Your AWS activity.
The context to act.

Spot suspicious credential use and sensitive account changes. TrailGuard connects CloudTrail activity with FraudGuard IP intelligence and your policies, so your team knows where to look.

From activity to finding Illustration
01 / CLOUDTRAIL EVENTAWS STS
GetCallerIdentity
Source IP
198.51.100.42
Identity
IAM user · deploy-bot
Source intelligence + your policy
RISKY SOURCE NETWORKReview

An access key. A risky origin.

An access key was used from an IP with elevated risk. Check whether this activity belongs to your team.

Source-IP riskAccess-key activity
Finding summary analysis SNS alert

Know what deserves a closer look

The event is recorded.
Now make sense of the risk.

Connect what happened in AWS
with where the request came from.

Possible credential misuse

Bring attention to access keys used from risky, blacklisted, or geoblocked public IPs. Give responders a reason to investigate.

The source behind the credentials

Changes that carry more risk

Surface privilege-sensitive activity and CloudTrail logging changes, with source context to help your team assess what happened.

Permissions · Access keys · Audit logging

Your policy, in the picture

Use your FraudGuard blocklists and geoblocks to flag unwanted sources. Optionally flag activity outside your approved networks.

Your own definition of trusted access

A clearer path to investigation

From CloudTrail logs
to your response workflow.

Plan your deployment
  1. 01 / READ

    Start with your AWS activity.

    TrailGuard processes CloudTrail logs as they arrive in S3, using Lambda in your AWS account.

    Your CloudTrail logs → Your Lambda
  2. 02 / CONNECT

    Add the missing context.

    Evaluate public source IPs against FraudGuard intelligence and your policies. Connect that context to the identity and action.

    Source risk + Event + Customer policy
  3. 03 / ALERT

    Give your team a starting point.

    Send findings for analysis, then deliver alerts through Amazon SNS to email or your connected incident workflows.

    Finding → Analysis → Notification

Your team decides how to respond. TrailGuard provides detection and context. Investigate the finding, then take the action your environment needs.

Fits the way AWS teams work

Your AWS account.
Your investigation trail.

Deploy with CloudFormation. Keep CloudTrail parsing and findings storage in your environment, with the event, source IP, and identity context your team needs to investigate.

We’ll help you review log coverage, data flow, and notification routing before deployment.

Talk through your environment

A few useful details

Before you connect
your CloudTrail.

Explore the API docs
Does TrailGuard block requests or disable keys?

No. TrailGuard analyzes recorded activity and alerts your team. Your responders decide whether to revoke credentials, adjust permissions, or take other action. For complementary source-network restrictions on AWS access, see AccessGuard.

Does a finding mean a credential was stolen?

Not by itself. A risky source or sensitive action is a reason to investigate. TrailGuard brings the source, identity, and event context together so you can determine whether the activity is expected.

What data leaves our AWS account?

CloudTrail parsing and findings storage run in your account. Finding summaries—including source IPs, identity details, and event metadata—are sent to FraudGuard for analysis as part of the alerting workflow. We’ll review this data flow with you during deployment.

Which CloudTrail activity can it evaluate?

TrailGuard evaluates delivered log records with a valid public source IP. Coverage depends on your CloudTrail configuration and log delivery; activity with internal or non-IP sources is outside this processing path.

Can alerts reach our existing tools?

Yes. Alerts are delivered through Amazon SNS. Configure subscriptions for email and connect downstream integrations for your incident tools. We’ll help you plan routing around the workflows your team already uses.

Which plans include TrailGuard?

TrailGuard is available on Business and Enterprise. Compare plans, then talk to us about your AWS accounts, CloudTrail setup, and alerting needs. AWS usage is billed separately by AWS.

Give your CloudTrail more context

Make the next finding
easier to act on.

Bring your AWS activity, source intelligence,
and security policy into the same investigation.