Aws Trails Not Multiregion
Description
Identifies AWS CloudTrail trails that are not configured for multi-region logging. Single-region trails create gaps in audit logging coverage since they only record API activities in one region, potentially missing important security events and activities in other AWS regions.
Detection Strategy
• Scans all CloudTrail trails in the account (excluding shadow trails)
• Reports a vulnerability when a trail's IsMultiRegionTrail property is set to false
• Each reported vulnerability includes the specific trail's ARN and its multi-region configuration status
Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' hacking team, fill out this contact form.