Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

AWS

Articles in AWS.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
AWSPlatform Changes

Amazon Detective Goes GA (Mar 2020): Investigation Graphs for AWS Security Findings

In March 2020, Amazon Detective became generally available. It helps security teams investigate findings from GuardDuty and other sources by automatically...

AWSHow-To & Hardening

How to Investigate a GuardDuty Finding With Amazon Detective

Amazon Detective helps you answer the key questions after a GuardDuty finding: is it real, what did the identity do, and how far did it go? Here is a...

AWSHow-To & Hardening

Cloud Incident Investigation Runbook for AWS

A short, consistent runbook helps small teams respond to AWS incidents calmly. Use this as a starting template.

AWSCIO Briefings

CIO Brief: Faster Investigations Mean Smaller Breaches

The short version: Security tools generate alerts. The value comes from deciding quickly which ones are real. Amazon Detective, launched in 2020, is one of...

AWSPlatform Changes

IAM Access Analyzer Launches (Dec 2019): Finding Unintended Public and Cross-Account Access

In December 2019, AWS launched IAM Access Analyzer. It used automated reasoning — mathematical analysis of policies — to identify resources that were shared...

AWSHow-To & Hardening

How to Use IAM Access Analyzer to Find Unused and External Access

IAM Access Analyzer finds two kinds of risky access: resources shared outside your organization, and permissions nobody uses. Here is how to use both to...

AWSHow-To & Hardening

Quarterly External Access Review Checklist for AWS

External access to your AWS resources should be known and approved. This quarterly review checklist keeps it that way.

AWSCIO Briefings

CIO Brief: Who Outside Your Company Can Reach Your AWS Resources?

The short version: Companies routinely share cloud resources with vendors and partners. Over time, nobody remembers who has access to what. AWS released a...

AWSPlatform Changes

AWS Launches IMDSv2 (Nov 2019): Closing the Capital One Attack Path

In November 2019, four months after the Capital One breach, AWS released version 2 of the EC2 Instance Metadata Service (IMDSv2). It was designed...

AWSHow-To & Hardening

How to Migrate an EC2 Fleet to IMDSv2 Without Breaking Applications

IMDSv2 protects instance credentials from SSRF attacks, but enforcing it across a large EC2 fleet can break older applications if done carelessly. Here is a...

AWSHow-To & Hardening

IMDSv2 Enforcement Checklist With SCPs and Launch Templates

Use this checklist to make IMDSv2 mandatory across your AWS organization and keep it that way.

AWSCIO Briefings

CIO Brief: How One AWS Setting Answers the Capital One Breach

The short version: After Capital One's 2019 breach, AWS released a setting — IMDSv2 — that blocks the technique the attacker used to steal cloud...

AWSIncident Teardowns

Imperva's Cloud WAF Breach (Aug 2019): A Stolen AWS API Key From an Internal Instance

In August 2019, Imperva, a security company known for its cloud web application firewall (formerly Incapsula), disclosed a data exposure affecting customers...

AWSHow-To & Hardening

How to Replace Long-Lived AWS Access Keys With IAM Roles and Identity Center

Long-lived IAM user access keys are one of the most common causes of AWS breaches. IAM roles and IAM Identity Center provide short-lived credentials...

AWSDetection & Response

Detecting Stolen AWS API Keys: CloudTrail, GuardDuty and Athena Queries

Stolen AWS API keys are frequently used for reconnaissance, data theft and resource abuse. These detections help you spot misuse quickly.

AWSCIO Briefings

CIO Brief: When Your Security Vendor Loses Its Cloud Keys

The short version: In 2019, Imperva — a company that sells security protection — disclosed that customer data was exposed after an attacker stole a cloud...

AWSIncident Teardowns

Capital One (July 2019): SSRF, the EC2 Metadata Service and 100 Million Records

On July 29, 2019, Capital One disclosed a breach affecting about 100 million people in the US and 6 million in Canada. It became the defining cloud breach...

AWSHow-To & Hardening

How to Enforce IMDSv2 and Lock Down EC2 Instance Role Permissions

IMDSv2 protects EC2 instance credentials from server-side request forgery, the technique used in the Capital One breach. Combined with least-privilege...

AWSDetection & Response

Detecting SSRF Metadata Credential Theft: CloudTrail, GuardDuty and Athena Queries

The Capital One attack path — SSRF to the metadata service, then stolen role credentials used to read data — leaves traces in CloudTrail and GuardDuty if...

AWSCIO Briefings

CIO Brief: The $80 Million Fine — What Regulators Expect From Cloud Security

The short version: Capital One's 2019 breach exposed data on about 106 million people. It was caused by a misconfigured firewall combined with a server that...

AWSPlatform Changes

AWS Control Tower Goes GA (June 2019): Guardrails for Multi-Account AWS

In June 2019, AWS Control Tower became generally available. It automated the creation of a secure multi-account AWS environment — a landing zone — with...

AWSHow-To & Hardening

How to Set Up AWS Control Tower With Preventive and Detective Guardrails

AWS Control Tower sets up a governed multi-account environment with guard rails. Here is how to set it up and choose the right controls.

AWSHow-To & Hardening

Control Tower Guardrail Selection Checklist

Control Tower offers hundreds of controls. Use this checklist to choose a practical starting set.

AWSCIO Briefings

CIO Brief: Governance at Scale — Why Control Tower Matters

The short version: AWS Control Tower, released in 2019, sets up your AWS cloud as a well-organized group of accounts with security rules built in. It is the...

← NewerPage 3 of 5Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.