AWS accounts with no multi-Region CloudTrail trail that is logging
What does ZopNight detect here?
ZopNight flags an AWS account that has no multi-Region CloudTrail trail, or whose trails are not logging, based on `cloudtrail:DescribeTrails` with shadow trails included and `cloudtrail:GetTrailStatus`. CloudTrail delivers one copy of management events to S3 free of charge, so the gap is about audit evidence: without a trail, API history beyond 90 days is lost.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1521 |
| Category | compliance |
| Severity | high |
| Metric | none — pure configuration read |
| Threshold | no multi-Region trail, or no trail logging |
| Source | ZopNight |
| Permissions used | cloudtrail:DescribeTrails · cloudtrail:GetTrailStatus |
Where it applies
What CloudTrail gives you for free, and what it does not
Every account gets CloudTrail event history without doing anything. The CloudTrail pricing page describes it as 90 days of management events you can view and search at no cost. After 90 days those events are gone. A trail is what makes the record durable: it delivers events to an S3 bucket you own, and the same page says one copy of ongoing management events delivered by a trail is free. An account with no trail therefore has a 90-day memory, which is rarely enough for an incident investigation or an audit.
A multi-Region trail matters because activity in a Region you do not normally use is exactly what an attacker would try.
Checking trails and logging state
Include shadow trails so that multi-Region trails homed elsewhere, and organization trails applied to member accounts, show up:
aws cloudtrail describe-trails --include-shadow-trails --region us-east-1 \ --query 'trailList[].[Name,HomeRegion,IsMultiRegionTrail,IsOrganizationTrail]' --output tableA trail can exist and be stopped. Check IsLogging for each:
aws cloudtrail get-trail-status --name TRAIL_ARN --query IsLoggingTwo conditions, either one triggers it
ZopNight holds one record per account with two answers: does any trail cover all Regions, and is any trail logging. It fires when either answer is no. Both answers are account-wide, so an account whose multi-Region trail has been stopped is not flagged as long as some other trail is still logging.
When the account is not flagged
If the trail list cannot be read, the rule does not fire. If the trails are listed but no
trail’s logging status can be read, ZopNight treats the account as not logging and flags it. The lookup runs from us-east-1 with
shadow trails included, which is what lets accounts covered by a multi-Region trail homed in another
Region, or by an AWS Organizations trail, register as compliant.
No saving; the cost is missing evidence
The finding carries a $0 estimate. The first management-event copy costs nothing, although the S3 bucket that stores the logs, data events and CloudTrail Insights all add charges.
Creating a multi-Region trail
- Create an S3 bucket with versioning and encryption for log storage.
- Create the trail:
aws cloudtrail create-trail --name org-audit --s3-bucket-name BUCKET --is-multi-region-trail. - Start it:
aws cloudtrail start-logging --name org-audit, and confirm the trail records both read and write management events. - Consider CloudTrail Insights for unusual API activity, and data events for S3 or Lambda if an audit requires them.