1---2name: performing-cloud-forensics-with-aws-cloudtrail3description: Perform forensic investigation of AWS environments using CloudTrail logs to reconstruct attacker activity, identify compromised credentials, and analyze API call patterns.4license: Apache-2.05---67# Performing Cloud Forensics with AWS CloudTrail89## When to Use1011- When investigating suspected AWS account compromise12- After detecting unauthorized API calls or credential exposure13- During incident response involving cloud infrastructure14- When analyzing S3 data exfiltration or IAM privilege escalation15- For post-incident forensic timeline reconstruction1617## Detection Gaps & Validation1819- **LookupEvents won't show data-plane activity:** `cloudtrail:LookupEvents` returns only management events for the last 90 days. S3 `GetObject`, `PutObject`, and Lambda `Invoke` are *data events*, absent unless data event logging was enabled before the incident - pivot to S3 server access logs / Athena to prove exfiltration.20- **Single-region or non-org trails leave blind spots:** an attacker operating in an unmonitored region produces no events in a region-scoped trail. Confirm the trail is multi-region and org-wide via `aws cloudtrail describe-trails` (`IsMultiRegionTrail`, `IsOrganizationTrail`).21- **Check for anti-forensics first:** hunt `StopLogging`, `UpdateTrail`, `DeleteTrail`, and `PutEventSelectors` events - an attacker may have blinded logging. Then run `aws cloudtrail validate-logs` against the digest files to detect deletion/tampering.22- **Attribute actions correctly:** track both `userIdentity.accessKeyId` and `sessionContext.sessionIssuer` - an `AssumeRole` issues temporary keys (`ASIA...`), so following only the original key loses the attacker after the pivot.23- **`AccessDenied` is signal, not noise:** denied calls are still logged and reveal recon and failed escalation; don't filter them out of the timeline.24- **How to confirm a finding:** corroborate the CloudTrail timeline against VPC Flow Logs (same source IP) and the resource's own logs, and remember every `eventTime` is UTC when sequencing events.25- **Don't conclude "no compromise" until** data events are accounted for (or shown to have been disabled), the trail covered all regions, and logging-tamper events plus digest validation have been checked.2627## Prerequisites2829- AWS account with CloudTrail enabled (management and data events)30- IAM permissions for cloudtrail:LookupEvents, s3:GetObject, athena:StartQueryExecution31- boto3 Python SDK installed32- CloudTrail logs delivered to S3 with optional Athena table configured33- AWS CLI configured with appropriate credentials3435## Workflow36371. **Scope Investigation**: Identify timeframe, affected accounts, and compromised credentials.382. **Query CloudTrail**: Use boto3 lookup_events or Athena to retrieve relevant API events.393. **Filter by Indicators**: Search for suspicious user agents, source IPs, and event names.404. **Reconstruct Timeline**: Build chronological sequence of attacker actions from API calls.415. **Analyze Access Patterns**: Identify data access, IAM changes, and resource modifications.426. **Identify Persistence**: Check for new IAM users, access keys, roles, or Lambda functions.437. **Generate Report**: Produce forensic timeline with findings and remediation steps.4445## Key Concepts4647| Concept | Description |48|---------|-------------|49| LookupEvents | CloudTrail API to query management events (last 90 days) |50| Athena Queries | SQL queries against CloudTrail logs in S3 for historical analysis |51| User Agent Analysis | Identify tool signatures (AWS CLI, SDK, console, custom) |52| AccessKeyId | Track activity by specific IAM access key |53| EventName | AWS API action name (e.g., GetObject, CreateUser, AssumeRole) |54| sourceIPAddress | Origin IP of API call for geolocation analysis |5556## Tools & Systems5758| Tool | Purpose |59|------|---------|60| boto3 CloudTrail client | Programmatic CloudTrail event lookup |61| AWS Athena | SQL-based analysis of CloudTrail S3 logs |62| AWS CLI | Command-line CloudTrail queries |63| jq | JSON processing for CloudTrail event parsing |64| CloudTrail Lake | Advanced event data store with SQL query support |6566## Output Format6768```69Forensic Report: AWS-IR-[DATE]-[SEQ]70Account: [AWS Account ID]71Timeframe: [Start] to [End]72Compromised Credentials: [Access Key IDs]73Suspicious Events: [Count]74Source IPs: [List of attacker IPs]75Actions Taken: [API calls by attacker]76Data Accessed: [S3 objects, secrets, etc.]77Persistence Mechanisms: [New users, keys, roles]78```