Skip to content
SecurityDIFFICULTY: ExpertSTATUS: Production

CloudTrail Threat Detection Platform

Real-time Security Event Ingestion & Threat Analysis

GitHub Repository
Client / ScopeInternal Enterprise Security
My RoleLead Cloud Security Engineer
Duration6 Months
Completion Date2026-04-12

1. SYSTEM OVERVIEW

Executive Summary

An event-driven cloud security analytics pipeline that ingests AWS CloudTrail records, applies normalization and risk scoring heuristics, and fires alert integrations under 45 seconds to secure distributed multi-tenant AWS accounts.

Business Problem

Security teams were blind to privilege escalations, impossible travel access anomalies, and critical token abuses, with incident containment cycles taking hours due to fragmented SIEM reporting.

Business Impact Value

Reduced MTTR (Mean Time to Respond) from 3 hours to under 3 minutes, mitigated risk of credentials leakage, and established audit-ready continuous cloud monitoring compliance.

Key Engineering Goals
  • Ingest and normalize 10k event/sec spikes without queue blockages
  • Filter out 95% of safe system noise via context-aware suppression
  • Deploy immutable evidence stores for post-incident audit retention
My System Responsibilities
  • Designed least-privilege IAM control models for distributed log acquisition
  • Implemented Lambda scoring heuristics engine and EventBridge routing
  • Engineered sub-minute alert pathways into ChatOps and incident workflows

2. SYSTEM FEATURES

Real-time Event IngestionComplexity: Medium

Serverless S3-triggered event pipelines normalizing raw JSON CloudTrail schemas.

Impl:S3 Event Notifications trigger Lambda parsers processing events in batches of 100.
Multi-Dimensional Risk ScorerComplexity: High

Mathematical incident prioritization engine scoring API calls against historical baselines.

Impl:A scoring heuristic evaluating actor reputation, target vulnerability, and action severity.
Automated Slack/PagerDuty AlertsComplexity: Low

ChatOps alert integration formatting threat metadata with direct links to logs.

Impl:SNS notifications mapped to Lambda alert formatters.

3. SYSTEM ARCHITECTURE

Distributed security architecture acquiring audit logs from organizational member accounts into a centralized security account using encrypted streams, then processing events asynchronously via concurrent serverless queues.

Topology Vector Diagram
CloudTrail Logs (S3) ──> S3 Event Notification ──> Lambda Parser ──> EventBridge
                                                                       │
┌──────────────────────────────────────────────────────────────────────┘
▼
Lambda Risk Scorer ──> DynamoDB (State Cache) ──> KMS Encrypted Evidence (S3)
   │
   └─[High Risk Risk >= 75]─> SNS ──> ChatOps (Slack) / PagerDuty Alert
Pipeline flow sequences
User/Role makes high-risk API call (e.g. iam:CreateAccessKey)
CloudTrail records API call and flushes log segment to centralized S3 bucket
S3 triggers Lambda parser which extracts identity, IP, and payload
Payload is checked against threat signatures in DynamoDB cache
Heuristics score threat; if above threshold, alerts fire via SNS to Slack
Repo directory structure
cloudtrail-detector/
├── src/
│   ├── handlers/
│   │   ├── parser.ts          # Normalization logic
│   │   └── scorer.ts          # Risk scoring engine
│   ├── rules/
│   │   └── privilege-escalation.ts # Signature checks
│   └── utils/
│       └── kms-helper.ts      # Evidence encryption
└── terraform/
    ├── main.tf                # Pipelines definitions
    └── variables.tf

4. INTERACTIVE SIMULATOR WIDGET

Run active operations audits utilizing the custom sandbox telemetry receiver widget below.

Controlled IAM Audit Pipeline
Click Run Audit to start security scanning logs.

5. ENGINEERING ARCHITECTURE DECISIONS (ADRs)

Decision ProfileSelect ingestion model for high-throughput multi-account log streams
Context

Log streams arrive in bursts and processing must be real-time while ensuring zero dropouts.

Alternatives Checked
  • Managed Kafka (MSK)
  • Kinesis Data Streams
  • Serverless S3 Event Notifications
Selected Decision

Serverless S3 Event Notifications triggering Lambda

Advantages
  • Zero idle cost during low activity periods
  • Scales automatically to match arbitrary incoming log volumes
  • Extremely simple architecture with minimal operational footprint
Disadvantages
  • Subject to Lambda cold starts
  • Slightly higher latency compared to persistent consumers
Trade-off details

Accepted a 1-second cold start latency on initial batch wakeups to achieve 85% cost savings compared to maintaining a running MSK cluster.

