Skip to main content

Command Palette

Search for a command to run...

SANS AWS Detection

Updated
2 min read
SANS AWS Detection
G

Hey there! 👋🏾 I'm Goody, a Cloud Threat Researcher by Day 🌞 and a Cloud Security Content Engineer by Night🌜. Join me on my journey as I explore the realm of Threat Detection in Cloud Security.

Lifecycle Process

  • Research the attack technique — Lab 1

  • Set up proper logging — Lab 2

  • Attack realistic assets — Lab 3

  • Review log data — Lab 4

  • Build detection — Lab 5

Prerequisites: An AWS account with administrator access

NOTE: In this lab, you will be attacking your AWS Account. So please do not use your AWS Production Account.

Disclaimer

This lab write-up credits SANS for the Workshop on Building Detections in AWS. It replicates the workshop guide by the Cloud Security SANS Team. Following the instructions may result in an AWS billing of around $2, considering prompt resource deletion after completing the lab.

Lab Objective

The overall process and takeaways will be:

  • Establish proper logging to detect adversarial activity

  • Perform the attack to generate the appropriate artifacts

  • Review the log event data

  • Create an automated process to quickly discover this activity

  • Test that the automated process is working effectively by “re-attacking” the AWS account

This exercise aims to enhance your skills in detecting and responding to potential security breaches, as well as improving your understanding of AWS security features.

Lab Exercise

Reference

More from this blog

Everything ~ Cloud Security

49 posts

C☁️d Security || Cl☁️d Threat Detection 🕸️