Sitemap
All pages on the site.
Home
Blog
- CloudTrail limitations: what log forensics cannot tell you
- AWS incident response example: leaked key to crypto-mining
- VPC Flow Logs analysis for exfiltration and mining
- AWS crypto-mining on a compromised account: respond fast
- Detecting StopLogging and GuardDuty disabled in CloudTrail
- S3 data exfiltration detection: what the logs can prove
- IAM privilege escalation and persistence in CloudTrail
- CloudTrail events to monitor, mapped to MITRE ATT&CK
- CloudTrail log analysis: a step-by-step guide
- How to investigate a leaked AWS access key
- How to export CloudTrail, VPC Flow and S3 logs for forensics
- AWS incident response: investigating a compromised account