TGViewer
Channel Public Channel
CloudSec Wine

CloudSec Wine

@cloud_sec

All about cloud security

Contacts:
@AMark0f
@dvyakimov

About DevSecOps:
@sec_devops
Subscribers
2.27K
Photos
1.1K
Videos
0
Links
1.4K

Showing posts older than #472 · Back to latest

Older Posts 20 shown
Post #471 760
🔶 The Many Ways to Manage Access to an EC2 Instance

By Sym’s Mathew Pregasen. Options: EC2 key pairs, SSH access via 3rd-party tools, SSH access via IAM policies, eliminate direct access via GitOps (SSM’s Run Command), and temporary or JIT access.

https://blog.symops.com/2022/09/22/ec2-access

#aws
  • 👍 1
  • 🔥 1
Post #468 766
🔶 zoph-io/aws-security-survival-kit

Victor Grenu helps you set up minimal alerting on typical suspicious activities on your AWS Account. Using this kit, you will deploy CloudWatch EventRules and CW alarms on:

1️⃣ Root User activities
2️⃣ CloudTrail changes
3️⃣ AWS Personal Health Events
4️⃣ IAM Users changes
5️⃣ MFA updates
6️⃣ Unauthorized Operations
7️⃣ Failed AWS Console login authentication

https://github.com/zoph-io/aws-security-survival-kit

#aws
  • 👍 1
  • 🔥 1
Post #463 744
🔶 thundra-io/merloc

By Thundra: A live AWS Lambda function development and debugging tool. MerLoc allows you to run AWS Lambda functions on your local while they are still part of a flow in the AWS cloud remote.

https://github.com/thundra-io/merloc

#aws
  • 👍 1
  • 🔥 1
Post #462 839
🔶 Authenticating to AWS the right way for (almost) every use-case

Lee Briggs covers the right way to authenticate to AWS in a variety of scenarios:

1️⃣ Authenticate to AWS as a Human User: AWS IAM Identity Center

2️⃣ Authenticate to AWS as an EC2 Instance: IAM Role, possibly Instance Profile

3️⃣ Authenticate to AWS as an application that only manages content in an S3 bucket: Presigned URLs

4️⃣ Authenticate to AWS as a CI/CD Pipeline: OIDC Providers

5️⃣ Authenticate to AWS as compute I manage that isn’t running inside AWS: IAM Roles Anywhere

https://leebriggs.co.uk/blog/2022/09/05/authenticating-to-aws-the-right-way

#aws
  • 🔥 3
Post #461 1.19K
🔶 matanolabs/matano

An open source security lake platform for AWS that lets you ingest petabytes of security and log data from various sources, store and query them in an open Apache Iceberg data lake, and create Python detections as code for realtime alerting. Matano is fully serverless and designed specifically for AWS and focuses on enabling high scale, low cost, and zero-ops.

https://github.com/matanolabs/matano

#aws
  • 👍 1
  • 🔥 1
Post #459 684
🔷 Azure Active Directory Pass-Through Authentication Flaws

Secureworks researchers analyzed how the protocols used by Pass-Through Authentication (PTA) could be exploited. The result? A compromised PTA agent certificate gives threat actors persistent and undetectable access to a target organization.

https://www.secureworks.com/research/azure-active-directory-pass-through-authentication-flaws

#azure
Sophos Azure Active Directory Pass-Through Authentication Flaws In May 2022, Sophos® Counter Threat Unit™ (CTU) researchers analyzed how the protocols used by Pass-Through Authentication could be exploited.
  • 🔥 1
Post #453 732
🔶 Attacking Firecracker: AWS' microVM Monitor Written in Rust

Firecracker is a microVM manager in Rust that powers AWS services like Lambda and Fargate. Here's how a red team team attacked a vulnerability in Firecracker.

https://www.graplsecurity.com/post/attacking-firecracker

#aws
SecOps Insights Firecracker Security: How Does microVM Isolation Really Work? Why are more security teams adopting Firecracker? How secure is it, and how suitable is it for your organization? This guide dives into this trending innovation.
  • 🔥 2
Post #452 823
🔶 CJ Moses might be the CISO of AWS, but service leaders own their own security

Interesting interview with AWS’s CJ Moses covering topics including:

1️⃣ What are your duties as CISO?
2️⃣ What is AWS’ security strategy?
3️⃣ What’s the biggest threat to cloud security right now and how do you stay ahead of all these bad actors?
4️⃣ What are the biggest security mistakes that you see enterprise customers repeating?

https://www.protocol.com/enterprise/cj-moses-aws-ciso

#aws
Protocol CJ Moses might be the CISO of AWS, but service leaders own their own security Moses, a former FBI tech leader and one-time AWS customer, thinks Amazon’s culture of ownership helps him secure AWS because executives are taught that they are directly responsible for the security of their services.
  • 🔥 2
  • 👍 1
Post #451 734
🔶 Incident Response in AWS

Post intended to help those already familiar with the principles of Incident Response to understand what to do when the incident involves the AWS Control Plane.

https://www.chrisfarris.com/post/aws-ir

#aws
  • 🔥 1
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →