Try our new research platform with insights from 80,000+ expert users

AWS CloudTrail vs CyberArk Privileged Access Manager comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 3, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

AWS CloudTrail
Ranking in User Activity Monitoring
2nd
Average Rating
8.6
Reviews Sentiment
6.4
Number of Reviews
15
Ranking in other categories
No ranking in other categories
CyberArk Privileged Access ...
Ranking in User Activity Monitoring
1st
Average Rating
8.6
Reviews Sentiment
6.8
Number of Reviews
225
Ranking in other categories
Enterprise Password Managers (2nd), Privileged Access Management (PAM) (1st), Mainframe Security (2nd), Operational Technology (OT) Security (3rd)
 

Mindshare comparison

As of August 2025, in the User Activity Monitoring category, the mindshare of AWS CloudTrail is 7.4%, down from 11.5% compared to the previous year. The mindshare of CyberArk Privileged Access Manager is 15.4%, down from 24.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
User Activity Monitoring
 

Featured Reviews

NabeelHassan - PeerSpot reviewer
Exploring management events and insights for enhanced compliance
More controls should be introduced in CloudTrail, especially to see the logs in CloudTrail itself without saving them in S3, as S3 starts to incur charges. Real-time log submission could be improved, as sometimes there is a lag of around two to three minutes, which should be under a minute.
Abdul Durrani - PeerSpot reviewer
Enables granular and secure access with just-in-time access and Zero Trust model
CyberArk provides a good amount of control over access types. However, as a future enhancement, having additional features for cross-platform integration would be beneficial. It would be good to have integrations with other tools and firewalls, such as Zscaler and CrowdStrike. Although I am not fully aware of recent updates, more cross-platform integration would be valuable. A SOC analyst would like to have centralized access in terms of information flowing in even for privileged access management. They would like to have control over everything instead of opening four to five tabs for different sorts of information. Cross-platform integration would help with that. Customers also want CyberArk's pricing to be better so that they can implement it further and have more licenses. Implementing a privileged access management solution can be challenging. It would be great if CyberArk could provide recommendations based on the compliance standards of an organization. It would help system admins ensure that all the required ports are closed and the systems are being managed properly. If any system is not being used anymore, any ports opened for that system need to be closed. Having such recommendations would be helpful.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"From a scalability point of view, the tool has no issue, and it is completely fine."
"One of the most valuable features of AWS CloudTrail is its ability to track and monitor API calls detailedly."
"AWS CloudTrail features a totally cloud-based deployment."
"It is a stable solution. AWS handles it well."
"The product’s most valuable feature is monitoring. It helps us audit the changes in AWS account at the application and resource level."
"AWS CloudTrail helps in accelerating incident investigation and response. It increases it because I pull out the logs to CloudTrail, and from CloudTrail watch, I'll send it to the Security Hub and do a visualization with Prometheus and Grafana."
"In one specific scenario, we encountered a situation where a terminated employee still had access to our environment without our knowledge. With AWS CloudTrail, we could track and monitor the employees' activities, revealing that they were downloading specific files from our customer's environment. Without it enabled, we wouldn't have been aware of this."
"AWS CloudTrail provides significant efficiency gains as it allows thorough monitoring of the environment, contributing substantially to security improvements."
"Password rotation, session recording & isolation and on-demand privileges."
"AIM has been a great help in automating password retrieval which removes the need for hard-coded credentials."
"CPM helps keep the password policy up to date."
"We also use CyberArk’s Secrets Manager. Because AWS is the biggest area for us, we have accounts in AWS that are being rotated by CyberArk. We also have a manual process for the most sensitive of our AWS accounts, like root accounts. We've used Secrets Manager on those and that has resulted in a significant risk reduction, as well."
"PSM (Privilege Session Manager."
"You can easily manage more than 4000 accounts with one PSM."
"The implementation of the PSM proxy has reduced the specific risk of "insider attacks" on our domain controllers and SLDAP servers by eliminating direct user login by an open secure connection on the user's behalf without ever revealing the privileged credentials."
"Session monitoring includes recordings of all activities performed."
 

