#guardduty — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #guardduty, aggregated by home.social.
-
https://www.linkedin.com/pulse/aws-guardduty-malware-protection-s3-why-falls-short-av-hite-cissp-yytde - #AWS #GuardDuty for #S3 falls short. Nice collection of findings https://www.linkedin.com/in/michael-hite.
-
How to use AWS Transfer Family and #GuardDuty for Malware Protection https://aws.amazon.com/blogs/security/how-to-use-aws-transfer-family-and-guardduty-for-malware-protection/
-
New AWS::GuardDuty::PublishingDestination
Use AWS::GuardDuty::PublishingDestination resource to create a publishing destination where you can export your GuardDuty findings.
https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-guardduty-publishingdestination.html #guardduty #cloudformation -
Security Incident Response Service launched by AWS to help customers monitor and manage security events
https://www.admin-magazine.com/News/AWS-Announces-Security-Incident-Response-Service
#security #monitoring #AWS #automate #response #communication #storage #GuardDuty -
New AWS::GuardDuty::MalwareProtectionPlan
Use AWS::GuardDuty::MalwareProtectionPlan resource to configure Malware Protection for S3 that helps you detect potential malware in the newly uploaded objects in your selected S3 buckets.
https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-guardduty-malwareprotectionplan.html #guardduty #cloudformation -
CW: Work Marketing
The #GuardDuty test suite has been updated by our security engineers to trigger many more finding types. https://github.com/awslabs/amazon-guardduty-tester #aws #cybersecurity
-
CW: Work launch
Big new #GuardDuty feature: Runtime Monitoring is now available for #ECS on EC2 and #Fargate! This is a major expansion of the EKS support we launched earlier this year. #AWS #reinvent2023 #cybersecurity https://aws.amazon.com/blogs/aws/introducing-amazon-guardduty-ecs-runtime-monitoring-including-aws-fargate/
-
A product enhancement arriving during re:Invent Advent: Amazon #GuardDuty improved ML-based detections for #EKS Audit Logs https://aws.amazon.com/about-aws/whats-new/2023/11/amazon-guardduty-machine-learning-capability-threat-detection-eks-detections/
-
CW: Work plug
Nice blog post on monitoring our #GuardDuty #EKS Agent https://aws.amazon.com/blogs/containers/measure-cluster-performance-impact-of-amazon-guardduty-eks-agent/ #aws
-
Updated AWS::GuardDuty::Detector
Use Features property to configure a GuardDuty feature. For more information about features, see Feature activation in GuardDuty.
https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-guardduty-detector.html #guardduty #cloudformation -
Amazon GuardDuty RDS Protection for Amazon Aurora is now generally available https://aws.amazon.com/about-aws/whats-new/2023/03/amazon-guardduty-rds-protection-aurora-generally-available/ @awscloud #aws #cloud #security #guardDuty
-
Exciting launch from my team: #GuardDuty #RDS Protection is now GA https://aws.amazon.com/about-aws/whats-new/2023/03/amazon-guardduty-rds-protection-aurora-generally-available/ #aws #cybersecurity
-
@dob That's a big scope.
Some things we do to make our lives easier and doesn't cost $$$.
Enable #guardduty and pipe all the alerts into a slack channel (+email as well).
Enable #cloudtrail log everything to an #S3 bucket in another account. #cloudwatch alerts on auth failures (to slack + email (some go to pagerduty #infosec contact).
We also have some alerts on updates when a cidr is added to a #SecurityGroup.Don't use #ssh or #bastion/#JumpHosts use #ssm to run automations on the hosts (package install, service restarts etc) also to get a shell on a box (if needed at all). (you can use #TransitiveTags with #RoleAssumption to give granular access).
Using #ssm for console access also logs the entire session (including someone doingsudo su - rootetc!) into #S3Use #MicroSegmentation within our #vpc. Instances behind an #alb will only accept traffic from the #alb #SecurityGroup etc.. #rds, #elasticache willl only accept traffic from instances in the appropriate #SecurityGroup. (Basically we don't use cidr ingress rules, we use security group ids) (this works across accounts in the same region with peering, but not across regions however).
-
"AWS GuardDuty Exfiltration Bypass with VPC Endpoints"
https://notdodo.medium.com/aws-guardduty-exfiltration-bypass-4720f6ed16a4
-
HIRING: Incident Response & Cloud Security Lead, Security Engineering / Remote, USA - https://infosec-jobs.com/job/5314-incident-response-cloud-security-lead-security-engineering/ #InfoSec #infosecjobs #CyberSecurity #cybersec #CyberCareer #cyberjobs #cybertalents #security #jobsearch #techjobs #AWS #workremotely #GCFA #SIEM #guardduty