Techniques
Sample rules
AWS CloudTrail Log Created
- source: elastic
- technicques:
- T1530
Description
Identifies the creation of an AWS log trail that specifies the settings for delivery of log data.
Detection logic
event.dataset:aws.cloudtrail and event.provider:cloudtrail.amazonaws.com and event.action:CreateTrail and event.outcome:success