AWS CloudTrail
Every API call in every account, read through an organization trail.
Category
Cloud
Setup
About 20 minutes
Events Wardell reads
API calls, console sign-ins, IAM changes, S3 data events
Wardell reads CloudTrail from the S3 bucket your organization trail already writes to, using a read-only role you create from our CloudFormation template. Nothing is installed in your accounts.
Detections cover access keys used from new networks, IAM privilege changes, logging being switched off, public buckets and unusual data reads. Findings from GuardDuty come along if you have it on.
What Wardell watches
Organization-wide trail in one step
Access key misuse and new-ASN detections
IAM and S3 policy change history on every case
GuardDuty findings grouped with related CloudTrail events
Try it on your own logs
Connect this source with a read-only key. Within 48 hours a Wardell analyst sends a written report of what it would have caught.