matanolabs / matano

Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS
https://matano.dev
Apache License 2.0
1.46k stars 99 forks source link

parser: Add additional CloudTrail fields #152

Closed Samrose-Ahmed closed 1 year ago

Samrose-Ahmed commented 1 year ago

Parses additional fields from CloudTrail schema including: addendum, sessionCredentialFromConsole, edgeDeviceDetails, and tlsDetails.

See docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-event-reference-record-contents.html