Introduction to AWS Threat Detection

Introduction to AWS Threat Detection

1h 5mBeginner2023-08-15

Authors

Day Johnson

Day Johnson

Course details

If you work in an AWS cloud environment, you can’t overlook the importance of security. Join instructor Day Johnson in this beginner-friendly course for an overview of how cloud security analysts, cloud security engineers, and cloud incident responders can use AWS to investigate and analyze potentially compromising security threats.

Explore foundational skills and tactics for auditing activities with MITRE Cloud Matrix and CloudTrail as well as how to investigate compute threats, IAM threats, and storage threats. By the end of this course, you’ll also have the skills required to start detecting threats with Amazon GuardDuty, the threat detection service built into AWS. This course also caters to entry-level security or cloud professionals looking to learn the basics of AWS cloud threat analysis.

Skills covered

Introduction toIncident ResponseAmazon Web Services (AWS)AmazonCloud ServicesCloud PlatformsCybersecurityCloud Computing

Concepts

Introduction

  • The rise of cloud threats
  • What you should know

MITRE Cloud Matrix

  • Understanding the MITRE Cloud Matrix
  • MITRE Cloud Tactics

Log Analysis in AWS

  • Why you need cloud audit logs
  • Understanding cloud planes
  • CloudTrail basics
  • How CloudTrail works
  • CloudTrail demo
  • Creating your first trail

CloudTrail Log Analysis

  • Introduction to CloudTrail log analysis with jq
  • jq installation
  • Unzipping CloudTrail files in bulk
  • Analyzing AWS identities with jq
  • Analyzing AWS events with jq
  • Enumeration in AWS
  • Analyzing AWS enumeration events with jq
  • Extracting AWS event details with jq
  • Introduction to CloudTrail log analysis with CloudTrail Lake
  • Getting started with AWS CloudTrail Lake
  • Challenge - Analyze CloudTrail Logs with jq
  • Solution - Analyze CloudTrail Logs with jq

Investigating Compute Threats

  • Analyzing enumeration attacks from EC2 instances
  • Amazon EC2 AMI exfiltration
  • Amazon EBS snapshot exfiltration

Investigating IAM Threats

  • AWS access key leakage
  • Malicious IAM user creation
  • Malicious access key creation
  • Malicious login profile creation
  • Malicious login profile update
  • Malicious privileged role assignment

Investigating Storage Threats

  • S3 bucket enumeration
  • S3 bucket versioning modification
  • S3 bucket policy modification
  • S3 object exfiltration
  • S3 object deletion

Investigating Logging and Monitoring Threats

  • CloudTrail logging stopped
  • CloudTrail trail deletion

Amazon GuardDuty

  • Detecting AWS threats with GuardDuty

Conclusion

  • Learning more about AWS security
40,000 Toman