Detecting Cryptojacking in Cloud: CloudTrail, GuardDuty and Athena Queries
Cryptojacking — using stolen cloud resources to mine cryptocurrency — is one of the most common outcomes of a cloud compromise. It is also one of the most...
Insights
Articles in Detection & Response.
Cryptojacking — using stolen cloud resources to mine cryptocurrency — is one of the most common outcomes of a cloud compromise. It is also one of the most...
Hardware vulnerabilities like Meltdown and Spectre are hard to detect being exploited. The practical detection task is making sure every system actually...
Leaked AWS access keys are often used within minutes of exposure. Detecting misuse quickly limits how much an attacker can do.
Most S3 misconfigurations begin with a configuration change. Monitoring those changes in near real time catches exposures within minutes rather than months.
Exploitation of public-facing web applications is one of the most common ways attackers get in. Detecting exploitation attempts — and especially successful...
Compromised administrator accounts give attackers control of an entire Microsoft 365 tenant. Detecting unusual admin behavior early is one of the...
Overly broad bucket policies are a frequent root cause of S3 exposures. Detecting policy changes that widen access — and catching risky policies already in...
NotPetya combined credential theft with legitimate admin tools to move across networks. Detecting that pattern early is one of the most effective ways to...
The best time to catch a public S3 bucket is the moment it becomes public. Detection rules on configuration changes close the window between a mistake and...
WannaCry and its successors exploited SMB flaws to spread across networks. Even with SMBv1 removed, detecting suspicious SMB activity is a valuable early...
When a provider leaks session tokens, the question is whether anyone used them. Detection focuses on sessions that look valid but behave differently from...
Credential stuffing uses username and password pairs leaked from other breaches to try to sign in to your Microsoft 365 tenant. Detection is about spotting...
DDoS attacks against DNS and web front ends are noisy, which makes them easy to notice and hard to diagnose quickly. The goal of detection is speed: confirm...