All integrations
Security

AWS CloudTrail

Monitor API activity, detect security events, audit compliance actions, identify unauthorized access attempts, and track infrastructure changes in real-time.

COVERAGE

What we monitor

Root account activity
Authentication failures and suspicious logins
Unauthorized API calls and access denials
Console login activity
IAM policy changes
Security group modifications
Resource creation and deletion
API key and credential changes

CAPABILITIES

Key features

1

Security Event Detection

Automatically detect suspicious API activity with AI context about threat severity and recommended response.

2

Compliance Auditing

Track all infrastructure changes and user actions for compliance reporting and audit trails.

3

Unauthorized Access Detection

Alert on failed authentication attempts and API calls from unexpected sources or patterns.

4

Privilege Escalation Monitoring

Identify when users or roles gain elevated permissions that weren't previously authorized.

5

MITRE ATT&CK Mapping

Every alert is automatically mapped to MITRE ATT&CK tactics for threat-driven security.

NATURAL LANGUAGE RULES

Example alert rules

Write monitoring rules in plain English. Stratl translates them to precise detection logic automatically.

stratl rule
"Alert immediately on any successful root account login"

Root account usage should be rare; this catches potential account compromise.

stratl rule
"Notify the security team if IAM policies are modified outside change windows"

Detects unauthorized privilege escalation or access changes.

stratl rule
"Alert on authentication failures from new IP addresses"

Identifies potential brute force attacks or compromised credentials.

ECOSYSTEM

Works with your stack

AWS CloudTrail events are correlated with activity across your entire AWS infrastructure.

CloudWatch
GuardDuty
Config
Security Hub

Your AWS alerts deserve intelligence

Stop drowning in CloudTrail noise. Start getting alerts that actually explain what happened and what to do about it.

No credit card required. Set up in under 5 minutes.