What could have been done to detect and automatically remediate the incident?

1 Comment

  1. Tyler
    Author

    I plot that the answer is:
    Using AWS Config, create a config rule that detects when AWS CloudTrail is disabled, as well as any calls to the root user create-api-key. Then use a Lambda function to re-enable CloudTrail logs and deactivate the root API keys.

Leave a Reply to Tyler Cancel reply

Your email address will not be published. Required fields are marked *

12 + seven =