Skip to the card

Card 056 of 9842026-09-28 issue

Observed arrival · 2026-09-28

A CloudTrail triage desk that stays in your browser

awsforensics.com Visit website
Editorial interest 82/100 Selection signal · not a rating of the site

AWS Forensics analyzes cloud log exports for suspected account compromise, returning a verdict, findings, an incident timeline, and remediation steps.

Landing page captured for the 2026-09-28 issue.
For
AWS administrators investigating suspected compromise
Worth noticing
Its sample traces a fictional chain from a leaked access key through disabled GuardDuty to S3 theft and crypto-mining.

Field notes

The page provides collection instructions for CloudTrail from an S3 trail or event history, including AWS CLI commands and reminders to repeat event-history downloads by region. It accepts compressed exports, folders, ZIPs, VPC Flow Logs, S3 access logs, GuardDuty JSON, and IAM credential reports; the site says multi-gigabyte exports are streamed locally. A built-in sample is explicitly synthetic and depicts a leaked-key incident.

Observed signals

Read the marks

Editorial observations of this landing page, not a rating.

○OpenPublic substance visible
✦PrettyNotable craft visible
●ProPolished or operationally mature
◎NicheUnusually specific use
ƒJavaScriptBrowser-side code central

One card from the complete issue

Regulated by Arithmetic

233,109 arrived 1,000 judged 984 catalogued Enter the complete issue
awsforensics.com

Landing page observed 2026-09-28. The live site may have changed.