What is AWS CloudTrail?

AWS CloudTrail is a service that enables governance, compliance, operational auditing, and risk auditing of your AWS account. With CloudTrail, you can log,continuously monitor, and retain events related to API calls across your AWS infrastructure. CloudTrail provides a history of AWS API calls for your account including API calls made through the AWS Management Console,…

AWS Security challenges

● Lack of end-end Security Visibility● 73% of Companies have Critical AWS Security Misconfigurations● Continuous Compliance & Remediation● Not Implementing Data Protection Mechanism● Failure to Enable Logging on All S3 buckets. S3 Bucket Permissions.● IAM Users Granted Direct Permissions● Disabled, Not Enabled, or Improperly Configured CloudTrail● Broad IP Range Access for DB Security Groups● VPC…

Thread detection classification

Backdoor: resource compromised and capable of contacting source home Behavior: activity that differs from established baseline Cryptocurrency: detected software associated with cryptocurrencies Pentest: activity detected similar to that generated by known penetration testing tools Persistence: established a presence in the environment Recon: attack scoping vulnerabilities by probing ports, listening, using database tables, etc. Resource consumption:…