#aws-cloudtrail
The way one company can bring down half the fucking internet
October 20, 2025 at 2:02 PM
Fun fact: they could have saved roughly $6 on their AWS bill by using S3 Server Access Logs in lieu of CloudTrail data events.
February 8, 2025 at 7:10 PM
It's been awesome getting to team up with @ramimac.me to dig into a new AWS feature! Read our thoughts on AWS's new CloudTrail network activity events (aka VPC endpoint logs): www.wiz.io/blog/aws-vpc...
CloudTrail Network Activity Events for AWS VPC Endpoints | Wiz Blog
How AWS VPC Endpoint CloudTrail logs can help you troubleshoot endpoint policies and strengthen your network's security against data exfiltration.
www.wiz.io
March 20, 2025 at 3:45 PM
AWS just announced Claude Platform on AWS.
No Bedrock required!!

You get Anthropic's native Claude experience directly in your AWS account!
- IAM handles access
- Billing is consolidated
- CloudTrail logs everything alongside your other services
April 26, 2026 at 11:05 AM
give it a fiscal quarter and i'm sure you'll be able to do whatever you need to do with AWS Social EventBridge Cloudtrail, powered exclusively by Amazon Q
February 7, 2025 at 4:12 AM
50 AWS CloudTrail Interview Questions and answers:

https://tapurl.to/awscloudtrail
September 27, 2026 at 1:13 PM
Sports fan: "The football game has 2 minutes left."

Person getting ready: "I'll be ready to go in 2 minutes."

AWS: "We're making a breaking change on Monday."
January 14, 2025 at 3:14 PM
AWS CloudTrail now supports Internet Protocol Version 6 (IPv6)

AWS CloudTrail introduces dual stack support for the CloudTrail API endpoints, enabling you to connect using Internet Protocol Version 6 (IPv6), Internet Protocol Version 4 (IPv4), or dual stack clients. Dual s...

#AWS #AwsCloudtrail
AWS CloudTrail now supports Internet Protocol Version 6 (IPv6)
AWS CloudTrail introduces dual stack support for the CloudTrail API endpoints, enabling you to connect using Internet Protocol Version 6 (IPv6), Internet Protocol Version 4 (IPv4), or dual stack clients. Dual stack support is also available when you privately access the CloudTrail API endpoint from your Amazon Virtual Private Cloud (VPC) using AWS https://docs.aws.amazon.com/vpc/latest/privatelink/what-is-privatelink.html. The urgency to transition to Internet Protocol version 6 (IPv6) is driven by the continued growth of internet, which is exhausting available Internet Protocol version 4 (IPv4) addresses. With simultaneous support for both IPv4 and IPv6 clients on CloudTrail endpoints, you are able to gradually transition from IPv4 to IPv6 based systems and applications, without needing to switch all over at once. This enables you to meet IPv6 compliance requirements and removes the need for expensive networking equipment to handle the address translation between IPv4 and IPv6 To learn more on best practices for configuring IPv6 in your environment, visit the whitepaper on https://docs.aws.amazon.com/whitepapers/latest/ipv6-on-aws/internet-protocol-version-6.html in AWS. Support for IPv6 on AWS CloudTrail is available in all commercial regions and the AWS GovCloud (US) Regions.
aws.amazon.com
December 23, 2024 at 10:05 PM
This is the first AWS MCP server I see a lot of value in. The CloudTrail MCP Server allows bots and agents to query up do 90 days of management events and up to 10 years of data in CloudTrail Lake. Wondering if I can use this to debug "why am I getting a permission error" use cases!
buff.ly/Z1qLsy0
AWS launches CloudTrail MCP Server for enhanced security analysis
AWS introduces a CloudTrail MCP server that enables AI agents to perform advanced security and compliance analysis across AWS environments using conversational...
aws-news.com
September 11, 2025 at 9:36 PM
Some very interesting research from Permiso Security on abusing differences in size limits and white space manipulation to obfuscate IAM policies (and other resources) such that they won’t appear in CloudTrail. CloudTrail evasion isn’t just about being invisible!
permiso.io/blog/cloudtr...
CloudTrail Logging Evasion: Where Policy Size Matters
Permiso uncovered a subtle yet critical logging evasion vulnerability within AWS environments - mainly the differing size limitations of individual AWS CloudTrail logs versus the actual content being ...
permiso.io
May 29, 2025 at 11:14 PM
yeah we're talking about a service that makes you spin up an S3 bucket and CloudTrail to get detailed billing and usage info docs.aws.amazon.com/awsaccountbi...
Logging Billing and Cost Management API calls with AWS CloudTrail - AWS BillingLogging Billing and Cost Management API calls with AWS CloudTrail - AWS Billing
Use AWS CloudTrail to log API actions for your AWS account.
docs.aws.amazon.com
February 12, 2024 at 6:46 PM
CloudTrail monitoring for AWS API access over VPC endpoints is now GA! This is a good security feature which shows which API calls were denied by a VPC endpoint. Previously this data was not available - you could only see allowed calls or denies with direct API access in CloudTrail. buff.ly/Mw0XDI1
Announcing AWS CloudTrail network activity events for VPC Endpoints
AWS CloudTrail now supports network activity events for VPC endpoints, providing enhanced visibility and security monitoring by capturing actions transmitt...
aws-news.com
May 12, 2025 at 7:00 AM
Old and busted: Cloud attackers making noisy List/Describe calls.

New hotness: Laundering enumeration calls through an AWS service silently.

Or at least, that used to work, until @datadoghq.com partnered with AWS to close this gap. Read more here:
securitylabs.datadoghq.com/articles/enu...
Enumerating AWS the quiet way: CloudTrail-free discovery with Resource Explorer | Datadog Security Labs
Discover how attackers could quietly enumerate AWS resources via Resource Explorer, and how Datadog and AWS worked together to close the visibility gap.
securitylabs.datadoghq.com
August 19, 2025 at 4:10 PM
Amazon SES now enables customers to log email sending events directly through AWS CloudTrail, providing a simplified and native solution for tracking and monitoring email sending activities across AWS regions.
Amazon SES now supports logging email sending events through AWS CloudTrail
Amazon SES now enables customers to log email sending events directly through AWS CloudTrail, providing a simplified and native solution for tracking and monitoring email sending activities across AWS regions.
aws-news.com
April 14, 2025 at 5:06 PM
https://lckhd.eu/3gD4y3

#AWS #Terraform #CloudWatch #CloudTrail #Observability

There are many different tools you need to use to debug issues on AWS, including app logs, Lambda logs, CloudTrail logs to see who changed what, and VPC flow logs to see if traffic was blocked or not. In many cases
September 21, 2026 at 4:53 PM
AWS Observability power for Kiro IDE enables developers to troubleshoot distributed applications using natural language queries across CloudWatch, Application Signals, CloudTrail, and Prometheus without leaving their editor.
Accelerate troubleshooting with AWS Observability as a Kiro power
AWS Observability power for Kiro IDE enables developers to troubleshoot distributed applications using natural language queries across CloudWatch, Application Signals, CloudTrail, and Prometheus without leaving their editor.
aws-news.com
September 25, 2026 at 5:39 PM
✍️ New blog post by nishikawaakira

Testing AWS DevOps Agent Security: Directed Actions, Guardrails, and CloudTrail Evidence

#aws #cloudtrail #security
Testing AWS DevOps Agent Security: Directed Actions, Guardrails, and CloudTrail Evidence
Before reading this article, I recommend familiarizing yourself with elevated roles and directed...
dev.to
September 23, 2026 at 5:24 AM
I'm never going to financially recover from this.
February 13, 2025 at 6:05 PM