Andy 'Bob' Brockhurst · @b3cft
62 followers · 90 posts · Server infosec.exchange

@dob That's a big scope.

Some things we do to make our lives easier and doesn't cost $$$.

Enable and pipe all the alerts into a slack channel (+email as well).

Enable log everything to an bucket in another account. alerts on auth failures (to slack + email (some go to pagerduty contact).
We also have some alerts on updates when a cidr is added to a .

Don't use or /#JumpHosts use to run automations on the hosts (package install, service restarts etc) also to get a shell on a box (if needed at all). (you can use with to give granular access).
Using for console access also logs the entire session (including someone doing sudo su - root etc!) into

Use within our . Instances behind an will only accept traffic from the etc.. , willl only accept traffic from instances in the appropriate . (Basically we don't use cidr ingress rules, we use security group ids) (this works across accounts in the same region with peering, but not across regions however).

#guardduty #cloudtrail #s3 #cloudwatch #infosec #securitygroup #ssh #bastion #ssm #transitivetags #roleassumption #microsegmentation #vpc #alb #rds #elasticache #aws

Last updated 2 years ago