Skip to main content

Field guides

Security investigation guides for cloud and SaaS audit logs

Evidence-first workflows for small teams investigating AWS, Google Cloud, Google Workspace, and GitHub activity. Each guide documents what the source can show, what it cannot show, and how to preserve useful evidence.

Cloud and SaaS sources

Start with the source you are investigating

AWS

How to investigate AWS CloudTrail anomalies

Scope Event history, reconstruct identity and intent, and know when a trail or CloudTrail Lake is required.

Read the guide →
GCP

How to investigate GCP Audit Log anomalies

Choose the right audit-log type, bound a Logs Explorer query, and reconstruct unusual administrative activity.

Read the guide →
AWS + GCP

What is the GCP equivalent of AWS CloudTrail?

Compare Google Cloud Audit Logs with CloudTrail event models, coverage boundaries, identity evidence, and investigation workflows.

Read the guide →
Google Workspace

How to investigate Google Workspace audit logs

Review suspicious login, administrator, and OAuth activity while respecting Reports API coverage limits.

Read the guide →
GitHub

How to investigate GitHub organization audit logs

Reconstruct actors, permission changes, and repository-setting activity in GitHub Enterprise Cloud.

Read the guide →
Explainer

Security vs cost anomaly detection

Understand why similarly named cloud tools answer different operational questions.

Read the guide →

Apply the workflow

Turn audit activity into an investigation queue.

Flare ranks supported cloud and SaaS audit evidence for small security teams.

Explore Flare