AWS WAF adds support for JSON parsing and inspection
Introducing Amazon VPC Endpoints for AWS CloudHSM
https://aws.amazon.com/about-aws/whats-new/2021/02/introducing-amazon-vpc-endpoints-aws-cloudhsm/
AWS Identity and Access Management now supports tags on additional resources
https://aws.amazon.com/about-aws/whats-new/2021/02/aws-identity-and-access-management-now-supports-tags-on-additional-resources/
AWS CloudHSM Adds New Availability Zones
https://aws.amazon.com/about-aws/whats-new/2021/02/aws-cloudhsm-adds-new-availability-zones/
Use tags to manage and secure access to additional types of IAM resources
Mitigate data leakage through the use of AppStream 2.0 and end-to-end auditing
I’ve spent the past weeks building a 2 day class in Cloud Security Engineering. Unfortunately, I won’t be able to upload the slides anywhere but the labs are made public. Hope someone finds them to be useful despite the lack of context provided by the slides.
125
27Feb 14 · 4:14 AM
🏷️IAM has more resources to tag🏷️ This is cool because now you can tag customer managed policies. Helps organize and control access to specific policies among other IAM resources. amzn.to/2Oref3L
67
16Feb 12 · 6:14 AM
🛡️ A Practical Guide to Writing Secure Dockerfiles
@madhuakula on useful Docker security resources + tools
* Securely passing in secrets
* Tools: BuiltKit, hadolint, dockle, dive, conftest
* DockerSlim: autogenerating Seccomp and AppArmor profiles
speakerdeck.com/madhuakula/a-p…
53
18Feb 10 · 5:00 PM
🤬 Creating IAM policies is hard
What if we could just observe AWS CLI calls and auto-generate an IAM policy?
Tool by @iann0036 that uses client-side monitoring (CSM) to do just that 🙌
github.com/iann0036/iamli…
59
10Feb 10 · 11:00 PM
If you perform penetration tests on AWS accounts regularly and are interested in trying out an extremely destructive 😈 AWS pentesting tool I am going to open source next week-ish, please ping me.
49
4Feb 10 · 12:27 AM
From @tdmalone in the og-aws Slack, you can't enforce HTTPS via an SCP because some AWS services use HTTP. ☹️
34
9Feb 10 · 4:56 PM
Dropping that new AWS security tool in 48 hours.
I honestly can’t contain my excitement.
Relevant content:
34
1Feb 14 · 8:15 PM
Lab 6: Memory dump of Windows instances with upload to S3.
Lab 7: Simple AWS response lab using boto3 and Python
github.com/karimelmel/clo…
The class will be held for a non-profit the coming week!
28
6Feb 14 · 4:15 AM
In my latest post, I talk about that weird situation of having the same root email for two #AWS accounts and what its implications are.
onecloudplease.com/blog/case-of-t…
26
7Feb 11 · 10:45 PM
Given the S3 durability guarantee that AWS loses 1 object per year for every 100B objects, and that in 2012 S3 was already storing 900B objects, I wish AWS would define what happens when they lose an S3 object. aws.amazon.com/s3/faqs/
This is neat. I saw in a job ad that AWS handles 750M TPS. I then found this article about it handling 1M TPS 9 years ago.
Talk about rapid growth! Will it continue at that rate? Which services contribute the most to that? S3 and CloudFront, maybe?
20
6Feb 10 · 11:17 PM
CloudFormation::Council::Bens, assemble! Custom resource providers can now be defined in templates
docs.aws.amazon.com/AWSCloudFormat…
@ben11kehoe @benbridts
19
3Feb 12 · 2:43 AM
This is neat. I saw in a job ad that AWS handles 750M TPS. I then found this article about it handling 1M TPS 9 years ago.
Talk about rapid growth! Will it continue at that rate? Which services contribute the most to that? S3 and CloudFront, maybe?
21
0Feb 10 · 10:47 PM
Opened a mid-level Pentester role as well. If you're passionate about cybersecurity but the specs dont quite match up, reach out to us anyway! Careers@rhinosecuritylabs.com
apply.workable.com/j/0C7173C530
11
9Feb 08 · 11:39 PM
🎥🍿An overview and demo of how to implement fine-grained access control with Amazon Cognito identity pools and a demo of using attributes from identity providers for access control (ABAC). More on identity pools here: docs.aws.amazon.com/cognito/latest…
@AWSIdentity
youtube.com/watch?v=tAUmz9…
14
3Feb 10 · 9:46 PMAWS Support is better than any other vendor support I've used.
I've been working professionally in IT for a decade in a variety of roles. I've opened tickets with Microsoft, VMware, Novell, Oracle, SolarWinds, Dell, EMC, NetApp, Red Hat, and many more. I've been working full time with AWS for over four years now and their Support has ALWAYS been top …
When discussing the cost of AWS with your clients do you bring up electricity costs for on-prem servers?
I was trying to get a client to move to 365 and AWS. They did like the cost estimation I had setup. To put the final nail in the coffin and seal the deal I calculated the run time for their servers and wattage. I also got one of their …
Zscaler Newbie
Dear Group Members,
What are your thoughts about ZScaler and what do you think are the benefits using it as well as the predictions for the future?
How would you describe ZScaler using a few words?
And what are/is the main difference(s) to traditional network security or Cisco’s technology?
Happy …