Future Scaling direction

Introduce an SQS buffer layer between S3 and Lambda to smooth out heavy burst workloads and handle retry logic.

6. DETAILED TECHNOLOGY STACK

cloud
• AWS CloudTrail• AWS EventBridge• AWS Lambda• AWS KMS
infrastructure
• Terraform• S3 Glacier• DynamoDB
security
• IAM Least-Privilege• KMS Encryption• AWS GuardDuty
testing
• LocalStack• Jest
monitoring
• CloudWatch Metrics• AWS X-Ray

7. SECURITY REVIEW & POSTURE

Least-Privilege Infrastructure Access

Centralized security parsing functions must query DynamoDB and read logs across organizational accounts without global administrative permissions.

Mitigation StrategyScoped IAM Policies using context keys, explicit SourceAccount parameters, and strict resource-level restrictions on all AWS Lambda execution roles.
Evidence Integrity Assurance

Intruders attempting to cover tracks might try to modify or delete logs and threat records in the evidence store.

Mitigation StrategyImmutable S3 buckets configured with Object Lock in Compliance Mode alongside KMS CMKs requiring multi-factor authentication for deletion.

8. PERFORMANCE METRICS TELEMETRY

Detection Latency38s

Optim:Direct event routing, batch size optimizations, and memory tuning of parser Lambdas.

Pipeline Throughput12,500 events/sec

Optim:Configured concurrent execution limits and partitioned DynamoDB keys for risk caches.

9. ENGINEERING CHALLENGES & RESOLUTIONS

Vulnerability Bottleneck

High volumes of benign system activity (e.g. deployment roles creating access keys) triggered false positives, drowning security teams in warnings.

Root Cause:Heuristics were too simple, matching only on high-severity API calls without examining the calling entity context or history.

System Investigation

Traced alert history over 30 days and observed that 88% of alerts originated from trusted automated CI/CD roles executing predictable tasks.

Engineering Solution

Implemented context-aware suppression. Roles that matched a specific cryptographically signed identity configuration and ran inside known IP CIDR blocks were automatically suppressed or assigned a lower risk score.

Trade-offs accepted

Introduced some latency in evaluation to check the DynamoDB identity directory, adding ~40ms to processing time.

Lessons Derived

Static rules always decay; threat detection systems must adapt to environment contexts and identify normal automated patterns.

10. SYSTEM LESSONS LEARNED

Engineering Lessons

Clean log ingestion requires strong schema validation on entry, as API structures occasionally shift without notice.

Architecture Lessons

Asynchronous event decoupling is essential; parsing failures must never block downstream incident processing.

Business Lessons

Operational security metrics (false-positive ratios, analyst review times) are just as critical as architectural ones.

System Redesign Plans

I would replace the DynamoDB caching layer with Redis to lower evaluation latency and enable easier cluster-wide scale.

11. ROADMAP & TECHNICAL DEBT

  • Integrate LLM-assisted alert summaries for security analysts
  • Implement active-response automated IAM isolation loops
  • Support Google Cloud audit logs ingestion

12. GITHUB SOURCE EXPLORER

Audit raw repository script configurations directly inside the active terminal workspace.

HarizuAru/Portfoliomain
Open on GitHub
Workspace Files
1
Encoding: UTF-8Lines: 1
Let's discuss your project

Interested in building a secure auto-scaling platform similar to this?

Keep exploring

Related Projects

All projects →
Cloud · DevOpsPrototype

Cloud-Native Serverless Architectures

A multi-cloud serverless deployment leveraging AWS Lambda, DynamoDB, and Azure Functions to build scalable pipelines that minimize operational overhead.

ArchitectureAPI Gateway → Lambda / Azure Functions → DynamoDB / CosmosDB

  • aws
  • azure
  • serverless
  • dynamodb
  • terraform
Security · DevOpsPrototype

Offensive Security Tooling

A collection of security assessment tools simulating attacks and identifying over-privileged credentials to verify enterprise infrastructure security.

ArchitectureIAM Config → Privilege Analyzer → Severity Dashboard

  • security
  • kali
  • iam
  • audit
  • react
Cloud · IoTProduction

Cold-Chain Thermal Management Platform

A thermal tracking platform deployed on harizeon.com that captures IoT sensor streams, plots container temperature metrics, and triggers instant alerts for cold-chain compliance.

ArchitectureIoT Sensors → AWS IoT Core → Express → DynamoDB → WebSockets → SNS

  • aws
  • iot
  • react
  • nodejs
  • websockets