Skip to content

Tamper-Evident Audit Trail

Every analyst action (acknowledge, resolve, dismiss, false-positive, assign), every remediation, and every configuration change — with a field-level diff — plus logins, logouts, and denied access attempts is recorded with who, when, their role, and origin IP to a write-once (WORM) S3 store with Object Lock.

The application can append but never alter or erase records, so the chain of custody holds even if a component is compromised. The trail is queryable in Athena and surfaced in scheduled reports. Choose GOVERNANCE or fully immutable COMPLIANCE retention at deploy.

Where to review it

  • The per-threat Audit History section.
  • The scheduled report's Audit Activity table.
  • The saved Athena query "Audit activity (who did what)" — database <stack>_siem, table audit.

A threat's full action history (status changes, notes, remediations) can be pulled directly from the WORM audit archive even after the live record has aged out of the operational store — so "what was done about this?" stays answerable (advanced+).

Analyst notes

As you work a threat, add free-text notes in the Audit History section. Notes are append-only and appear in the threat's history (and the audit trail) alongside status changes and remediations, so the investigation reads as a running record.

Retention and archive

The live threat list in DynamoDB — the one you triage — is kept bounded by a daily archive pass, so dashboard totals stay exact and the list stays fast after months of activity. A threat leaves the live list when it is handled (resolved / false-positive / dismissed) and older than a short grace window, when it passes a hard age cap regardless of status, or — as a ceiling — when the live count runs high (oldest / lowest-severity first). Every removal is recorded in the audit trail, and the forensic copy in the S3 datalake and the WORM audit store keep their own, longer retention — archiving only prunes the operational store, never the record of what happened. Tune the grace window, hard age cap, and the live-count high/low-water marks under Settings → Threat Retention & Archive.