Special offers now — see discounted courses.
day
:
hour
:
min
:
sec
See special offers
Introduction to AWS Threat Detection

Introduction to AWS Threat Detection

1h 5mBeginner2023-08-15

Authors

Day Johnson

Day Johnson

Course details

If you work in an AWS cloud environment, you can’t overlook the importance of security. Join instructor Day Johnson in this beginner-friendly course for an overview of how cloud security analysts, cloud security engineers, and cloud incident responders can use AWS to investigate and analyze potentially compromising security threats.

Explore foundational skills and tactics for auditing activities with MITRE Cloud Matrix and CloudTrail as well as how to investigate compute threats, IAM threats, and storage threats. By the end of this course, you’ll also have the skills required to start detecting threats with Amazon GuardDuty, the threat detection service built into AWS. This course also caters to entry-level security or cloud professionals looking to learn the basics of AWS cloud threat analysis.

Skills covered

Introduction toIncident ResponseAmazon Web Services (AWS)AmazonCloud ServicesCloud PlatformsCybersecurityCloud Computing

Concepts

0. Introduction

  • 01 - The rise of cloud threats
  • 02 - What you should know

1. MITRE Cloud Matrix

  • 03 - Understanding the MITRE Cloud Matrix
  • 04 - MITRE Cloud Tactics

2. Log Analysis in AWS

  • 05 - Why you need cloud audit logs
  • 06 - Understanding cloud planes
  • 07 - CloudTrail basics
  • 08 - How CloudTrail works
  • 09 - CloudTrail demo
  • 10 - Creating your first trail

3. CloudTrail Log Analysis

  • 11 - Introduction to CloudTrail log analysis with jq
  • 12 - jq installation
  • 13 - Unzipping CloudTrail files in bulk
  • 14 - Analyzing AWS identities with jq
  • 15 - Analyzing AWS events with jq
  • 16 - Enumeration in AWS
  • 17 - Analyzing AWS enumeration events with jq
  • 18 - Extracting AWS event details with jq
  • 19 - Introduction to CloudTrail log analysis with CloudTrail Lake
  • 20 - Getting started with AWS CloudTrail Lake
  • 21 - Challenge - Analyze CloudTrail Logs with jq
  • 22 - Solution - Analyze CloudTrail Logs with jq

4. Investigating Compute Threats

  • 23 - Analyzing enumeration attacks from EC2 instances
  • 24 - Amazon EC2 AMI exfiltration
  • 25 - Amazon EBS snapshot exfiltration

5. Investigating IAM Threats

  • 26 - AWS access key leakage
  • 27 - Malicious IAM user creation
  • 28 - Malicious access key creation
  • 29 - Malicious login profile creation
  • 30 - Malicious login profile update
  • 31 - Malicious privileged role assignment

6. Investigating Storage Threats

  • 32 - S3 bucket enumeration
  • 33 - S3 bucket versioning modification
  • 34 - S3 bucket policy modification
  • 35 - S3 object exfiltration
  • 36 - S3 object deletion

7. Investigating Logging and Monitoring Threats

  • 37 - CloudTrail logging stopped
  • 38 - CloudTrail trail deletion

8. Amazon GuardDuty

  • 39 - Detecting AWS threats with GuardDuty

Conclusion

  • 40 - Learning more about AWS security

About us

LyndaKade is a leading learning platform that helps people learn business, software, technology, and creative skills to achieve personal and professional goals.

Phone numberAparat ChannelTelegram SupportTelegram ChannelInstagram Page

All rights to this site belong to LyndaKade.

Terms of Service|Privacy Policy

نماد الکترونیک enamad در صورت اتصال با آی‌پی داخل کشور، نمایش داده خواهد شد.
logo-samandehi - لوگو ساماندهی
Zarinpal
Zibal