Using AWS Security for Developers
Rahul Singh
Technical Product Manager
CloudTrail: one API call, one record
eventNameeventTimeuserIdentityrequestParameters
CloudTrail: one API call, one record
eventNameeventTimeuserIdentityrequestParameterserrorCode
Two fields, one identity
arn, starting arn:aws:sts:sessionIssuer, starting arn:aws:iam:
Two fields, one identity
arn, starting arn:aws:sts:sessionIssuer, starting arn:aws:iam:The actor is not a field
sourceIPAddress
Forty fields, four that matter

Forty fields, four that matter
Where they come from
eventName, resource from requestParametersuserIdentity, actor inferred
Management events
Decrypt lands here

Management events
Decrypt lands hereData events



Decided before, read after

Decided before, read after
IAM Access Analyzer

IAM Access Analyzer


Unused access findings

Unused access findings
Used is not the same as required

Unused access findings
Used is not the same as required
Least privilege, measured
Using AWS Security for Developers