Introduction to AWS Threat Detection
1h 5mBeginner2023-08-15
Authors

Day Johnson
Course details
If you work in an AWS cloud environment, you can’t overlook the importance of security. Join instructor Day Johnson in this beginner-friendly course for an overview of how cloud security analysts, cloud security engineers, and cloud incident responders can use AWS to investigate and analyze potentially compromising security threats.
Explore foundational skills and tactics for auditing activities with MITRE Cloud Matrix and CloudTrail as well as how to investigate compute threats, IAM threats, and storage threats. By the end of this course, you’ll also have the skills required to start detecting threats with Amazon GuardDuty, the threat detection service built into AWS. This course also caters to entry-level security or cloud professionals looking to learn the basics of AWS cloud threat analysis.
Explore foundational skills and tactics for auditing activities with MITRE Cloud Matrix and CloudTrail as well as how to investigate compute threats, IAM threats, and storage threats. By the end of this course, you’ll also have the skills required to start detecting threats with Amazon GuardDuty, the threat detection service built into AWS. This course also caters to entry-level security or cloud professionals looking to learn the basics of AWS cloud threat analysis.
Skills covered
Introduction toIncident ResponseAmazon Web Services (AWS)AmazonCloud ServicesCloud PlatformsCybersecurityCloud Computing
Concepts
Introduction
- The rise of cloud threats
- What you should know
MITRE Cloud Matrix
- Understanding the MITRE Cloud Matrix
- MITRE Cloud Tactics
Log Analysis in AWS
- Why you need cloud audit logs
- Understanding cloud planes
- CloudTrail basics
- How CloudTrail works
- CloudTrail demo
- Creating your first trail
CloudTrail Log Analysis
- Introduction to CloudTrail log analysis with jq
- jq installation
- Unzipping CloudTrail files in bulk
- Analyzing AWS identities with jq
- Analyzing AWS events with jq
- Enumeration in AWS
- Analyzing AWS enumeration events with jq
- Extracting AWS event details with jq
- Introduction to CloudTrail log analysis with CloudTrail Lake
- Getting started with AWS CloudTrail Lake
- Challenge - Analyze CloudTrail Logs with jq
- Solution - Analyze CloudTrail Logs with jq
Investigating Compute Threats
- Analyzing enumeration attacks from EC2 instances
- Amazon EC2 AMI exfiltration
- Amazon EBS snapshot exfiltration
Investigating IAM Threats
- AWS access key leakage
- Malicious IAM user creation
- Malicious access key creation
- Malicious login profile creation
- Malicious login profile update
- Malicious privileged role assignment
Investigating Storage Threats
- S3 bucket enumeration
- S3 bucket versioning modification
- S3 bucket policy modification
- S3 object exfiltration
- S3 object deletion
Investigating Logging and Monitoring Threats
- CloudTrail logging stopped
- CloudTrail trail deletion
Amazon GuardDuty
- Detecting AWS threats with GuardDuty
Conclusion
- Learning more about AWS security