you can easily identify actions like the following:

  • S3 Bucket Made Public
  • Security Group Modification
  • Lambda Function Deletion
  • Deactivation of MFA on an IAM User

By monitoring for all of these events at runtime, Upwind is able to alert you the second suspicious or malicious events occur.

How to Deploy the CloudTrail Integration


Deploying Upwind’s CloudTrail integration is straightforward, requiring only a provided CloudFormation or Terraform template. Within minutes, you begin receiving new detections and enriched information.

AWS-CloudTrail-3-1024x577

Learn More

To learn more about Upwind’s use of AWS CloudTrail for real-time threat detections, visit the Upwind Documentation Center (login required), or schedule a demo.

Contents

Further Reading

API-ASM Blog

Validate the Real-World Exposure of Your APIs with Upwind Attack Surface Management

Your APIs are probably the least-monitored component of your attack surface. They multiply faster than any team can document, and most scanners only ever pick up the ones you already know about. But that gap just got smaller. Upwind’s Attack Surface Management capabilities now provide a unified view of cloud and API exposure, helping security…
gemini-svg

Metabase Instances Actively Exploited: Unauthenticated Admin Takeover via BI Layer Reset Password SQL Injection (CVE-2026-72898)

Executive Summary Upwind recently observed multiple Advanced Persistent Threat (APT) groups actively exploiting CVE-2026-72898. This vulnerability - an unauthenticated SQL injection in the Metabase password reset endpoint carrying a critical CVSS score of 10.0, was actively exploited as a zero-day before a patch became available. An unauthenticated remote attacker can craft a malicious SQL injection…
Buyers Demos

Why Buyers Remember Solving a Demo, Not Watching One

Key Takeaways I recently sat down with Upwind Solutions Architect, Evan Grace to learn more about his process. After some intros, he told me about his new hobby, hydroponics. For those who don’t know, hydroponics is a method of growing plants without soil. This was unbelievable to me but after Evan explained his deep dive…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS