Alpenglow Ranger District · The Fire Lookout · Season Report
Security Posture Evidence Report
City of Alpenglow demo account · region us-east-1 · generated 2026-07-31T07:58:41.650Z by the sec-evidence-report Lambda (plank 8, Planetek AWS Boardwalk)
Demo scope: the GuardDuty findings below are AWS-generated sample findings
(titles prefixed “[SAMPLE]”), the practice smokes that exercise the detection→aggregation→evidence pipeline.
Security Hub and Config results are real evaluations of this live AWS account, including its nine always-on
demo environments.
1 · Audit trail: CloudTrail
Trail
sec-trail
Logging now
✓ yes
Multi-region
✓ yes
Log-file integrity validation
✓ yes
Logs encrypted with customer-managed KMS key
✓ yes
Latest log delivery
2026-07-31T07:57:34.373Z
2 · Encryption: KMS
Key
alias/sec-trail
Customer-managed
✓ yes
Automatic annual rotation
✓ yes
Key state
Enabled
3 · Threat detection: GuardDuty
Active findings (sample)
409
High severity
173
Medium severity
170
Low severity
66
Distinct finding types
115 (in a 200-finding sample)
Smoke field guide · what the watch is trained to see:
Finding type
What it means
Trojan:Runtime/DropPoint!DNSmedium ·5
A resource is behaving as though it carries malware.
Trojan:Runtime/DropPointmedium ·5
A resource is behaving as though it carries malware.
Trojan:Runtime/DriveBySourceTraffic!DNShigh ·5
A resource is behaving as though it carries malware.
6 · Least privilege: IAM permissions boundary (simulated proof)
Role sec-boundary-demo carries boundary arn:aws:iam::926634327975:policy/sec-permission-boundary.
Effective permissions are the intersection of its policy and the boundary, proven below with
iam:SimulatePrincipalPolicy, not assertion. Standing orders hold: the watch may read the record, never rewrite it.
Action simulated
Decision
s3:GetObject
allowed
s3:PutObject
implicitDeny, blocked by the boundary despite being granted by the role's policy
iam:CreateUser
implicitDeny, granted by neither the policy nor the boundary