S3 buckets storing CloudTrail logs have MFA Delete enabled. MFA Delete adds an extra layer of protection…
Your AWS CloudTrail trails are sending logs to CloudWatch Logs and that delivery has occurred within the…
Your AWS CloudTrail trails have Insights enabled. CloudTrail Insights uses machine learning to…
Your AWS CloudTrail trails use SSE-KMS encryption with customer-managed keys for log files stored in S3…
Your AWS CloudTrail trails have log file integrity validation enabled. When enabled, CloudTrail generates…
S3 server access logging is enabled on the bucket that stores your CloudTrail logs. When enabled, S3…
The S3 bucket storing your CloudTrail logs is not publicly accessible. CloudTrail logs contain a detailed…
AWS CloudTrail is logging API activity across all AWS regions. CloudTrail records every API call made in…
Your AWS account has a CloudTrail trail that records management events (read and write API operations)…
Your AWS CloudTrail trails are configured to log S3 object-level read data events. By default, CloudTrail…
Your AWS CloudTrail trails are recording S3 object-level write operations (such as PutObject…
This check analyzes your CloudTrail logs to detect AWS identities that are making an unusually high number…
This check analyzes CloudTrail activity related to Amazon Bedrock to detect potential "LLM jacking"…
This check analyzes CloudTrail logs to detect identities (IAM users or roles) performing high-risk actions…