How to investigate AWS CloudTrail anomalies
Scope Event history, reconstruct identity and intent, and know when a trail or CloudTrail Lake is required.
Read the guide →Field guides
Evidence-first workflows for small teams investigating AWS, Google Cloud, Google Workspace, and GitHub activity. Each guide documents what the source can show, what it cannot show, and how to preserve useful evidence.
Cloud and SaaS sources
Scope Event history, reconstruct identity and intent, and know when a trail or CloudTrail Lake is required.
Read the guide →Choose the right audit-log type, bound a Logs Explorer query, and reconstruct unusual administrative activity.
Read the guide →Compare Google Cloud Audit Logs with CloudTrail event models, coverage boundaries, identity evidence, and investigation workflows.
Read the guide →Review suspicious login, administrator, and OAuth activity while respecting Reports API coverage limits.
Read the guide →Reconstruct actors, permission changes, and repository-setting activity in GitHub Enterprise Cloud.
Read the guide →Understand why similarly named cloud tools answer different operational questions.
Read the guide →Apply the workflow
Flare ranks supported cloud and SaaS audit evidence for small security teams.
Explore Flare