TrailDiscover (Beta)

Enrich incoming CloudTrail events with TrailDiscover data

Overview

TrailDiscover enrichment is in open beta starting with Panther version 1.107, and is available to all customers. Please share any bug reports and feature requests with your Panther support team.

TrailDiscover is a continuously evolving repository of CloudTrail events containing detailed descriptions, MITRE ATT&CK insights, real-world incident references, research links, and information about security implications.

Learn how to view stored Enrichment Provider data here, and how to view log events with enrichment data here.

How TrailDiscover works

The TrailDiscover Enrichment Provider enriches CloudTrail events with relevant information from TrailDiscover, using the log's eventName key. If you use Amazon Security Lake, TrailDiscover enriches the api.operation field, which contains the CloudTrail event name.

Setting up TrailDiscover enrichment

How to set up TrailDiscover enrichment in the Panther Console

  1. In the left-hand navigation bar in your Panther Console, click Detections.

  2. Click the Packs tab.

  3. Search for "TrailDiscover," and on the TrailDiscover Lookup Tables tile, click the Enabled toggle ON.

  4. In the pop-up confirmation modal, click Continue.

  5. To verify the Lookup Table is enabled, from the left sidebar menu, click Configure > Enrichment Providers.

    • On this page, you can see Panther-managed Enrichment Providers. You can also see whether the sources are currently enabled or disabled and when a source’s data was last refreshed.

Example event enriched with TrailDiscover

Below is a CloudTrail log enriched with TrailDiscover data. The TrailDiscover object within p_enrichment contains additional information about the AssumeRole event, such as links to associated incidents, research, and MITRE ATT&CK tactics and techniques.

Last updated

Was this helpful?