@Frichette_n Mirroring some of the earlier comments, I'd expect most detections to not rely on Cloudtrail event history - in which case this would likely impair defences considerably. That said, I'd consider outright deleting trails as 'loud'. Updating trail mgmt event types might be viable
🔖 Data exfiltration with native AWS S3 features
A deep dive on different options for abuse of legitimate S3 features with the end goal of data exfiltration, so to better understand the shortcomings of native AWS logging and monitoring tooling.
https://t.co/0a2E5wpl9r
Put some time into understanding what the implications of using certain s3 features for data exfiltration are - with a focus on how they can be detected. https://t.co/Rl3mPqygoL
@0xdabbad00 Can see how 50k AMIs total could easily trip up some large orgs. 5 public AMIs also seems really small for those in the business of making AMIs externally available
Risky Business News is nearing launch! @campuscodi published an example RBN newsletter yesterday. This one is just a proof of concept to see how well the format works. The plan is to publish one of these, with an accompanying podcast, three times a week.
https://t.co/a1a2rD6RQi