Monday,
December 09, 2024

๐Ÿฅ– Palette Cleanser

Welcome back from re:Invent everyone. I trust you've had a chance to recover from your time in Vegas, or from your time watching your friends in Vegas from afar. I hope you made it home without making any bad decisions. Do tattoos stay in Vegas?

If you missed any of the live talks, AWS Events has already dropped them all on YouTube. I've made a playlist of all the security presentations for your convenience.

Now let's murder this issue. Get it? Issue 187?

Have feedback about AWS Security Digest? Tell us here. This issue is also available to share online.

๐Ÿ“‹ Chef's selections

  • Amazon GuardDuty Extended Threat Detection by Matt Lewis

    My mental model for GuardDuty has always been as a toy service. Sorry, AWS friends <3. It's nice if you want compliance or a baseline capability, but serious detection and response teams know single events become noise at scale. It's super exciting to see AWS leaning into "attack sequences" that combine multiple related events and signals. Is AWS moving towards becoming a serious player in CDR?

    For the nerds, Chester Le Bron writes about related detection concepts on his blog.

  • Exploiting Public AWS Resources - CLI Attack Playbook by Eduard Agavriloae

    Hacking The Cloud is an awesome community project led by my hero Nick Frichette. I don't often include HTC pages here because it feels a little bit like including Wikipedia articles. They are more of a reference than a new item. This article however reads as both a reference and a cool summary of available research/techniques for hacking public resources.

  • CloudGoat Official Walkthrough Series: โ€˜sqs_flag_shopโ€™ by John De Armas

    CloudGoat is Rhino Security Labsโ€™ tool for deploying โ€œvulnerable by designโ€ AWS infrastructure to practice cloud hacking. John walks us through an attack on a CloudGoat web application that exposes access to an SQS queue. The impact of an attack on an application queue is often determined by how much the attacker can find out about message types and formats.

๐Ÿฅ— AWS security blogs

๐Ÿ› Reddit threads on r/aws


๐Ÿค– Dessert

Dessert is made by robots, for those that enjoy the industrial content.

๐Ÿง IAM permission changes

๐Ÿช API changes

๐Ÿน IAM managed policy changes

โ˜• CloudFormation resource changes

    No resource updates this week.

๐ŸŽฎ Amazon Linux vulnerabilities

    No new CVEs.

๐Ÿ“บ AWS Security Bulletins

    No bulletins this week.

YouTube Twitter LinkedIn