Incident response guide for AWS CloudTrail investigations – Part 2

In Part 1 of this guide, we examined two common incident scenarios: cross-account Amazon Simple Storage Service (Amazon S3) data deletion with ransomware implications, and cryptocurrency mining deployed through AWS CloudFormation using exposed AWS Management Console credentials. We also introduced key incident response terminology and investigative frameworks for analyzing AWS CloudTrail events.…

Image: AWS Security Blog

Coverage 1 publisher

  1. AWS Security Blog

    Incident response guide for AWS CloudTrail investigations – Part 2

Articles stay on their publishers’ sites; each link opens the original.