Tom Servo · @angelus_04
1592 followers · 75483 posts · Server mastodon.gamedev.place
Tom Servo · @angelus_04
1547 followers · 71680 posts · Server mastodon.gamedev.place
Tom Servo · @angelus_04
1537 followers · 70113 posts · Server mastodon.gamedev.place
Tom Servo · @angelus_04
1510 followers · 66935 posts · Server mastodon.gamedev.place
Maksim Aniskov · @maksim
7 followers · 60 posts · Server fedi.aniskov.com

GuardDuty supports Lambda
aws.amazon.com/about-aws/whats
Amazon GuardDuty expands threat detection coverage to continuously monitor network activity logs, starting with VPC Flow Logs, generated from the execution of AWS Lambda functions to detect threats to Lambda such as functions maliciously repurposed for unauthorized cryptocurrency mining, or compromised Lambda functions that are communicating with known threat actor servers.

#aws #guardduty #lambda #awslambda

Last updated 1 year ago

CFN Updates · @cfnupdates
65 followers · 104 posts · Server awscommunity.social

Updated AWS::GuardDuty::Detector

Use Features property to configure a GuardDuty feature. For more information about features, see Feature activation in GuardDuty.
docs.aws.amazon.com/AWSCloudFo

#guardduty #Cloudformation

Last updated 1 year ago

Christos Matskas ✅ · @christosmatskas
604 followers · 420 posts · Server hachyderm.io

Amazon GuardDuty RDS Protection for Amazon Aurora is now generally available aws.amazon.com/about-aws/whats @awscloud

#aws #cloud #security #guardduty

Last updated 1 year ago

Nicolas Ward · @ultranurd
488 followers · 2139 posts · Server tacobelllabs.net
Nicolas Ward · @ultranurd
487 followers · 2134 posts · Server tacobelllabs.net
Maksim Aniskov · @maksim
3 followers · 21 posts · Server fedi.aniskov.com
Mika Rautio · @mrautio
18 followers · 28 posts · Server infosec.exchange

AWS GuardDuty will have RDS protection to provide intrusion detection system coverage in AWS’ PaaS databases. Quite nice for PCI DSS compliance and such.

aws.amazon.com/about-aws/whats

#aws #guardduty #pcidss

Last updated 2 years ago

Container runtime threat detection now in . announcements

#guardduty #reInvent #keynote

Last updated 2 years ago

Lorna Simes · @lornasimes
45 followers · 123 posts · Server mastodon.scot

201 winners for Owners Group and my 19th win as an owner!
Well done, Guard Duty. I love this horse!

RT @ownersgroupuk@twitter.com

What a start for Guard Duty! It’s an ownersgroup.co.uk double on the day @Southwell_Races@twitter.com - this time for @ELavelleracing@twitter.com and jockey Jack Wildman. Congratulations to all 👏🏻 🏆

🐦🔗: twitter.com/ownersgroupuk/stat

#ownersgroup #guardduty

Last updated 2 years ago

Ståle Pettersen · @kozmic
129 followers · 5 posts · Server infosec.exchange

New region 'ap-south-2' launched by AWS a week ago, but there are no GuardDuty support for this region :( Meaning attackers can do whatever they want in this region without being detected by GuardDuty :facepalm-emoji:

(yes, ideally you should restrict regions with AWS SCPs)

-south-2

#aws #guardduty #ap #cloud #security

Last updated 2 years ago

Andy 'Bob' Brockhurst · @b3cft
62 followers · 90 posts · Server infosec.exchange

@dob
We have -> -> ->

The lambda decodes the and sends to slack. We add a priority ( adding !here or !channel etc) based on the Guard Duty levels. I think we filter a couple out. We have the option to send to a email as well.

We're a pretty small(ish) startup so we don't have a SOC etc, just a couple of people hanging out in slack :sadglasses:

#guardduty #sns #sqs #lambda #pagerduty

Last updated 2 years ago

Andy 'Bob' Brockhurst · @b3cft
62 followers · 90 posts · Server infosec.exchange

@dob That's a big scope.

Some things we do to make our lives easier and doesn't cost $$$.

Enable and pipe all the alerts into a slack channel (+email as well).

Enable log everything to an bucket in another account. alerts on auth failures (to slack + email (some go to pagerduty contact).
We also have some alerts on updates when a cidr is added to a .

Don't use or /#JumpHosts use to run automations on the hosts (package install, service restarts etc) also to get a shell on a box (if needed at all). (you can use with to give granular access).
Using for console access also logs the entire session (including someone doing sudo su - root etc!) into

Use within our . Instances behind an will only accept traffic from the etc.. , willl only accept traffic from instances in the appropriate . (Basically we don't use cidr ingress rules, we use security group ids) (this works across accounts in the same region with peering, but not across regions however).

#guardduty #cloudtrail #s3 #cloudwatch #infosec #securitygroup #ssh #bastion #ssm #transitivetags #roleassumption #microsegmentation #vpc #alb #rds #elasticache #aws

Last updated 2 years ago

Gonçalo Valério · @dethos
295 followers · 1159 posts · Server s.ovalerio.net