Logo image
Investigating Advanced Persistent Threat Tactics in Cloud Environments: A Forensic Study of AWS CloudTrail Log Data
Journal article   Open access   Peer reviewed

Investigating Advanced Persistent Threat Tactics in Cloud Environments: A Forensic Study of AWS CloudTrail Log Data

Adeolu Opeyemi Ojo and Mohammed Benmubarak
International Journal of Innovative Science and Research Technology, Vol.10(7), pp.3170-3176
07/08/2025

Abstract

Forensic Analysis CloudTrail Advance Persistent Threats (APTs) Amazon AWS Cloud MITRE ATT&CK Cyber Kill Chain Pyramid of Pain
The focus of this study is to identify and reduce Advanced Persistent Threats (APTs) in the cloud environment of Amazon Web Services (AWS). Popular security frameworks like MITRE ATT&CK, Cyber-Kill Chain and Pyramid of Pain were employed to improve effectiveness of forensic investigation in cloud environments. Tactics, techniques and procedures (TTPs) using Cloud Trail log data were analyzed in order to discover the efficiency of these frameworks in attack patterns identification. Findings from the study reveals that logs are crucial for identifying attack trends such as lateral movement, exfiltration of data, escalation of privileges in order to help improve understanding and analysis of APT activities in AWS environment, and the integration of frameworks such as MITRE ATT & CK, Cyber-Kill Pains and Pyramid of Pain provides strategies that are proactive to quelling advanced cyber adversaries
pdf
Investigating Advanced Persistent Threat Tactics in Cloud Environments: A Forensic Study of AWS CloudTrail Log Data518.41 kBDownloadView
Published (Version of record)Open AccessCC BY-NC V4.0 Open Access
url
Link to Published VersionView
Published (Version of record)Open accessCC BY-NC V4.0 Open

Metrics

106 File views/ downloads
47 Record Views

Details

Logo image

Usage Policy