Possible credential misuse
Bring attention to access keys used from risky, blacklisted, or geoblocked public IPs. Give responders a reason to investigate.
The source behind the credentialsSpot suspicious credential use and sensitive account changes. TrailGuard connects CloudTrail activity with FraudGuard IP intelligence and your policies, so your team knows where to look.
GetCallerIdentity
198.51.100.42An access key was used from an IP with elevated risk. Check whether this activity belongs to your team.
Know what deserves a closer look
Connect what happened in AWS
with where the request came from.
Bring attention to access keys used from risky, blacklisted, or geoblocked public IPs. Give responders a reason to investigate.
The source behind the credentialsSurface privilege-sensitive activity and CloudTrail logging changes, with source context to help your team assess what happened.
Permissions · Access keys · Audit loggingUse your FraudGuard blocklists and geoblocks to flag unwanted sources. Optionally flag activity outside your approved networks.
Your own definition of trusted accessA clearer path to investigation
TrailGuard processes CloudTrail logs as they arrive in S3, using Lambda in your AWS account.
Your CloudTrail logs → Your LambdaEvaluate public source IPs against FraudGuard intelligence and your policies. Connect that context to the identity and action.
Source risk + Event + Customer policySend findings for analysis, then deliver alerts through Amazon SNS to email or your connected incident workflows.
Finding → Analysis → NotificationYour team decides how to respond. TrailGuard provides detection and context. Investigate the finding, then take the action your environment needs.
Fits the way AWS teams work
Deploy with CloudFormation. Keep CloudTrail parsing and findings storage in your environment, with the event, source IP, and identity context your team needs to investigate.
We’ll help you review log coverage, data flow, and notification routing before deployment.
Talk through your environmentNo. TrailGuard analyzes recorded activity and alerts your team. Your responders decide whether to revoke credentials, adjust permissions, or take other action. For complementary source-network restrictions on AWS access, see AccessGuard.
Not by itself. A risky source or sensitive action is a reason to investigate. TrailGuard brings the source, identity, and event context together so you can determine whether the activity is expected.
CloudTrail parsing and findings storage run in your account. Finding summaries—including source IPs, identity details, and event metadata—are sent to FraudGuard for analysis as part of the alerting workflow. We’ll review this data flow with you during deployment.
TrailGuard evaluates delivered log records with a valid public source IP. Coverage depends on your CloudTrail configuration and log delivery; activity with internal or non-IP sources is outside this processing path.
Yes. Alerts are delivered through Amazon SNS. Configure subscriptions for email and connect downstream integrations for your incident tools. We’ll help you plan routing around the workflows your team already uses.
TrailGuard is available on Business and Enterprise. Compare plans, then talk to us about your AWS accounts, CloudTrail setup, and alerting needs. AWS usage is billed separately by AWS.
Give your CloudTrail more context
Bring your AWS activity, source intelligence,
and security policy into the same investigation.