Glossary

Logging Gaps to Test For:

CloudTrail not enabled in all regions (attackers operate in unexpected regions) - Data events not logged (S3 object-level access, Lambda invocations) - Management events filtered (some API calls not recorded) - Log file validation not enabled (logs can be tampered with) - CloudTrail logs stored in a

Learn More

Related Terms