If you're an attacker who's just landed in an AWS account, the most expensive thing about your future is detection. Every API call you make leaves a trail in CloudTrail, gets forwarded to a SIEM, becomes evidence the team uses to boot you out and reconstruct what you touched. The cost of your campaign rises linearly with the number of events on record.
So you make one call first:
aws cloudtrail stop-logging --name org-audit-trail
Enter fullscreen mode
Exit fullscreen mode






