Cloud audit logs are no longer just after-the-fact evidence. If an attacker can change the log pipeline, they can hide activity from defenders or keep seeing what happens after access is supposed to be gone.
Unit 42 shows concrete abuse paths against AWS CloudTrail and Google Cloud Logging. One set of techniques blocks or alters log delivery so security teams lose visibility. Another redirects logs into an account the attacker controls, creating a standing view into the victim environment even after remediation.
The trust assumption changes across any environment where the log source can be modified, not just AWS or Google Cloud.