#amazon-guardduty #threat-detection #cloud-security #security-identity #incident-response
#amazon-guardduty #threat-detection #cloud-security #security-identity #incident-response
Why Your AWS GuardDuty Data Isn't Showing Up in Microsoft Sentinel (And How to Fix It)
#aws #devsecops #guardduty
Why Your AWS GuardDuty Data Isn't Showing Up in Microsoft Sentinel (And How to Fix It)
#aws #devsecops #guardduty
– CloudTrail logs
– VPC Flow Logs
– GuardDuty findings
– IAM changes
– S3 access logs
Preserve first. Analyze second. Never rush containment blindly.
– CloudTrail logs
– VPC Flow Logs
– GuardDuty findings
– IAM changes
– S3 access logs
Preserve first. Analyze second. Never rush containment blindly.
Amazon's AWS GuardDuty security team is warning of an ongoing crypto-mining campaign that targets its Elastic Compute Cloud (EC2) and Elastic Container Service (ECS) using compromised credentials for Identity and Acce…
#hackernews #news
Amazon's AWS GuardDuty security team is warning of an ongoing crypto-mining campaign that targets its Elastic Compute Cloud (EC2) and Elastic Container Service (ECS) using compromised credentials for Identity and Acce…
#hackernews #news
Amazon GuardDuty and our automated security monitoring systems identified an ongoing cryptocurrency (crypto) mining campaign beginning on November 2, 2025. The operation uses compromised AWS Identity and Access Management …
#hackernews #news
Amazon GuardDuty and our automated security monitoring systems identified an ongoing cryptocurrency (crypto) mining campaign beginning on November 2, 2025. The operation uses compromised AWS Identity and Access Management …
#hackernews #news
AmazonのAWS GuardDutyセキュリティチームは、Identity and Access Management(IAM)の侵害された認証情報を用いてElastic Compute Cloud(EC2)およびElastic Container Service(ECS)を標的にする、進行中の暗号資産マイニング(クリプトマイニング)キャンペーンについて警告しています。 この活動は11月2日に開始され、マイニング活動を長期化させ、インシデント対応者の対応を妨げる永続化メカニズムが用いられていました。…
AmazonのAWS GuardDutyセキュリティチームは、Identity and Access Management(IAM)の侵害された認証情報を用いてElastic Compute Cloud(EC2)およびElastic Container Service(ECS)を標的にする、進行中の暗号資産マイニング(クリプトマイニング)キャンペーンについて警告しています。 この活動は11月2日に開始され、マイニング活動を長期化させ、インシデント対応者の対応を妨げる永続化メカニズムが用いられていました。…
– Privilege escalation attempts
– IAM policy changes
– Public S3 bucket changes
– Security group changes
– Unauthorized API calls
– KMS key misuse
– GuardDuty high-severity alerts
If you monitor these, you’re ahead of 90% of teams.
– Privilege escalation attempts
– IAM policy changes
– Public S3 bucket changes
– Security group changes
– Unauthorized API calls
– KMS key misuse
– GuardDuty high-severity alerts
If you monitor these, you’re ahead of 90% of teams.
GuardDuty 报警称,一项利用被盗 IAM 凭证的多阶段 AWS 攻击正在 ECS 和 EC2 上快速部署矿工,并包含检测、遏制和防护的步骤。
GuardDuty 报警称,一项利用被盗 IAM 凭证的多阶段 AWS 攻击正在 ECS 和 EC2 上快速部署矿工,并包含检测、遏制和防护的步骤。
GuardDuty flags a multi-stage AWS attack using stolen IAM credentials to rapidly deploy crypto miners on ECS and EC2, with steps for detection, containment, and prevention.
GuardDuty flags a multi-stage AWS attack using stolen IAM credentials to rapidly deploy crypto miners on ECS and EC2, with steps for detection, containment, and prevention.
GuardDutyの通知を仕分けたい。特にサンプル大量通知問題をなんとかしたい。
https://www.m3tech.blog/entry/2025/12/07/090000
GuardDutyの通知を仕分けたい。特にサンプル大量通知問題をなんとかしたい。
https://www.m3tech.blog/entry/2025/12/07/090000
I am not a crackpot.
I am not a crackpot.
#AmazonGuardDuty #ExtendedThreatDetection #AWSSecurity #CloudSecurity #ECSAndEC2
ift.tt/Y0adPB3
#AmazonGuardDuty #ExtendedThreatDetection #AWSSecurity #CloudSecurity #ECSAndEC2
ift.tt/Y0adPB3
Amazon Web Services (AWS) this week made an AWS Security Hub for analyzing cybersecurity data in near real time generally available, while at the same time extending the GuardDuty threat detection capabilities it pro…
#hackernews #news
Amazon Web Services (AWS) this week made an AWS Security Hub for analyzing cybersecurity data in near real time generally available, while at the same time extending the GuardDuty threat detection capabilities it pro…
#hackernews #news