home.social

#for509 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #for509, aggregated by home.social.

  1. #Ransomware threat actors are increasingly abusing AWS's Server-Side Encryption (SSE-C) to encrypt S3 buckets without needing to drop malware. Most recently a TA known as #Codefinger is using this technique.

    🕵 Make sure you're monitoring S3 and encryption activity via CloudTrail & GuardDuty.

    halcyon.ai/blog/abusing-aws-na

    #CloudForensics #FOR509 #AWS

  2. :blobcheer:

    Yay, passed my #SANS #FOR509 #GIAC Cloud Forensic Responder (GCFR).

    I'd definitely recommend the course if one is interested in cloud and incident response (but finish the "basic" FOR508 before this course).

  3. Congratulations to our #FOR509 Day 6 Capstone winners in #Singapore last week.
    It was one of the closest challenges between the competing teams I've seen.

    #CloudForensics
    #DFIR @sansapac

  4. One of my brilliant coauthors Megan Roddie did a write up from our SANS #FOR509 #CloudForensics class on how to extract #AWS logs for analysis.

    #DFIR #CSIRT #CERT
    sans.org/blog/aws-cloud-log-ex