Performing Serverless Function Security Review
Overview
Cybersecurity skill for performing serverless function security review. Follows industry best practices and security standards.
When to Use
Trigger phrases:
"performing serverless function security review"
"Performing security reviews of serverless functions across AWS Lambda, Azure Fun"
When auditing serverless applications before production deployment
When investigating potential data exposure through function environment variables or logs
When assessing the blast radius of a compromised serverless function execution role
When compliance reviews require documentation of serverless security controls
When building secure-by-default templates for serverless deployments
Do not use for container or VM security assessments (use container scanning tools), for API security testing (use DAST tools on the API Gateway layer), or for real-time serverless threat detection (use AWS Lambda Extensions with security agents).
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- AWS CLI, Azure CLI, and gcloud CLI configured with appropriate permissions
- Access to read function configurations, policies, and execution roles
- Prowler or Checkov for automated serverless security scanning
- SAM CLI or Serverless Framework for local function analysis
- CloudTrail, Azure Monitor, or Cloud Audit Logs enabled for function invocation monitoring
Workflow
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
- Plan Operations — Define objectives, scope, and success criteria for serverless function security review operations.
- Prepare Environment — Set up tools, access, and data sources required for serverless function security review.
- Execute Core Workflow — Perform the serverless function security review operations following established procedures.
- Validate Results — Verify that results meet quality standards and objectives.
- Report Findings — Document results, observations, and recommendations.
- Follow Up — Track remediation actions and verify fixes where applicable.
Tools
- Analysis Platform — Data processing and visualization
- Collaboration Tools — Team coordination and knowledge sharing
Process
- Reconnaissance — Gather target information, identify attack surface, enumerate services
- Analysis/Exploitation — Execute the technique, analyze results, document findings
- Reporting — Document IOCs, write findings, provide remediation recommendations
Verification
Anti-Rationalization Table
| Rationalization |
Reality |
| "We are too small to be targeted" |
Automated attacks target everyone. Size does not matter. |
| "Security slows us down" |
A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" |
Vulnerabilities in production are exploited within hours. Fix before deploy. |
1---2name: performing-serverless-function-security-review3description: Use when performing security reviews of serverless functions across AWS Lambda, Azure Functions, and GCP Cloud Functions to identify overly permissive execution roles, insecure environment variables, injection vulnerabilities, and missing runtime protections. . Use when working with performing serverless function security review.4license: Apache-2.05---67# Performing Serverless Function Security Review89## Overview1011Cybersecurity skill for performing serverless function security review. Follows industry best practices and security standards.1213## When to Use14**Trigger phrases:**15- "performing serverless function security review"16- "Performing security reviews of serverless functions across AWS Lambda, Azure Fun"171819- When auditing serverless applications before production deployment20- When investigating potential data exposure through function environment variables or logs21- When assessing the blast radius of a compromised serverless function execution role22- When compliance reviews require documentation of serverless security controls23- When building secure-by-default templates for serverless deployments2425**Do not use** for container or VM security assessments (use container scanning tools), for API security testing (use DAST tools on the API Gateway layer), or for real-time serverless threat detection (use AWS Lambda Extensions with security agents).262728## When NOT to Use2930- When you lack proper authorization for testing31- For production systems without change management32- When the task requires legal or compliance expertise beyond technical scope333435## Prerequisites3637- AWS CLI, Azure CLI, and gcloud CLI configured with appropriate permissions38- Access to read function configurations, policies, and execution roles39- Prowler or Checkov for automated serverless security scanning40- SAM CLI or Serverless Framework for local function analysis41- CloudTrail, Azure Monitor, or Cloud Audit Logs enabled for function invocation monitoring4243## Workflow4445```python46# Example: IOC detection47import re4849IOC_PATTERNS = {50 "ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",51 "domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",52 "hash_md5": r"\b[a-f0-9]{32}\b",53 "hash_sha256": r"\b[a-f0-9]{64}\b",54}5556def extract_iocs(text: str) -> dict:57 return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}58```59601. **Plan Operations** — Define objectives, scope, and success criteria for serverless function security review operations.612. **Prepare Environment** — Set up tools, access, and data sources required for serverless function security review.623. **Execute Core Workflow** — Perform the serverless function security review operations following established procedures.634. **Validate Results** — Verify that results meet quality standards and objectives.645. **Report Findings** — Document results, observations, and recommendations.656. **Follow Up** — Track remediation actions and verify fixes where applicable.6667## Tools6869- **Analysis Platform** — Data processing and visualization70- **Collaboration Tools** — Team coordination and knowledge sharing717273## Process74751. **Reconnaissance** — Gather target information, identify attack surface, enumerate services761. **Analysis/Exploitation** — Execute the technique, analyze results, document findings771. **Reporting** — Document IOCs, write findings, provide remediation recommendations7879## Verification8081- [ ] All serverless function security review procedures executed completely and documented82- [ ] Findings validated against multiple data sources83- [ ] False positives identified and filtered84- [ ] Results documented with evidence and timestamps85- [ ] Recommendations provided with risk-based prioritization8687## Anti-Rationalization Table8889| Rationalization | Reality |90|---|---|91| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |92| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |93| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |