9.2 Cloud Telemetry and Audit Logging (AWS CloudTrail, Azure Activity, GCP Audit)
Key Takeaways
AWS CloudTrail Event history records 90 days of management events in each Region without creating a trail; centralized durable retention requires a trail or event data store, and S3 object or Lambda data events require explicit selection.
CloudTrail Log File Integrity Validation uses SHA-256 hashes, chained digest references, and RSA signatures to validate delivered log files and detect integrity or continuity failures after delivery.
Microsoft Azure centralizes telemetry across Activity Logs, Entra ID Sign-in and Audit logs, and VNet flow logs; new NSG flow logs have been unavailable since June 30, 2025 and existing NSG flow logs retire September 30, 2027.
Google Cloud Platform separates Cloud Audit Logs into immutable Admin Activity (retained 400 days free), Data Access (disabled by default), System Events, and Policy Denied streams.
Critical indicators of cloud compromise include defense evasion API calls (StopLogging, DeleteTrail), ConsoleLogin without MFA, sudden creation of administrative access keys, and massive anomalous VPC Flow Log egress.
Cloud Telemetry and Audit Logging (AWS CloudTrail, Azure Activity, GCP Audit)
Forensic reconstruction of cloud intrusions demands comprehensive visibility across distributed, API-driven architectures. Unlike on-premises networks where traffic passes through physical taps and local syslog daemons, cloud telemetry spans administrative audit logs, identity authentication streams, virtual network flow records, and managed threat intelligence engines. Incident handlers must understand the logging architectures and forensic telemetry sources across Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP), while mastering log file integrity validation and indicators of cloud compromise.
AWS Telemetry Architecture
AWS provides foundational telemetry sources essential for cloud investigations:
- AWS CloudTrail: Serves as the authoritative record of API activity within an AWS account, capturing requesting IAM identities, timestamps, source IPs, user agents, API operations, request parameters, and response elements. CloudTrail distinguishes between two core event types:
- Management Events: Capture control plane operations, such as launching EC2 instances, modifying security groups, attaching IAM policies, or configuring S3 buckets. CloudTrail Event history provides a 90-day regional view of management events without setup. A multi-Region trail or appropriately scoped event data store is needed for centralized, durable collection across enabled Regions; responders must also account for opt-in Regions and the organization's actual trail configuration.
- Data Events: Capture high-volume data plane operations, such as
s3:GetObject,s3:PutObject, and AWS Lambda function executions. Data events are disabled by default due to high log volume and ingestion costs. Responders investigating data exfiltration must confirm whether S3 data events were active; otherwise, CloudTrail cannot confirm which specific objects were accessed or downloaded.
- Log File Integrity Validation: To prevent adversaries from altering or deleting CloudTrail logs stored in Amazon S3 to cover their tracks, CloudTrail provides built-in Log File Integrity Validation. When enabled, CloudTrail delivers hourly digest files alongside standard log files. Each digest file contains SHA-256 hashes of delivered log files and the hash of the preceding digest file, forming an unbroken hash chain. CloudTrail digitally signs each digest file using an RSA private key managed by AWS. Responders execute
aws cloudtrail validate-logsto verify signatures and hash-chain continuity and detect altered or missing delivered files within the validated range. - CloudWatch Logs and VPC Flow Logs: Amazon CloudWatch Logs aggregates operational telemetry and application output, enabling metric filtering and automated alarms. Amazon VPC Flow Logs capture network IP traffic across virtual network interfaces (ENIs). Flow logs record 5-tuple connection data: source IP, destination IP, source port, destination port, protocol, packets, bytes, and action taken (
ACCEPTorREJECT). VPC Flow Logs are indispensable for detecting command-and-control (C2) beaconing, network scanning, lateral movement, and unauthorized external data transfers. - Amazon GuardDuty: A managed threat detection service that continuously evaluates CloudTrail event logs, VPC Flow Logs, DNS query logs, and Kubernetes audit logs. Using machine learning and threat intelligence feeds, GuardDuty detects unauthorized behaviors, including cryptocurrency mining, unexpected API calls from Tor exit nodes, and credential exfiltration via instance metadata.
Microsoft Azure Telemetry Ecosystem
Microsoft Azure centralizes security telemetry across several foundational services:
- Azure Activity Logs: Records control plane operations across Azure Resource Manager (ARM), providing visibility into resource creation, configuration updates, service health events, and administrative actions executed across Azure subscriptions.
- Microsoft Entra ID (formerly Azure AD) Audit and Sign-in Logs: Entra ID functions as the central identity provider. Sign-in logs capture interactive authentications, non-interactive logins, service principal requests, conditional access evaluations, MFA fulfillment, and sign-in risk levels (e.g., atypical travel, unfamiliar properties). Entra ID Audit logs track governance actions, including administrative role assignments (such as Global Administrator), group modifications, application registrations, and credential resets.
