to protect organizations, their critical systems, and sensitive information from cyber- attacks. ⚬These cyber-attacks are usually aimed at accessing, changing, or destroying sensitive information; extorting money from users; or interrupting normal business processes. ⚬Two teams in Cybersecurity: the Red Team and the Blue Team. Cybersecurity
or a software that can be exploited. Threat A threat is anything that could exploit a vulnerability Risk Risk is the probability of a negative event occurring Sensative info Usernames, passwords, secret keys, secrets, config files, Service Entities IT Infrastucture Services provided by Cloud Service provider. Attacker, Victim, Organization, Service Provider Servers, Storage and Networking Capabilities Event, Incident, Security Incident Potential events which breaks CIA Triad
Easy Usage • Continuous Monitoring • Multi-account and Multi-region support • No additional software is required • Integrates with other AWS Services • Incident Response
Severity • Your EC2 instances interacting with botnet command and control server • Bots are agents launching DDOS Attacks • This means your instance is compromised.
Your EC2 instance is interacting with an IP associated with crypto activity. • Hackers use compromised resources for bitcoin mining requires investigation. • If it is a valid use case, you can set up a suppression rule for it.
and manipulate, interrupt, or destroy data in the victim's account. • Example: Deleting security groups etc. AWS Environment Impact:IAMUser/AnomalousBehavior
for detecting and responding to – ■ cyber threats, ■ security breaches ■ cyberattacks. • The goal of Incident Response: To prevent cyberattacks Incident Response
your recovery resources before you need them • Understand the AWS Shared Responsibility Model • Do not use root account credentials for day-to-day interactions with AWS! • Activate multi-factor authentication (MFA) on the AWS account root user and any users with interactive access to AWS Identity and Access Management (IAM) • Audit IAM users and their policies frequently • Monitor your account and its resources • Enable logging and Monitoring Best Practices