0
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?

rootユーザーのログイン履歴はバージニア北部のCloudTrailに保存される

Posted at

前置き

GuardDutyでrootユーザのログインを検知して、CloudTrailでイベント名「ConsoleLogin」でログイン証跡を探していましたが、見つかりませんでした。

結論

Global Service Eventsは、バージニア北部(us-east-1)のCloudtrailに保存される仕様である。

Global Service Eventsとは

以下のサービスなど

  • AWS Identity and Access Management (IAM)
  • AWS STS (Security Token Service)
  • Amazon CloudFront
  • AWS Route 53
  • AWS Console Sign-in Events (rootユーザー含む)
  • Certificate Manager operations
0
0
0

Register as a new user and use Qiita more conveniently

  1. You get articles that match your needs
  2. You can efficiently read back useful information
  3. You can use dark theme
What you can do with signing up
0
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?