We finally got to take the @SummitRoute training by @0xdabbad00 (which we postponed when Covid first hit).
1) It's predictably great;
2) We are getting to learn about dropping these cool looking Canarytoken things...
Read about my concerns with the new Lightsail object storage and a security issue I discovered that has been fixed. Great work by the team there on resolving this so quickly. https://t.co/znrpY0nf4O
It's been a while since I reported a security issue to AWS. Happy Friday AWS security team. 😀 (It's not too bad, you can wait until Monday to look at it).
Ensuring your data in S3 buckets can withstand ransomware attacks or similar threats is not as trivial as you might expect. Here is my guidance.
https://t.co/QnKbBsXz4d
My 3rd annual "AWS Security Maturity Roadmap" is out! This is my guide for the steps to securely run on AWS. See what changed this year and download it at https://t.co/ziK34RG5vU
Did you know Lex, Transcribe, and other AWS AI services will move your data out of the regions you put it in and send your data to AWS affiliates? You should opt out of that. I've described how here. https://t.co/wGEYgOdDeo
For red teams and pentesters, and defenders wanting to know attacks to look for and protect against, I've written down the techniques I would use to attack AWS environments.
https://t.co/8lehoTzY7X
@dagrz@danieljbaird Daniel, the IAM linter I wrote can help find some issues: https://t.co/G6za1gRTLb
Usually the steps for improving IAM include looking for unused creds to get rid of, reducing privs of unnecessary admins, use SSO to avoid long-lived access keys. Happy to chat more.
In "The state of ABAC on AWS" I describe the limitations of AWS related to tagging and the steps AWS needs to take to improve this situation. https://t.co/XEwI6l2z2U
I'm making 3.5 years of anonymized Cloudtrail logs from https://t.co/56Y9ZTNbSN available for security research, with guidance on how to analyze these with Athena. This is nearly 2M log events from nearly 10K "attackers". https://t.co/CBbEkrOwtB
Following Haroon's lead I've added a /love page for the tweets about my training and other work. Potential clients should find it useful, and it definitely makes me feel good seeing how my work has helped others. 💙
https://t.co/vPM19M9Y35
Just finished 2 days of Advanced AWS Security Training with @0xdabbad00 on @_ringzer0. Great practical content that anyone running on AWS should take. Highly recommended.
Just finished the AWS Security training by @0xdabbad00 . Was well structured and I appreciated the insights he presented from real world audits and incidents.
I just finished up a @SummitRoute AWS web security training led by @0xdabbad00 My brain is mush after all that. If you're looking for AWS security training for your team check them out.
There are some good tips in this security maturity roadmap from @SummitRoute for enabling AWS Organizations and Access Analyzer to improve the security of your AWS accounts. Good reading! https://t.co/TtEiCozNpY
Interested in AWS security training? That's what I do! I'm primarily focused on private training for companies. See what others have said here: https://t.co/OS9iX0AjNm
I also have a remote training open to individuals on August 3-4: https://t.co/yQ6pRymBNM