elastic
low
kql
AWS CloudTrail Log Created
Detects creation of a new AWS CloudTrail trail via CreateTrail API. While legitimate during onboarding or auditing
improvements, adversaries can create trails that write to attacker-controlled destinations, limit regions, or otherwise
subvert monitoring objectives. New trails should be validated for destination ownership, encryption, multi-region
coverage, and organizational scope.