AWS-011 Amazon Web Services (AWS)
CloudTrail log-file validation is enabled.
CloudTrail log-file validation is enabled.
- Domain
- Amazon Web Services (AWS)
- Area
- Logging
- Automated / manual
- Automated
Risk if it fails
Tampered logs can hide an intrusion.
If logs can be silently edited, an attacker can delete the evidence of their break-in, leaving investigators with a clean but false record.
How Tess tests it
1 test — each concludes only on cited evidence.
CloudTrail log-file validation is enabled.
Automated- Procedure
- Confirm LogFileValidationEnabled=true on each trail.
Read-only command
aws cloudtrail describe-trails --query 'trailList[].{Name:Name,Validation:LogFileValidationEnabled}' More in Amazon Web Services (AWS)
Want Tess to test AWS-011 against your evidence?
Book a demo