AWS CloudTrail is Amazon Web Services’ native logging and auditing service, recording API calls and account activity across an AWS environment. It’s a foundational data source for cloud security monitoring, giving visibility into who did what, when, and from where within AWS infrastructure.
How it works
Direct API integration (aws) ingesting CloudTrail event logs for cloud activity monitoring.
Data ingested
CloudTrail API events, IAM activity
Frequently asked questions
Expel connects to AWS CloudTrail through a CloudFormation StackSet deployed directly in your AWS account. The wizard-driven process configures log forwarding without manual scripting, and many customers complete setup in well under 15 minutes. Once connected, Expel collects, stores, and indexes CloudTrail logs to support custom alerting and analyst investigation.
Expel gives security teams continuous analyst review of AWS CloudTrail activity instead of relying on internal staff to watch logs around the clock. Alerts route into Workbench, Expel’s analyst operations platform, where detections are mapped to the MITRE ATT&CK framework. Lean cloud security teams get that coverage without adding headcount.
Native CloudTrail alerting flags raw events, but Expel adds analyst judgment and cross-account context before anything reaches your team. Expel enriches AWS alerts through automated orchestration, then evaluates them against detections built on the MITRE ATT&CK framework inside Workbench. That combination separates real threats from noise instead of forwarding every flagged event.
Expel automates the enrichment step of CloudTrail alert investigation, pulling in additional context before an analyst ever opens the case. That orchestration cuts down manual lookup work so analysts spend time on judgment calls, not data gathering. Enriched alerts land in Workbench, where they are evaluated against detections mapped to MITRE ATT&CK.
Expel’s sales team runs live demos of the AWS CloudTrail integration, which you can request at expel.com/request-demo. During the session, a representative shows how CloudTrail alerts are enriched, mapped to MITRE ATT&CK detections, and surfaced in Workbench, using examples relevant to your account structure if you share it in advance.