Cons

"AWS CloudTrail can sometimes generate too much information, which might lead to a lot of unnecessary data, particularly false positives."
"AWS CloudTrail does not fit directly into our architecture as it functions more as a helper service, which limited our utilization of its capabilities."
"AWS CloudTrail should be redesigned to capture non-API calls. It would be more effective to have one tool that can perform multiple tasks instead of relying on multiple services for non-API activities."
"The solution should incorporate visibility for CloudWatch events."
"I have not experienced any challenges while using it."
"More controls should be introduced in CloudTrail, especially to see the logs in CloudTrail itself without saving them in S3, as S3 starts to incur charges."
"Filtering multiple values within the console is a feature that has yet to exist in AWS CloudTrail. You can look up a user identity, service, or action, but you can't search for multiple dimensions."
"The platform’s reporting log sheet feature could be more user-friendly."
"I would prefer that this is a fully-managed service, rather than have to manage the software ourselves and keep it up to date."
"In CyberArk Privileged Access Manager, the UI has room for improvement, as does the dashboard reporting, which could be made better or easier to use."
"The current interface is not very intuitive."
"What needs to be improved in CyberArk Enterprise Password Vault is their customer support, particularly in terms of responsiveness, willingness to help, and being more understanding. The initial setup and upgrade process for the solution is complex and can only be done by CyberArk, so this is another area for improvement."
"Updates have been somewhat difficult, resulting in challenges when moving from one version to another. The current version includes automatic updates."
"The solution is too complicated to use and should be simplified. It took me a long time to understand how to use it. There is a lot that the solution can improve for the future."
"This product needs professional consulting services to onboard accounts effectively based user profiles."
"Maintaining the product is challenging. Upgrades require a lot of resources, as it impacts the entire organization. For example, upgrading components like the Privileged Session Manager (PSM) and the vault is time-consuming and difficult. In the long term, I would like to see these processes simplified, especially for on-premise installations."
 

Pricing and Cost Advice

"AWS CloudTrail is a cheap solution."
"AWS CloudTrail is pretty affordable, and I have to double-check, but the service is free to use. I can add logs on the console, but if I want to store logs long-term, then I have to pay a storage fee, but it's relatively inexpensive."
"The solution is free if you don't need customizations but is not expensive otherwise."
"AWS CloudTrail is free."
"CloudTrail itself is free of cost."
"It is a very cheap service because management is a SaaS offering from AWS."
"I would rate the cost of CyberArk Privileged Access Manager seven out of ten with ten being the most expensive."
"CyberArk has been Gartner's number-one pick for the past ten years, so you can infer that their pricing is higher than everyone else. When you are the best, you will charge appropriately for it."
"No, I do not have any advice on the price of the product."
"CyberArk is good at what they do, and the price reflects that. You have to pay the price for the same."
"They have two types of licensing: purchase and subscription. You have to pay for each admin user, such as Microsoft admin, mail admin, database admin, etc."
"It can be an expensive product."
"The product's licensing is yearly. I would rate the solution's pricing a six out of ten."
"In comparison to other products on the market, CyberArk is a more costly product."
report
Use our free recommendation engine to learn which User Activity Monitoring solutions are best for your needs.
864,155 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
No data available
Computer Software Company
16%
Financial Services Firm
15%
Manufacturing Company
9%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about AWS CloudTrail?
In one specific scenario, we encountered a situation where a terminated employee still had access to our environment without our knowledge. With AWS CloudTrail, we could track and monitor the emplo...
What is your experience regarding pricing and costs for AWS CloudTrail?
AWS CloudTrail is categorized into management events, data events, and CloudTrail Insights. For one hundred thousand events, management costs are approximately two dollars, data events ten cents, a...
What needs improvement with AWS CloudTrail?
I'm satisfied function-wise with AWS CloudTrail; only the integration with third-party solutions is a point for improvement.
How does Sailpoint IdentityIQ compare with CyberArk PAM?
We evaluated Sailpoint IdentityIQ before ultimately choosing CyberArk. Sailpoint Identity Platform is a solution to manage risks in cloud enterprise environments. It automates and streamlines the m...
What do you like most about CyberArk Privileged Access Manager?
The most valuable features of the solution are control and analytics.
 

Also Known As

CloudTrail
CyberArk Privileged Access Security, CyberArk Enterprise Password Vault
 

Overview

 

Sample Customers

HTC, British Gas, Solinor, 2C2P
Rockwell Automation
Find out what your peers are saying about AWS CloudTrail vs. CyberArk Privileged Access Manager and other solutions. Updated: July 2025.
864,155 professionals have used our research since 2012.