Hands On Workshop Building Better Detections AWS Edition

Опубликовано: 13 Октябрь 2024
на канале: SANS Cloud Security
249
6

This is a 2-hour hands-on workshop. As with any enterprise environment, we can (and should) focus on hardening our defenses to keep the adversaries out, but these defenses may some day be evaded via a variety of methods. Cloud is no different. In this workshop, we will work through the process of creating a detection that we can use as defenders to spot an adversary performing attack techniques against our AWS environments.

The overall process and takeaways will be:
Establish proper logging to detect the adversarial activity
Perform the attack to generate the appropriate artifacts
Review the log event data
Create an automated process to quickly discover this activity
Test that the automated process is working effectively by “re-attacking” the AWS account

Prerequisites: Prepare for this webcast by watching the introductory webcast Building Better Cloud Detections... By Hacking? (AWS Edition)

System Requirements:
Laptop with a modern web browser
AWS account with root access or an IAM user with Administrator Access permissions
If you need an AWS account, you can create a free tier account with root access at https://aws.amazon.com/free/. The cost will be minimal (pennies) to complete the workshop
Basic Understanding of AWS is helpful

This content supports materials and concepts from SEC541: Cloud Security Attacker Technique, Monitoring, and Threat Detection, https://www.sans.org/cyber-security-c...

About the Speaker
As a hands-on practitioner with a gift for architecture design, Shaun McCullough explores the good and bad of how the Cloud is changing the way the industry secures and runs infrastructure. During his 25+ years of experience, Shaun has spent equal parts in security engineer and operations as well as software development. With extensive experience within the Department of Defense, Shaun was the Technical Director of the Red and Blue operations teams, a researcher of advanced host analytics, and ran a threat intelligence focused open source platform based on MITRE ATT&CK. Previously, he was a consultant with H&A Security Solutions, focusing on analytic development, DevOps support, and security automation tooling. Shaun is co-author of SANS SEC541: Cloud Security Attacker Techniques, Monitoring, and Threat Detection. Learn more about Shaun at https://www.sans.org/profiles/shaun-m...

SANS Cloud Security focuses the deep resources of SANS on the growing threats to The Cloud by providing training, GIAC certification, research, and community initiatives to help security professionals build, deploy and manage secure cloud infrastructure, platforms, and applications.

SANS Cloud Security Curriculum: www.sans.org/cloud-security
GIAC Cloud Security Certifications: https://www.giac.org/focus-areas/clou...
LinkedIn:   / sanscloudsec  
Discord: www.sansurl.com/cloud-discord
Twitter: @SANSCloudSec