Investigating AWS Incidents

Investigate security incidents in Amazon Web Services -- reconstruct attacker activity from CloudTrail, VPC Flow Logs, and GuardDuty, anchor the investigation on the compromised principal (access key or role), trace privilege escalation and persistence through IAM API calls, detect data exfiltration and crypto-mining, and contain without destroying evidence or tipping off the attacker. Use when responding to a suspected AWS compromise, exposed access keys, anomalous CloudTrail activity, a GuardDuty finding, unexpected IAM changes, crypto-mining EC2 instances, or S3 data exfiltration.

trilwu 840043a 18.7 KB Updated

File contents

trilwu/secskills/tree/main/secskills-defense/skills/investigating-aws-incidents commit 840043a516

Frequently asked questions

npx skillmds add trilwu/investigating-aws-incidents