Aws Cloudtrail Integration
Every AWS API call, correlated with identity and threat context.
What this integration does
AWS CloudTrail meets agentic SOC
AWS CloudTrail records every API action taken in your AWS environment. ManySignal ingests management events and optionally data events, normalises them to OCSF, and runs them through identity-enrichment and behavioural baselining to surface anomalous privileged actions within seconds.
Ingestion of management events across all regions and accounts
Optional data event ingestion (S3 object reads, Lambda invocations)
IAM principal enrichment — resolves assumed-role sessions to originating users
Data collected
- Management events (IAM, EC2, S3 bucket ops, KMS, etc.)
- Console sign-in and MFA events
- STS assume-role and federation events
- Optional: S3 object-level data events
- CloudTrail log file integrity digests
Actions supported
- Revoke active IAM session tokens for a user or role
- Disable IAM access key
- Attach a deny-all IAM policy to a principal
- Create a Security Hub custom finding
- Trigger PagerDuty or Jira ticket on high-severity verdict
Getting started
Set up in minutes
- 1
Verify CloudTrail is enabled
- 2
Configure S3 delivery
- 3
Enable SQS or EventBridge notification
- 4
Tune data event volume
Aws Cloudtrail Integration: frequently asked questions
What is the typical ingestion lag for CloudTrail events?
Management events appear in CloudTrail within 15 minutes of the API call. ManySignal processes them within 30 seconds of S3 delivery — overall latency is typically under 20 minutes.
Does ManySignal ingest CloudTrail Insights events?
Yes. CloudTrail Insights findings for unusual API call rates are ingested and correlated with the underlying management events for richer context.
How does ManySignal handle log file tampering?
ManySignal validates CloudTrail log file integrity digests on ingest. A digest mismatch triggers a high-severity alert indicating potential log tampering.
Related integrations
Amazon Web Services Integration
Integration
Aws Guardduty Integration
Integration
Aws Security Hub Integration
Integration
Aws Config Integration
Integration
Aws Vpc Flow Logs Integration
Integration
Microsoft Azure Integration
Integration
Azure Activity Logs Integration
Integration
Microsoft Entra Id Integration
Integration
Microsoft Defender Integration
Integration
Microsoft Defender For Cloud Integration
Integration
Microsoft Defender For Identity Integration
Integration
Microsoft Sentinel Integration
Integration
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.