97 articles AWS Page 2 / 10
How can I find the resources associated with an Amazon EC2 security group
https://aws.amazon.com/premiumsupport/knowledge-center/ec2-find-security-group-resources/
Apply only security updates in Amazon linux AMI
# list the available security updates $ yum list-security –security # applying the security patches $ sudo yum update –security
AWS EC2 UBUNTU AMI LOCATOR
https://cloud-images.ubuntu.com/locator/ec2/
What is AWS CloudTrail?
AWS CloudTrail is a service that enables governance, compliance, operational auditing, and risk auditing of your AWS account. With CloudTrail, you can log,continuously monitor, and retain events related to API calls across your AWS infrastructure. CloudTrail provides a history of AWS API calls for your account including API calls made through the AWS Management Console,…
Example S3 bucket polices VPC endpoint
https://docs.aws.amazon.com/AmazonS3/latest/userguide/example-bucket-policies-vpc-endpoint.html Example Restricting access to a specific VPC enpoint Example Restricting access to a specific VPC
Automate server patch with AWS Patch Manager and Inspector Architecture
AWS Security challenges
● Lack of end-end Security Visibility● 73% of Companies have Critical AWS Security Misconfigurations● Continuous Compliance & Remediation● Not Implementing Data Protection Mechanism● Failure to Enable Logging on All S3 buckets. S3 Bucket Permissions.● IAM Users Granted Direct Permissions● Disabled, Not Enabled, or Improperly Configured CloudTrail● Broad IP Range Access for DB Security Groups● VPC…
Thread detection classification
Backdoor: resource compromised and capable of contacting source home Behavior: activity that differs from established baseline Cryptocurrency: detected software associated with cryptocurrencies Pentest: activity detected similar to that generated by known penetration testing tools Persistence: established a presence in the environment Recon: attack scoping vulnerabilities by probing ports, listening, using database tables, etc. Resource consumption:…