CFN Updates · @cfnupdates
70 followers · 201 posts · Server awscommunity.social

Updated AWS::CloudTrail::EventDataStore

Use the IngestionEnabled property to specify whether you want the event data store to ingest events.
docs.aws.amazon.com/AWSCloudFo

#cloudtrail #Cloudformation

Last updated 1 year ago

John Mulhall · @johmmlhll
4 followers · 189 posts · Server mastodon.ie

update from Maolte Technical Solutions Limited. findings down to 9 with 2nd and several running off key in , which are now have an . Do stay tuned for developments towards the end of the week...

#aws #organizations #demo #project #security #hub #cloudtrail #metrics #filters #cloudwatch #alarm #AWSCommunity #cloudinfrastructure #cloud

Last updated 1 year ago

TribalCyberSecurity · @tribalcyber
29 followers · 19 posts · Server infosec.exchange
John Mulhall · @johmmlhll
4 followers · 163 posts · Server mastodon.ie

making progress on org wide . I solved the issue from yesterday and have org-wide now set up in a robust configuration that complies with project requirements. It's a useful tool to develop once insights start to register, which is why creating an topic made sense. Stay tuned for updates...

#aws #organizations #demo #project #service #configuration #encryption #cloudtrail #insights #sns #cloudinfrastructure #cloudarchitecture

Last updated 2 years ago

John Mulhall · @johmmlhll
3 followers · 160 posts · Server mastodon.ie

That's a wrap for the day on my . I ran into problems around and when configuring . Got it and will check it tomorrow before I take a few hours away from the office.

#aws #organizations #demo #project #configuration #cloudtrail #sns #s3 #insights

Last updated 2 years ago

CFN Updates · @cfnupdates
43 followers · 69 posts · Server awscommunity.social

New AWS::CloudTrail::ResourcePolicy.ResourcePolicy

Use the ResourcePolicy property to specify the JSON-formatted string that contains the resource-based policy to attach to the CloudTrail channel.
docs.aws.amazon.com/AWSCloudFo

#cloudtrail #Cloudformation

Last updated 2 years ago

CFN Updates · @cfnupdates
42 followers · 68 posts · Server awscommunity.social

New AWS::CloudTrail::ResourcePolicy.ResourceArn

Use the ResourceArn property to specify the Amazon Resource Name (ARN) of the CloudTrail channel attached to the resource-based policy. The following is the format of a resource ARN: arn:aws:cloudtrail:us-east-2:123456789012:channel/MyChannel.
docs.aws.amazon.com/AWSCloudFo

#cloudtrail #Cloudformation

Last updated 2 years ago

CFN Updates · @cfnupdates
42 followers · 67 posts · Server awscommunity.social

New AWS::CloudTrail::ResourcePolicy

Use the ResourcePolicy resource to attach a resource-based permission policy to a CloudTrail channel that is used for an integration with an event source outside of AWS. For more information about resource-based policies, see CloudTrail resource-based policy examples in the CloudTrail User Guide.
docs.aws.amazon.com/AWSCloudFo

#cloudtrail #Cloudformation

Last updated 2 years ago

Teri Radichel · @teriradichel
658 followers · 139 posts · Server infosec.exchange

Analyzing CloudTrail Requests Related to SCPs: ACM.140 Trying to figure out conditions and ARNs to create a delegated administrator for SCPs
~~~~
by Teri Radichel | Jan 25, 2023

medium.com/cloud-security/anal

#cloudtrail #scp #iam #delegatedadministrator #cloudsecurity #governance

Last updated 2 years ago

CK's Technology News · @CKsTechNews
1816 followers · 3057 posts · Server cktn.todon.de
Gonçalo Valério · @dethos
297 followers · 1212 posts · Server s.ovalerio.net

"AWS CloudTrail vulnerability: Undocumented API allows CloudTrail bypass"

securitylabs.datadoghq.com/art

#cloudtrail #aws #security

Last updated 2 years ago

Emily Gladstone Cole · @Emily
240 followers · 295 posts · Server infosec.exchange

folks: check out this now-fixed vulnerability that someone found by observing AWS account traffic and parsing it. securitylabs.datadoghq.com/art

#aws #iam #iamadmin #cloudtrail

Last updated 2 years ago

Seshu · @seshu
0 followers · 2 posts · Server infosec.exchange

Many and use-cases rely on . A good audit trail captures sufficient information about WHO, WHAT, WHEN and WHERE. If any of these are missing or lacking in details, it becomes a nightmare to glue things together. I spent a decent amount of time analyzing CT. Lets check how good AWS CloudTrail is!

medium.com/@seshu/aws-cloudtra

#cspm #CIEM #aws #cloudtrail #iam

Last updated 2 years ago

Andy 'Bob' Brockhurst · @b3cft
62 followers · 90 posts · Server infosec.exchange

@dob That's a big scope.

Some things we do to make our lives easier and doesn't cost $$$.

Enable and pipe all the alerts into a slack channel (+email as well).

Enable log everything to an bucket in another account. alerts on auth failures (to slack + email (some go to pagerduty contact).
We also have some alerts on updates when a cidr is added to a .

Don't use or /#JumpHosts use to run automations on the hosts (package install, service restarts etc) also to get a shell on a box (if needed at all). (you can use with to give granular access).
Using for console access also logs the entire session (including someone doing sudo su - root etc!) into

Use within our . Instances behind an will only accept traffic from the etc.. , willl only accept traffic from instances in the appropriate . (Basically we don't use cidr ingress rules, we use security group ids) (this works across accounts in the same region with peering, but not across regions however).

#guardduty #cloudtrail #s3 #cloudwatch #infosec #securitygroup #ssh #bastion #ssm #transitivetags #roleassumption #microsegmentation #vpc #alb #rds #elasticache #aws

Last updated 2 years ago

Paco Hope #BLM · @paco
299 followers · 592 posts · Server infosec.exchange

I started visualising my events on using . I blogged about it and put the code on Github.
Blog post: blog.paco.to/2019/cloudtrail-t
GitHub: github.com/pacohope/cloudtrail

#cloudtrail #aws #elasticsearch

Last updated 6 years ago

Paco Hope #BLM · @paco
299 followers · 592 posts · Server infosec.exchange

I have to admit, once I got and running in my account, I just had to Log All The Things. Got some great ability to analyse out of it.

#kibana #elk #aws #cloudtrail

Last updated 6 years ago