An extra 30% off every course until Sunday, October 11.Choose your certification →

Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

3.4.3.4. Implementing Robust Security Auditing

3.4.3.4. Implementing Robust Security Auditing

Security auditing must be tamper-proof, comprehensive, and continuously analyzed — not just stored.

Tamper-proof audit trail:
  1. CloudTrail delivers logs to S3 with log file integrity validation
  2. S3 bucket: Object Lock (WORM), deny s3:DeleteObject, cross-account (auditors can't be compromised by the same attacker)
  3. SCP: deny cloudtrail:StopLogging and cloudtrail:DeleteTrail across all accounts
Proving vs. preventing tampering:
  • Log file validation proves integrity: every hour CloudTrail delivers a digest file holding SHA-256 hashes of that hour's log files, signed (SHA-256 with RSA) and chained to the previous digest. aws cloudtrail validate-logs --trail-arn <arn> --start-time <time> walks the chain and reports any modified, deleted or missing log file — months or years later.
  • S3 Object Lock in Compliance mode prevents tampering: no principal, including the root user, can overwrite or delete a locked object version until its retention period ends. Validation detects, Object Lock prevents — an auditor asking for tamper-proof and complete logs wants both.
  • Neither is replaced by KMS encryption (controls who can read, not whether content changed), S3 versioning (old versions can still be deleted), an SCP (never restricts the management account, and an org admin can detach it), or an AWS Backup copy (it faithfully copies a file that was already altered).
Comprehensive coverage:
  • Management events: all API calls (default)
  • Data events: S3 object access, Lambda invocations, DynamoDB reads (enable explicitly — high volume)
  • Insights events: unusual API call patterns
Continuous analysis pipeline:
CloudTrail → S3 → Athena (ad-hoc queries)
          → CloudWatch Logs → Metric Filters → Alarms
          → EventBridge → Lambda (real-time detection)
          → Security Hub → Findings dashboard
Key CloudTrail metric filters for security alerting:
# Root account usage
{ $.userIdentity.type = "Root" && $.eventType != "AwsServiceEvent" }

# Console login without MFA
{ $.eventName = "ConsoleLogin" && $.additionalEventData.MFAUsed = "No" }

# Authorization failures (potential scanning)
{ $.errorCode = "AccessDenied" || $.errorCode = "UnauthorizedAccess" }

Exam Trap: CloudTrail logging can be disabled by an administrator — which is exactly what an attacker would do after gaining admin access. Protect against this with an SCP that denies cloudtrail:StopLogging and cloudtrail:DeleteTrail for all accounts. Store logs in a separate security account where application account admins have no access.

See how it connects
Alvin Varughese
Written byAlvin Varughese
Founder•20 professional certifications