Posts tagged: #mitre-attack
Defense evasion on AWS: StopLogging, DeleteTrail, event selectors, GuardDuty detectors deleted, Config and Flow Logs removed, and what CloudTrail keeps.
How attackers keep access to AWS through IAM: backdoor users, extra keys, admin policies, role trust and identity providers, and how CloudTrail shows it.
The CloudTrail events every AWS responder should know, from recon to impact, with the fields that carry the evidence and their MITRE ATT&CK technique ids.