Securing Serverless Functions
Overview
Cybersecurity skill for securing serverless functions. Follows industry best practices and security standards.
When to Use
Trigger phrases:
"securing serverless functions"
"This skill covers security hardening for serverless compute platforms including "
When deploying Lambda functions or Azure Functions with access to sensitive data or cloud APIs
When auditing existing serverless workloads for overly permissive IAM roles
When integrating serverless functions into a DevSecOps pipeline with automated security scanning
When hardcoded secrets or vulnerable dependencies are discovered in function code
When establishing runtime monitoring for serverless workloads to detect injection or credential theft
Do not use for container-based compute security (see securing-kubernetes-on-cloud), for API Gateway configuration (see implementing-cloud-waf-rules), or for serverless architecture design decisions.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- AWS Lambda, Azure Functions, or GCP Cloud Functions with deployment access
- CI/CD pipeline with dependency scanning tools (npm audit, Snyk, Dependabot)
- AWS Secrets Manager, Azure Key Vault, or HashiCorp Vault for secrets management
- CloudWatch, Application Insights, or Cloud Logging for function monitoring
Workflow
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
- Define Objectives — Clarify the goals and scope for serverless functions.
- Gather Resources — Collect tools, data, and access needed for serverless functions.
- Execute Process — Carry out serverless functions operations methodically.
- Verify Quality — Check results against acceptance criteria.
- Document Outcomes — Record findings, decisions, and next steps.
Tools
- Analysis Platform — Data processing and visualization
- Collaboration Tools — Team coordination and knowledge sharing
Process
- Prepare — Gather requirements, verify prerequisites, set up environment
- Execute — Run securing serverless functions workflow with configured parameters
- Verify — Validate output meets requirements, document results
Verification
Anti-Rationalization Table
| Rationalization |
Reality |
| "We are too small to be targeted" |
Automated attacks target everyone. Size does not matter. |
| "Security slows us down" |
A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" |
Vulnerabilities in production are exploited within hours. Fix before deploy. |
1---2name: securing-serverless-functions3description: Use when this skill covers security hardening for serverless compute platforms including AWS Lambda, Azure Functions, and Google Cloud Functions. It addresses least privilege IAM roles, dependency vulnerability scanning, secrets management integration, input validation, function URL authentication, and runtime monitoring to protect against injection attacks, credential theft, and supply chain compromises.4license: Apache-2.05---67# Securing Serverless Functions89## Overview1011Cybersecurity skill for securing serverless functions. Follows industry best practices and security standards.1213## When to Use14**Trigger phrases:**15- "securing serverless functions"16- "This skill covers security hardening for serverless compute platforms including "171819- When deploying Lambda functions or Azure Functions with access to sensitive data or cloud APIs20- When auditing existing serverless workloads for overly permissive IAM roles21- When integrating serverless functions into a DevSecOps pipeline with automated security scanning22- When hardcoded secrets or vulnerable dependencies are discovered in function code23- When establishing runtime monitoring for serverless workloads to detect injection or credential theft2425**Do not use** for container-based compute security (see securing-kubernetes-on-cloud), for API Gateway configuration (see implementing-cloud-waf-rules), or for serverless architecture design decisions.262728## When NOT to Use2930- When you lack proper authorization for testing31- For production systems without change management32- When the task requires legal or compliance expertise beyond technical scope333435## Prerequisites3637- AWS Lambda, Azure Functions, or GCP Cloud Functions with deployment access38- CI/CD pipeline with dependency scanning tools (npm audit, Snyk, Dependabot)39- AWS Secrets Manager, Azure Key Vault, or HashiCorp Vault for secrets management40- CloudWatch, Application Insights, or Cloud Logging for function monitoring4142## Workflow4344```python45# Example: IOC detection46import re4748IOC_PATTERNS = {49 "ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",50 "domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",51 "hash_md5": r"\b[a-f0-9]{32}\b",52 "hash_sha256": r"\b[a-f0-9]{64}\b",53}5455def extract_iocs(text: str) -> dict:56 return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}57```58591. **Define Objectives** — Clarify the goals and scope for serverless functions.602. **Gather Resources** — Collect tools, data, and access needed for serverless functions.613. **Execute Process** — Carry out serverless functions operations methodically.624. **Verify Quality** — Check results against acceptance criteria.635. **Document Outcomes** — Record findings, decisions, and next steps.6465## Tools6667- **Analysis Platform** — Data processing and visualization68- **Collaboration Tools** — Team coordination and knowledge sharing697071## Process72731. **Prepare** — Gather requirements, verify prerequisites, set up environment741. **Execute** — Run securing serverless functions workflow with configured parameters751. **Verify** — Validate output meets requirements, document results7677## Verification7879- [ ] All serverless functions procedures executed completely and documented80- [ ] Findings validated against multiple data sources81- [ ] False positives identified and filtered82- [ ] Results documented with evidence and timestamps83- [ ] Recommendations provided with risk-based prioritization8485## Anti-Rationalization Table8687| Rationalization | Reality |88|---|---|89| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |90| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |91| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |