As we mentioned earlier in this chapter, CloudTrail doesn't log everything, including many services that are completely unsupported. Again, that list of unsupported services can be found here: https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-unsupported-aws-services.html. What this means is that our API calls to these services will not get logged anywhere by CloudTrail (including Event history!). Some of these services can prove to be very lucrative for us as attackers, so if you compromise a user and find that they have access to any of those services, they are worth checking out because you can stay under the radar and still benefit greatly. Another big point ...
Unsupported CloudTrail services for attackers and defenders
Get Hands-On AWS Penetration Testing with Kali Linux now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.