Monitoring attested requests
You can use your AWS CloudTrail logs to monitor Decrypt, DeriveSharedSecret, GenerateDataKey, GenerateDataKeyPair, and GenerateRandom operations that use attestation. In these log entries, the
additionalEventData
field has a recipient
field with
information from the attestation document in the request. These fields are included only
when the Recipient
parameter in the request specifies a signed attestation
document.
The specific information included in the CloudTrail log depends on the attestation method used.