{"repo":"adanalvarez/TrailDiscover","free":true,"listed":false,"github":"https://github.com/adanalvarez/TrailDiscover","clone":"git clone https://github.com/adanalvarez/TrailDiscover.git","description":"An evolving repository of CloudTrail events with detailed descriptions, MITRE ATT&CK insights, real-world incidents, references and security implications","language":"Python","stars":174,"topics":["aws","aws-security","cloud-security","mitre-attack","security"],"license":"CC-BY-4.0","category":"security-tools","readme_excerpt":"TrailDiscover An evolving repository of CloudTrail events with detailed descriptions, MITRE ATT&amp;CK insights, real-world incidents references, other research references and security implications. Why This Project Exists I started TrailDiscover because I often wondered if certain AWS commands had been used in past cyber attacks and what information was available about them. Since most API actions create a CloudTrail event with the same name, I decided to focus on CloudTrail events, also because aproaching it this way might help using this information with SIEMs. This project is about making it easier to understand which AWS actions have been misused before, how others might be misused and the event they generate. I hope this helps people decide what to watch out for, speed up figuring out what happened in an attack, and inspire new security research. Website The easiest way to consume this information is via the website: https://traildiscover.cloud/ What's in the Project Here's what you'll find in TrailDiscover: - Events Folder : This is the main folder, here each AWS service has its own folder and inside you will find a JSON file for each event, like CloudTrail/DeleteTrail.json or Cognito/GetCredentialsForIdentity.json . - Docs Folder : This folder contains a website where you can search through the events easily. You can access the website via: https://traildiscover.cloud/ - Tools Folder : Contains build.py , a single pipeline that formats events, redacts CloudTrail logs,","default_branch":null,"files":null,"tree":[],"storefront":"/r/adanalvarez","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/adanalvarez/TrailDiscover/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}