Profile picture
, 17 tweets, 6 min read Read on Twitter
#BSidesLV next talk: Cloud Rules Everything Around Me 🐝 by @KyleHaxWhy
#BSidesLV cloudsec* typos aint nuthin ta fuck with
#BsidesLV agenda:
1. basics on cloud concepts.
2. Logging
3. Config mgmt
4. IR

Shared responsibility model is a thing.
#BSidesLV logging: easy to DoS yourself if done improperly.

AWS: CloudTrail, VPC Flowlogs (now with VPC mirroring), Cloudwatch metrics & alarms
#BSidesLV cloudtrail tells you who, what, when. User agent tells you if it was cli, browser, etc.

Need to centralise life (can do with azure event logs as well). Single point to consume logs. Has benefit off-account DR. Gotcha: 20kb bucket policy limit.
#BsidesLV info visualisation is key. Usage over time, error rates. Top error names & top event names.
#BSidesLV Alarms:
#BSidesLV Azure: Activity Logs (diagnostic, AD reporting, storage analysitics) and Network Security Logs

Prior art: Sean Metcalf at BSides Charm “You moved to Office 365 Now What”

Office365: some logs not enabled by default
#BSidesLV continuous compliance.

Inventory management “if you don’t know what you got, how can you Protect Ya Neck?”

Tracking Shadow IT. “Here’s this new account I added”
#BSidesLV AWS Config Rules makes it easy to stand up CIS benchmarks. Used to be $2 a config rule, so some price/scalability issues. It’s a per-region cost. Now it’s per-invocation so cost should be lower.
#BSidesLV tools:
- prowler by Toni Blyx. “Forensic Readniess Test”
- Security Monkey by Netflix & cross-account role authentication
- commercial: Redlock
#BSidesLV “IAM... standing in front of you”
#BSidesLV AWS switch role method. Federates identity between accounts. Scalable, auditable.

azure: federated identity from AD already.

considerations: MFA MFA MFA. Federated Identities. User Lifecycle Policies (tags & automation)
#BSidesLV tool: “AWS IR” for key disabling.

Incident Response:
- Have a per-cloud IR plan
- ensure IR team has sufficient access
- run game days & runbooks
#BSidesLV all tools will be linked on twitter: @KyleHaxWhy
#BSidesLV q&a: SNS is minute level resolution, can we get faster? A: can’t really get faster than they’ll provide it to us

Q: thought about automation of IR?
A: yes, valuable. Tools like margarita-shotgun to capture memory
#BSidesLV a: data transfer costs are a thing & can suck. Any advice?

A: yes, will tweet out a diagram @KyleHaxWhy & need to monitor closely
Missing some Tweet in this thread?
You can try to force a refresh.

Like this thread? Get email updates or save it to PDF!

Subscribe to French
Profile picture

Get real-time email alerts when new unrolls are available from this author!

This content may be removed anytime!

Twitter may remove this content at anytime, convert it as a PDF, save and print for later use!

Try unrolling a thread yourself!

how to unroll video

1) Follow Thread Reader App on Twitter so you can easily mention us!

2) Go to a Twitter thread (series of Tweets by the same owner) and mention us with a keyword "unroll" @threadreaderapp unroll

You can practice here first or read more on our help page!

Follow Us on Twitter!

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just three indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3.00/month or $30.00/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!