# AWS Security Incident Response: Tracking Attackers Through Audit Logs Page: https://stenobird.com/podcast/the-business-compass-llc-podcasts-7078188/aws-security-incident-response-tracking-attackers-through-audit-logs Text version: https://stenobird.com/podcast/the-business-compass-llc-podcasts-7078188/aws-security-incident-response-tracking-attackers-through-audit-logs.md Podcast: [The Business Compass LLC Podcasts](https://stenobird.com/podcast/the-business-compass-llc-podcasts-7078188) Published: 2026-07-23T04:31:48+00:00 Episode link: https://podcast.businesscompassllc.com/e/aws-security-incident-response-tracking-attackers-through-audit-logs/ Audio file: https://mcdn.podbean.com/mf/web/n54qr9mzavthw9zn/b908865b-8bbf-49ed-a3f0-5c973f009595.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/the-business-compass-llc-podcasts-7078188/episodes/aws-security-incident-response-tracking-attackers-through-audit-logs Duration seconds: 1224 ## Resource A suspicious API call fires at 2 AM. An IAM role you don’t recognize starts spinning up EC2 instances. Your S3 bucket permissions changed — and nobody on your team did it. ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/the-business-compass-llc-podcasts-7078188/episodes/aws-security-incident-response-tracking-attackers-through-audit-logs/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/the-business-compass-llc-podcasts-7078188/aws-security-incident-response-tracking-attackers-through-audit-logs.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.