Book a demo call with us
Cross icon
Network

AWS CloudTrail

Coming soon

An AWS service that records all API calls and user activity across an AWS environment, creating a detailed audit trail. It's a foundational data source for cloud forensics, compliance, and threat detection.

AWS CloudTrail

What is AWS CloudTrail?

AWS CloudTrail is the native audit logging service for Amazon Web Services environments. It captures every API call made within an AWS account, whether triggered by a user, a role, or an automated service, and stores those events as structured logs. This creates a complete, tamper-evident record of who did what, when, and from where across the entire AWS infrastructure. CloudTrail is foundational for cloud security operations: it feeds detection rules in SIEM platforms, supports forensic reconstruction of security incidents, and provides the evidentiary trail needed for compliance frameworks like SOC 2, PCI-DSS, and ISO 27001. For SOC teams, it is often the first data source consulted when investigating unusual cloud activity, privilege escalation, or unauthorized resource creation.

How does AWS CloudTrail work with Qevlar?

Qevlar ingests CloudTrail logs to investigate cloud-related alerts automatically. When a detection fires on unusual API behavior, a new IAM role creation, or a suspicious cross-account access pattern, Qevlar can trace the full sequence of events through CloudTrail data without requiring an analyst to manually query the AWS console.

Want to help your analysts focus on the most critical alerts?

Frequently asked questions

What is AWS CloudTrail?

bar
bar

AWS CloudTrail records every API call and user action across an AWS environment, creating a detailed, tamper-evident audit trail that is foundational for cloud forensics, compliance and threat detection.

What can you do with AWS CloudTrail in Qevlar?

bar
bar

Qevlar can read CloudTrail events to investigate cloud alerts automatically — tracing privilege escalation, unusual API behavior or suspicious cross-account access through the full sequence of recorded events, without an analyst querying the AWS console by hand.

Can Qevlar reconstruct what happened during a cloud incident?

bar
bar

Yes. By following the CloudTrail record, Qevlar rebuilds the timeline of who did what, when and from where, then correlates it with identity and network signals to establish the real scope and impact.

Does this work alongside my existing AWS security tooling?

bar
bar

Yes. Qevlar consumes CloudTrail as an investigation data source and complements native AWS services, adding an autonomous investigation layer on top of the telemetry you already collect.

Other integrations