Tamper-Evident Audit Trail¶
Every analyst action (acknowledge, resolve, dismiss, false-positive, assign), every remediation, and every configuration change — with a field-level diff — plus logins, logouts, and denied access attempts is recorded with who, when, their role, and origin IP to a write-once (WORM) S3 store with Object Lock.
The application can append but never alter or erase records, so the chain of custody holds even if a component is compromised. The trail is queryable in Athena and surfaced in scheduled reports. Choose GOVERNANCE or fully immutable COMPLIANCE retention at deploy.
Where to review it¶
- The per-threat Audit History section.
- The scheduled report's Audit Activity table.
- The saved Athena query "Audit activity (who did what)" — database
<stack>_siem, tableaudit.
A threat's full action history (status changes, notes, remediations) can be pulled directly from the WORM audit archive even after the live record has aged out of the operational store — so "what was done about this?" stays answerable (advanced+).
Analyst notes¶
As you work a threat, add free-text notes in the Audit History section. Notes are append-only and appear in the threat's history (and the audit trail) alongside status changes and remediations, so the investigation reads as a running record.
Retention and archive¶
The live threat list in DynamoDB — the one you triage — is kept bounded by a daily archive pass, so dashboard totals stay exact and the list stays fast after months of activity. A threat leaves the live list when it is handled (resolved / false-positive / dismissed) and older than a short grace window, when it passes a hard age cap regardless of status, or — as a ceiling — when the live count runs high (oldest / lowest-severity first). Every removal is recorded in the audit trail, and the forensic copy in the S3 datalake and the WORM audit store keep their own, longer retention — archiving only prunes the operational store, never the record of what happened. Tune the grace window, hard age cap, and the live-count high/low-water marks under Settings → Threat Retention & Archive.