"Mindmap" your way into the Cloud: A framework for hunting in AWS and GCP

Опубликовано: 04 Ноябрь 2024
на канале: SANS Cloud Security
1,405
56

Interested in more great talks like this? SANS CloudSecNext FREE Global Summit is coming up June 3-4. Learn more and register here: https://www.sans.org/u/1dhq


Threat hunting is a deliberate effort to proactively search through data in order to detect threats that have evaded otherwise predictable security alerts or detections. The subset of logs that we don't generally care about could serve as major treasure troves to perform rewarding hunts. When it comes to the cloud, the AWS and GCP MITRE ATT&CK Matrix give us a good starting point on how to approach each of the cloud-specific attacker Techniques, Tactics and Procedures (TTPs). However, which of these listed tactics should we care about for hunting ? How do these TTPs translate in terms of actual logsets like AWS Cloudtrail or GCP Stackdriver? This presentation will present to the audience a mind-map for threat hunting in AWS and GCP environments. More specifically, this mind-map would translate Cloud ATT&CK TTPs to specific patterns to look for in these 2 logsets: 1. AWS Cloudtrail and 2. GCP Stackdriver. The presentation will also take the audience through how the mind-map is applied to hunt for 2 specific example use-cases focused on GCP and AWS.

Vidya Gopalakrishnan @vidya_gkrishnan, Security Engineer, Palo Alto Networks

View upcoming Summits: http://www.sans.org/u/DuS
Download the presentation slides (SANS account required) at http://www.sans.org/u/195g