M ManySignal
MS
CT
Integration

Aws Cloudtrail Integration

Every AWS API call, correlated with identity and threat context.

What this integration does

AWS CloudTrail meets agentic SOC

AWS CloudTrail records every API action taken in your AWS environment. ManySignal ingests management events and optionally data events, normalises them to OCSF, and runs them through identity-enrichment and behavioural baselining to surface anomalous privileged actions within seconds.

Ingestion of management events across all regions and accounts

Optional data event ingestion (S3 object reads, Lambda invocations)

IAM principal enrichment — resolves assumed-role sessions to originating users

Data collected

  • Management events (IAM, EC2, S3 bucket ops, KMS, etc.)
  • Console sign-in and MFA events
  • STS assume-role and federation events
  • Optional: S3 object-level data events
  • CloudTrail log file integrity digests

Actions supported

  • Revoke active IAM session tokens for a user or role
  • Disable IAM access key
  • Attach a deny-all IAM policy to a principal
  • Create a Security Hub custom finding
  • Trigger PagerDuty or Jira ticket on high-severity verdict

Getting started

Set up in minutes

  1. 1

    Verify CloudTrail is enabled

  2. 2

    Configure S3 delivery

  3. 3

    Enable SQS or EventBridge notification

  4. 4

    Tune data event volume

Aws Cloudtrail Integration: frequently asked questions

What is the typical ingestion lag for CloudTrail events?

Management events appear in CloudTrail within 15 minutes of the API call. ManySignal processes them within 30 seconds of S3 delivery — overall latency is typically under 20 minutes.

Does ManySignal ingest CloudTrail Insights events?

Yes. CloudTrail Insights findings for unusual API call rates are ingested and correlated with the underlying management events for richer context.

How does ManySignal handle log file tampering?

ManySignal validates CloudTrail log file integrity digests on ingest. A digest mismatch triggers a high-severity alert indicating potential log tampering.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.