Alpenglow Ranger District · The Fire Lookout · Season Report

Security Posture Evidence Report

City of Alpenglow demo account · region us-east-1 · generated 2026-07-31T07:58:41.650Z by the sec-evidence-report Lambda (plank 8, Planetek AWS Boardwalk)

Demo scope: the GuardDuty findings below are AWS-generated sample findings (titles prefixed “[SAMPLE]”), the practice smokes that exercise the detection→aggregation→evidence pipeline. Security Hub and Config results are real evaluations of this live AWS account, including its nine always-on demo environments.

1 · Audit trail: CloudTrail

Trailsec-trail
Logging now✓ yes
Multi-region✓ yes
Log-file integrity validation✓ yes
Logs encrypted with customer-managed KMS key✓ yes
Latest log delivery2026-07-31T07:57:34.373Z

2 · Encryption: KMS

Keyalias/sec-trail
Customer-managed✓ yes
Automatic annual rotation✓ yes
Key stateEnabled

3 · Threat detection: GuardDuty

Active findings (sample)409
High severity173
Medium severity170
Low severity66
Distinct finding types115 (in a 200-finding sample)

Smoke field guide · what the watch is trained to see:

Finding typeWhat it means
Trojan:Runtime/DropPoint!DNS medium ·5A resource is behaving as though it carries malware.
Trojan:Runtime/DropPoint medium ·5A resource is behaving as though it carries malware.
Trojan:Runtime/DriveBySourceTraffic!DNS high ·5A resource is behaving as though it carries malware.
PrivilegeEscalation:Runtime/UserfaultfdUsage medium ·5Someone is trying to gain more permission than they were given.
PrivilegeEscalation:Runtime/ElevationToRoot low ·5Someone is trying to gain more permission than they were given.
PrivilegeEscalation:Runtime/ContainerMountsHostDirectory medium ·5Someone is trying to gain more permission than they were given.
PrivilegeEscalation:Runtime/CGroupsReleaseAgentModified high ·5Someone is trying to gain more permission than they were given.
Persistence:Runtime/SuspiciousCommand low ·5Someone is trying to keep access they should not have.
Impact:Runtime/SuspiciousDomainRequest.Reputation low ·5A resource is being used to cause harm, such as a denial-of-service.
Execution:Runtime/SuspiciousShellCreated low ·5A behavior the watch is trained to flag.
Execution:Runtime/NewBinaryExecuted medium ·5A behavior the watch is trained to flag.
Discovery:Runtime/SuspiciousCommand low ·5Someone is mapping the account to see what is worth taking.

4 · Posture management: Security Hub (AWS Foundational Security Best Practices)

Standard statusPENDING
Control findings evaluated808
Passed630
Failed178
Warning / not available0 / 0
Failed by severitycrit 1 · high 8 · med 142 · low 27

Top failed controls:

5 · Compliance automation: AWS Config, NIST 800-53 rev 5

Configuration recorderrecording
Conformance packsec-nist-800-53-rev5 · NIST 800-53 rev 5 (AWS operational best practices pack)
Rules evaluated130
Compliant32
Non-compliant27
Insufficient data (no applicable resources yet)71

Non-compliant rules:

6 · Least privilege: IAM permissions boundary (simulated proof)

Role sec-boundary-demo carries boundary arn:aws:iam::926634327975:policy/sec-permission-boundary. Effective permissions are the intersection of its policy and the boundary, proven below with iam:SimulatePrincipalPolicy, not assertion. Standing orders hold: the watch may read the record, never rewrite it.

Action simulatedDecision
s3:GetObjectallowed
s3:PutObjectimplicitDeny, blocked by the boundary despite being granted by the role's policy
iam:CreateUserimplicitDeny, granted by neither the policy nor the boundary