Posts tagged: #iam
How attackers keep access to AWS through IAM: backdoor users, extra keys, admin policies, role trust and identity providers, and how CloudTrail shows it.
The CloudTrail events every AWS responder should know, from recon to impact, with the fields that carry the evidence and their MITRE ATT&CK technique ids.
A leaked AWS access key: deactivate it, then use CloudTrail to find where it was used, what it enumerated, what it created and which data it could reach.
AWS account compromised? What to do first, which logs to secure, how to scope the attack in CloudTrail and how to contain it without destroying evidence.