Exfiltration Paths in Isolated Environments using VPC Endpoints

Опубликовано: 07 Октябрь 2024
на канале: SANS Cloud Security
1,723
38

In environments where sensitive workloads and data reside, controlling where traffic can exit is often done with network level controls, such as security groups and network access control lists. However, when the workloads need access to AWS managed services, these controls are no longer enough as the control plane may expose the environment to other AWS tenants if not configured correctly.

About The Speaker
Jonathan Adler
Jonathan is a Security Consultant at F-Secure Consulting where he delivers offensive and defensive security engagements with a focus on helping clients secure their AWS estates. Prior to joining F-Secure, Jonathan designed and implemented cloud-native infrastructure on AWS for venture-backed U.S. startups.
Jonathan Adler, Security Consultant, F-Secure Consulting

SANS Institute Summits at https://www.sans.org/cyber-security-s...
SANS Cloud Security Curriculum, https://www.sans.org/cloud-security/
SANS Cloud Security on Twitter: @SANSCloudSec
SANS Cloud Security on LinkedIn:   / sanscloudsec