- Azure Monitor and Microsoft Defender for Cloud: Azure Monitor ingests metrics and log data into Log Analytics workspaces, enabling complex Kusto Query Language (KQL) threat hunting. Microsoft Defender for Cloud provides Cloud Security Posture Management (CSPM) and Cloud Workload Protection (CWPP), alerting responders to threats targeting VMs, SQL databases, and container registries.
- Virtual Network (VNet) Flow Logs: Capture layer-4 flow records at virtual-network scope and feed Azure Traffic Analytics. Microsoft stopped allowing creation of new NSG flow logs after June 30, 2025 and will retire existing NSG flow logs on September 30, 2027, so current designs should use VNet flow logs while preserving any historical NSG records needed for an investigation.
Google Cloud Platform (GCP) Telemetry Architecture
GCP organizes audit telemetry through Cloud Audit Logs across four distinct streams:
- Admin Activity Logs: Record administrative API calls that alter resource configurations or metadata (such as creating Compute Engine instances or changing IAM roles). These logs are immutable, enabled by default, and retained for 400 days at no cost.
- Data Access Logs: Record API calls that create, modify, or read customer data (e.g., BigQuery queries, Cloud Storage object reads). Data Access logs are disabled by default (except for BigQuery) and require explicit configuration.
- System Event Logs: Record administrative actions executed by automated GCP backend systems (such as VM live migrations).
- Policy Denied Logs: Generated when a security policy (such as Cloud IAM or VPC Service Controls) denies access to a resource.
GCP VPC Flow Logs record sampled network flows from virtual instances, while Security Command Center (SCC) acts as the centralized vulnerability and threat detection dashboard, surfacing misconfigurations, compromised service accounts, and exfiltration anomalies.
Detecting Suspicious Cloud Activity and Indicators of Attack
Incident handlers must configure detection rules and hunt for high-fidelity indicators of adversary cloud activity:
- Defense Evasion: Adversaries frequently attempt to disable logging upon acquiring credentials. Responders must alert on API calls such as
StopLogging,DeleteTrail, andUpdateTrailin AWS, disabling diagnostic settings in Azure, or deleting log sinks in GCP. - Authentication Anomalies: High-risk indicators include
ConsoleLoginevents executed without MFA, logins originating from commercial VPNs or Tor exit nodes, impossible travel alerts (logins from distant regions within impossible timeframes), and unexpected access key creation (CreateAccessKey) on dormant accounts. - Privilege Expansion: High-risk indicators include policy tampering (e.g.,
AttachUserPolicy,PutRolePolicygranting wildcard*:*permissions), modifying IAM trust policies, or registering unapproved external identity providers. - Mass Data Egress: Spikes in
s3:GetObjectrequests, massive outbound byte counts in VPC Flow Logs, and large-scale snapshot sharing across external account IDs signal active data exfiltration requiring immediate containment.
An incident handler must verify whether an adversary who acquired administrative cloud credentials modified or deleted AWS CloudTrail log files stored in an Amazon S3 bucket to conceal unauthorized API activities. Which native mechanism cryptographically validates the authenticity and integrity of delivered CloudTrail logs?
Enforcing S3 Object Lock with a 30-day governance retention period
Comparing CloudWatch metric alarms against AWS Cost Explorer billing records
Querying Amazon GuardDuty finding histories for unauthorized S3 API invocations
CloudTrail Log File Integrity Validation using hourly SHA-256 digest files and RSA digital signatures
A healthcare company suspects that confidential patient diagnostic records stored in an Amazon S3 bucket were exfiltrated during a credential compromise. However, when the incident handler reviews default AWS CloudTrail logs, there are zero recorded entries for s3:GetObject operations against the bucket, despite confirmed evidence of external network exfiltration. What explains the absence of these read events in CloudTrail?
CloudTrail Event history records management events without setup, whereas object-level S3 operations are data events that must be explicitly selected for a trail or event data store
S3 buckets automatically suppress read events whenever requests originate from authenticated IAM sessions
CloudTrail only records failed API calls (AccessDenied) and discards successful data retrieval requests
Amazon S3 stores all object-level read telemetry exclusively in VPC Flow Logs rather than CloudTrail
While monitoring cloud audit logs, an alert triggers indicating that an administrator account invoked the StopLogging API on an AWS CloudTrail multi-region trail, followed immediately by DeleteTrail on a secondary trail. In the context of cloud incident detection, what tactic does this activity indicate?
Initial access via federated identity token replay
Defense evasion intended to blind security monitoring and conceal subsequent malicious actions
Data exfiltration via unmonitored DNS query tunneling
Privilege escalation through automated role assumption
Sections you finish are checked off in the contents.