Skip to main content

Cloud Activity

Lacework generates policy-based alerts when there are policy violations detected from cloud activities. You can define alert rules to trigger alerts when policy-based violations are found. See Alert Rules.

The following tabs list all policy-based alerts for AWS, Azure, and GCP:

Alert Name Alert Type Event Model Alert Subcategory
Access key deletedAccessKeyDeletedCloudTrailCepCloud Activity
CloudTrail changedCloudTrailChangedCloudTrailCepCloud Activity
CloudTrail deletedCloudTrailDeletedCloudTrailCepCloud Activity
CloudTrail stoppedCloudTrailStoppedCloudTrailCepCloud Activity
CloudTrail stoppedCloudTrailStoppedCloudTrailCepCloud Activity
Config service changeConfigServiceChangeCloudTrailCepCloud Activity
Customer master key disabledCustomerMasterKeyDisabledCloudTrailCepCloud Activity
Customer master key scheduled for deletionCustomerMasterKeyScheduledForDeletionCloudTrailCepCloud Activity
Failed console loginFailedConsoleLoginCloudTrailCepCloud Activity
IAM access key changedIAMAccessKeyChangedCloudTrailCepCloud Activity
IAM policy changedIAMPolicyChangedCloudTrailCepCloud Activity
NACL changeNACLChangeCloudTrailCepCloud Activity
Network gateway changeNetworkGatewayChangeCloudTrailCepCloud Activity
New access keyNewAccessKeyCloudTrailCepCloud Activity
New customer master keyNewCustomerMasterKeyCloudTrailCepCloud Activity
New customer master key aliasNewCustomerMasterKeyAliasCloudTrailCepCloud Activity
New grant added to customer master keyNewGrantAddedToCustomerMasterKeyCloudTrailCepCloud Activity
New S3 bucketNewS3BucketCloudTrailCepCloud Activity
New AWS user createdNewUserCloudTrailCepCloud Activity
New VPCNewVPCCloudTrailCepCloud Activity
New VPN connectionNewVPNConnectionCloudTrailCepCloud Activity
Route table changeRouteTableChangeCloudTrailCepCloud Activity
S3 bucket ACL changedS3BucketACLChangedCloudTrailCepCloud Activity
S3 bucket deletedS3BucketDeletedCloudTrailCepCloud Activity
S3 bucket policy changedS3BucketPolicyChangedCloudTrailCepCloud Activity
Security group changeSecurityGroupChangeCloudTrailCepCloud Activity
Successful console login without MFASuccessfulConsoleLoginWithoutMFACloudTrailCepCloud Activity
Unauthorized API callUnauthorizedAPICallCloudTrailCepCloud Activity
Usage of root accountUsageOfRootAccountCloudTrailCepCloud Activity
VPC changeVPCChangeCloudTrailCepCloud Activity
VPN gateway changeVPNGatewayChangeCloudTrailCepCloud Activity