Observed arrival · 2026-09-28
A CloudTrail triage desk that stays in your browser
AWS Forensics analyzes cloud log exports for suspected account compromise, returning a verdict, findings, an incident timeline, and remediation steps.
- For
- AWS administrators investigating suspected compromise
- Worth noticing
- Its sample traces a fictional chain from a leaked access key through disabled GuardDuty to S3 theft and crypto-mining.
Field notes
The page provides collection instructions for CloudTrail from an S3 trail or event history, including AWS CLI commands and reminders to repeat event-history downloads by region. It accepts compressed exports, folders, ZIPs, VPC Flow Logs, S3 access logs, GuardDuty JSON, and IAM credential reports; the site says multi-gigabyte exports are streamed locally. A built-in sample is explicitly synthetic and depicts a leaked-key incident.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue