Skip to content
cloud-security

CloudTrail

AWS CloudTrail

Definition

AWS CloudTrail records API calls made to AWS services, capturing the caller identity, timestamp, source IP, request parameters, and response elements for every action. It provides an immutable audit trail for detecting unauthorized access, investigating incidents, and demonstrating compliance.

CloudTrail logs should be centralized in a dedicated logging account, protected with S3 Object Lock, and streamed to a SIEM for real-time threat detection.


Ship secure code faster

Crash Override integrates security into the developer workflow. No context switching, no waiting on reviews.