AWS-011 Amazon Web Services (AWS)

CloudTrail log-file validation is enabled.

CloudTrail log-file validation is enabled.

Domain
Amazon Web Services (AWS)
Area
Logging
Automated / manual
Automated

Risk if it fails

Tampered logs can hide an intrusion.

If logs can be silently edited, an attacker can delete the evidence of their break-in, leaving investigators with a clean but false record.

How Tess tests it

1 test — each concludes only on cited evidence.

CloudTrail log-file validation is enabled.

Automated
Procedure
Confirm LogFileValidationEnabled=true on each trail.

Read-only command

aws cloudtrail describe-trails --query 'trailList[].{Name:Name,Validation:LogFileValidationEnabled}'

More in Amazon Web Services (AWS)

Want Tess to test AWS-011 against your evidence?

Book a demo