Amazon Detective Goes GA (Mar 2020): Investigation Graphs for AWS Security Findings
In March 2020, Amazon Detective became generally available. It helps security teams investigate findings from GuardDuty and other sources by automatically...
In March 2020, Amazon Detective became generally available. It helps security teams investigate findings from GuardDuty and other sources by automatically...
Amazon Detective helps you answer the key questions after a GuardDuty finding: is it real, what did the identity do, and how far did it go? Here is a...
A short, consistent runbook helps small teams respond to AWS incidents calmly. Use this as a starting template.
The short version: Security tools generate alerts. The value comes from deciding quickly which ones are real. Amazon Detective, launched in 2020, is one of...
In December 2019, AWS launched IAM Access Analyzer. It used automated reasoning — mathematical analysis of policies — to identify resources that were shared...
IAM Access Analyzer finds two kinds of risky access: resources shared outside your organization, and permissions nobody uses. Here is how to use both to...
External access to your AWS resources should be known and approved. This quarterly review checklist keeps it that way.
The short version: Companies routinely share cloud resources with vendors and partners. Over time, nobody remembers who has access to what. AWS released a...
In November 2019, four months after the Capital One breach, AWS released version 2 of the EC2 Instance Metadata Service (IMDSv2). It was designed...
IMDSv2 protects instance credentials from SSRF attacks, but enforcing it across a large EC2 fleet can break older applications if done carelessly. Here is a...
Use this checklist to make IMDSv2 mandatory across your AWS organization and keep it that way.
The short version: After Capital One's 2019 breach, AWS released a setting — IMDSv2 — that blocks the technique the attacker used to steal cloud...
In August 2019, Imperva, a security company known for its cloud web application firewall (formerly Incapsula), disclosed a data exposure affecting customers...
Long-lived IAM user access keys are one of the most common causes of AWS breaches. IAM roles and IAM Identity Center provide short-lived credentials...
Stolen AWS API keys are frequently used for reconnaissance, data theft and resource abuse. These detections help you spot misuse quickly.
The short version: In 2019, Imperva — a company that sells security protection — disclosed that customer data was exposed after an attacker stole a cloud...
On July 29, 2019, Capital One disclosed a breach affecting about 100 million people in the US and 6 million in Canada. It became the defining cloud breach...
IMDSv2 protects EC2 instance credentials from server-side request forgery, the technique used in the Capital One breach. Combined with least-privilege...
The Capital One attack path — SSRF to the metadata service, then stolen role credentials used to read data — leaves traces in CloudTrail and GuardDuty if...
The short version: Capital One's 2019 breach exposed data on about 106 million people. It was caused by a misconfigured firewall combined with a server that...
In June 2019, AWS Control Tower became generally available. It automated the creation of a secure multi-account AWS environment — a landing zone — with...
AWS Control Tower sets up a governed multi-account environment with guard rails. Here is how to set it up and choose the right controls.
Control Tower offers hundreds of controls. Use this checklist to choose a practical starting set.
The short version: AWS Control Tower, released in 2019, sets up your AWS cloud as a well-organized group of accounts with security rules built in. It is the...