AWS CloudTrail
Overview
AlphaSOC normalizes AWS CloudTrail telemetry into the Open Cybersecurity Schema Framework (OCSF) format. The fields listed below are available for use in Sigma detection rules. For complete field definitions and semantics, refer to the linked OCSF class schema pages.
AWS CloudTrail: API Activity
OCSF Category: Application Activity
OCSF Class: API Activity
OCSF Fields
activity_idactivity_nameactor.idp.nameactor.idp.uidactor.session.created_timeactor.session.is_mfaactor.session.issueractor.user.account.uidactor.user.credential_uidactor.user.nameactor.user.typeactor.user.uidapi.operationapi.request.uidapi.response.errorapi.response.error_messageapi.service.nameapi.versioncategory_namecategory_uidclass_nameclass_uidcloud.account.uidcloud.providercloud.regionhttp_request.user_agentmetadata.event_codemetadata.product.feature.namemetadata.product.namemetadata.product.versionmetadata.uidmetadata.versionseverityseverity_idsrc_endpoint.ipsrc_endpoint.uidstatusstatus_idtimetype_nametype_uid
AWS CloudTrail: Account Change
OCSF Category: Identity & Access Management
OCSF Class: Account Change
OCSF Fields
activity_idactivity_nameactor.idp.nameactor.idp.uidactor.session.created_timeactor.session.is_mfaactor.session.issueractor.user.account.uidactor.user.credential_uidactor.user.nameactor.user.typeactor.user.uidapi.operationapi.request.uidapi.response.errorapi.response.error_messageapi.service.nameapi.versioncategory_namecategory_uidclass_nameclass_uidcloud.account.uidcloud.providercloud.regionhttp_request.user_agentmetadata.event_codemetadata.product.feature.namemetadata.product.namemetadata.product.versionmetadata.uidmetadata.versionpolicy.uidseverityseverity_idsrc_endpoint.ipsrc_endpoint.uidstatusstatus_idtimetype_nametype_uiduser.nameuser.uid
AWS CloudTrail: Authentication
OCSF Category: Identity & Access Management
OCSF Class: Authentication
OCSF Fields
activity_idactivity_nameactor.idp.nameactor.idp.uidactor.session.created_timeactor.session.is_mfaactor.session.issueractor.user.account.uidactor.user.credential_uidactor.user.nameactor.user.typeactor.user.uidapi.operationapi.request.uidapi.response.errorapi.response.error_messageapi.service.nameapi.versioncategory_namecategory_uidclass_nameclass_uidcloud.account.uidcloud.providercloud.regiondst_endpoint.svc_namehttp_request.user_agentmetadata.event_codemetadata.product.feature.namemetadata.product.namemetadata.product.versionmetadata.uidmetadata.versionsession.credential_uidsession.uidseverityseverity_idsrc_endpoint.ipsrc_endpoint.uidstatusstatus_idtimetype_nametype_uiduser.nameuser.uid