Issue #113

Monday · April 10, 2023

šŸ„— AWS security blogs

  • Reduce triage time for security investigations with Amazon Detective visualizations and export data — To respond to emerging threats, you will often need to sort through large datasets rapidly to prioritize security findings. Amazon Detective recently released two new features to help you do this. New visualizations in Detective show the connections between entities related to multiple Amazon GuardDuty findings, and a new export …
  • TLS inspection configuration for encrypted traffic and AWS Network Firewall — AWS Network Firewall is a managed service that provides a convenient way to deploy essential network protections for your virtual private clouds (VPCs). In this blog, we are going to cover how to leverage the TLS inspection configuration with AWS Network Firewall and perform Deep Packet Inspection for encrypted traffic. …
  • Logging strategies for security incident response — Effective security incident response depends on adequate logging, as described in the AWS Security Incident Response Guide. If you have the proper logs and the ability to query them, you can respond more rapidly and effectively to security events. If a security event occurs, you can use various log sources …

šŸ› Reddit threads on r/aws

šŸ“Œ Newsletters

šŸ“Œ "AWS Security" on Google News

🧁 IAM permission changes

  • trustedadvisor: 10 new actions — 10 new actions: CreateEngagement (Grants permission to create an engagement), CreateEngagementAttachment (Grants permission to create an engagement attachment), CreateEngagementCommunication (Grants permission to create an engagement communication), GetEngagement (Grants permission to view an engagment), GetEngagementAttachment (Grants permission to view an engagment attachment), GetEngagementType (Grants permission to view a specific engagement type), …
  • codecatalyst: 3 new actions | 8 updated actions, 1 updated resource — 3 new actions: ListTagsForResource (Grants permission to list tags for an Amazon CodeCatalyst resource), TagResource (Grants permission to tag an Amazon CodeCatalyst resource), UntagResource (Grants permission to untag an Amazon CodeCatalyst resource); 8 updated actions: AcceptConnection (conditions), AssociateIamRoleToConnection (conditions), DeleteConnection (conditions), DisassociateIamRoleFromConnection (conditions), GetBillingAuthorization (conditions), GetConnection (conditions), ListIamRolesForConnection (conditions), PutBillingAuthorization …
  • sumerian: — AWS Service Removed

šŸŖ API changes

Get every AWS security change,
on a plate every Monday.

6,700+ engineers, builders and CISOs let us diff the AWS changelog every week.