๐ฃ I'm starting a research newsletter @ https://t.co/ZidPZzL0Rw
Also I'm giving away a few subs to @cybrcom [https://t.co/L4pSIgHTb5] to random folks that subscribe.
I do a ton of research daily on stuff and people ask me about stuff, this seemed like the best next step. That's it, no pitch ๐
I'm glad to share my write-up on CloudWatch Logs using the AWSLogs CLI โ it's truly great to know how to filter logs and search for errors within AWS.
Thanks @cybrcom ๐๐๐
https://t.co/fiqIevKw5N
๐ Most IAM tutorials? All theory.
This lab walks you through:
โ Creating scoped IAM roles
โ Fixing misconfigured policies
โ Using permissions boundaries
โ Capturing a real S3 flag
Secure, practical AWS training โ
https://t.co/OYPmJwCL3q
#AWSSecurity#IAM#S3Security
๐๏ธ Tomorrow.
๐ป Real labs.
๐ง Real skills.
๐ Real AWS security.
Join @cybrcomโs LIVE study group for the AWS Security Specialty โ packed with labs, troubleshooting & prep tools.
๐ May 20 | 9am PDT
Register: https://t.co/DF33MUcbZP
#AWS#SecuritySpecialty#CyberPrep
๐ต๏ธโโ๏ธ You donโt need to brute-force 3.66 QUADRILLION guesses to find an AWS Org ID.
Just 360.
In this lab, you simulate a real breach using stolen IAM keys to enumerate S3 buckets and uncover the Org ID with precision.
Try it now ๐
๐ https://t.co/BOp7pfVdMt
#CloudSecurity
๐ You donโt master cloud security by watching slides.
You master it by getting your hands dirty.
Join Cybrโs interactive AWS Security Specialty study group โ built by pros, powered by live labs.
๐ Register: https://t.co/DF33MUcbZP
#AWS#SecuritySpecialty#CloudSecurity
Want more cloud security gems like this?
We're covering everything in our AWS Security Specialty course.
๐ RT to help someone secure their AWS setup
๐ Follow @cybrcom for weekly AWS + security insights!
#AWSCommunity#DevSecOps#CloudInfra#SecuritySpecialty
How to set it up:
1๏ธโฃ Log into your AWS Management Account
2๏ธโฃ Go to Identity Center โ Settings โ Management
3๏ธโฃ Click โRegister a delegated administratorโ
4๏ธโฃ Enter your member account ID
5๏ธโฃ Confirm & shift permissions
Bonus tip:
Deploy permission sets in the delegated account โ not your management account.
This follows AWSโs Security Reference Architecture for safer, scalable governance. ๐ก๏ธ
Delegating IAM Identity Center creates a security boundary.
The delegated admin:
๐ซ Cannot delete your Identity Center
๐ซ Cannot modify permission sets from the management account
โ Can still manage users and assignments safely
Are you managing IAM Identity Center from your AWS management account?
Thatโs a security red flag. Hereโs how to fix it using AWS best practices. ๐
#AWS#CloudSecurity#IAM#AWSCertified
IAM Identity Center should not be administered from your management account.
Instead, delegate its administration to a member account (like a Shared Services account). Here's why:
โ Minimize access to the root account
โ Reduce config risks
โ Enforce least privilege
"This looked easy โ just modify a policy and create a role."
Thatโs what I thought.
Then I spent 3 weeks banging my head against one missing permission. ๐
Hereโs what I learned in @therealcybrโs IAM + S3 lab ๐
๐ https://t.co/nnqSJjr4tx
โ I learned about trust policies
โ I got better at testing IAM assumptions
โ I now respect permissions boundaries
โ And Iโll never forget s3:ListAllMyBuckets again ๐