TrailDiscover (Beta)
Enrich incoming CloudTrail events with TrailDiscover data
Overview
TrailDiscover enrichment is in open beta starting with Panther version 1.107, and is available to all customers. Please share any bug reports and feature requests with your Panther support team.
TrailDiscover is a continuously evolving repository of CloudTrail events containing detailed descriptions, MITRE ATT&CK insights, real-world incident references, research links, and information about security implications.
Learn how to view stored Enrichment Provider data here, and how to view log events with enrichment data here.
How TrailDiscover works
The TrailDiscover Enrichment Provider enriches CloudTrail events with relevant information from TrailDiscover, using the log's eventName
key. If you use Amazon Security Lake, TrailDiscover enriches the api.operation
field, which contains the CloudTrail event name.
Setting up TrailDiscover enrichment
How to set up TrailDiscover enrichment in the Panther Console
In the left-hand navigation bar in your Panther Console, click Detections.
Click the Packs tab.
Search for "TrailDiscover," and on the TrailDiscover Lookup Tables tile, click the Enabled toggle
ON
.In the pop-up confirmation modal, click Continue.
To verify the Lookup Table is enabled, from the left sidebar menu, click Configure > Enrichment Providers.
On this page, you can see Panther-managed Enrichment Providers. You can also see whether the sources are currently enabled or disabled and when a source’s data was last refreshed.
Example event enriched with TrailDiscover
Below is a CloudTrail log enriched with TrailDiscover data. The TrailDiscover
object within p_enrichment
contains additional information about the AssumeRole
event, such as links to associated incidents, research, and MITRE ATT&CK tactics and techniques.
Last updated