Category: Uncategorized

    • Intelligent Threat Detection service.
    • Detects malicious activity in your AWS account.
      • Examples include: cryptomining, data exfil, compromised AWS credentials or account
    • Uses AI, machine learning, anomaly detection, malicious file discovery.
    • One-click to enable.
    • Analyses data sources:
      • Examples:
        • CloudTrail Management Events – anomalous API calls, unauthorised deployments
        • VPC Flow Logs – anomalous traffic, strange IP addresses
        • Route 53 DNS Query Logs – compromised EC2 instances sending encoded data within DNS queries
    • Includes Extended Threat Protection.
      • Detects multi-stage attacks spanning multiple data sources and EC2 instances
    • GuardDuty Protection Plans:
      • Malware Protection for EC2 – scans EBS volumes to detect malware
      • EKS Protection – monitors Kubernetes audit logs from EKS clusters for suspicious activities
      • Runtime Monitoring – monitors OS-level events on EC2, ECS, EKS for threats
      • Lambda Protection – analyses Lambda network activity logs using VPC Flow Logs to detect threats such as cryptomining or communications with known malicious servers
      • S3 Protection – identifies security risks in S3 buckets such as data exfil
      • Malware Protection for S3 – identifies malware in S3 buckets
      • Malware Protection for AWS Backup – scans Backup resources (ex. EBS Snapshots, AMIs) for malware
      • RDS Protection – analyses RDS and Aurora login activity for threats
    • GuardDuty Findings
      • Findings are generated by GuardDuty from data streams (ex. CloudTrail logs, VPC Flow Logs). Findings severity ranges from 0.1 -> 8+.
      • Example:
        • ThreatPurpose:ResourceTypeAffected/ThreatFamilyName.DetectionMechanism!Artifact
        • ThreatPurpose – purpose of threat (ex. cryptomining, backdoor)
        • ResourceTypeAffected – which AWS resource is targeted (ex. EC2, S3)
        • ThreatFamilyName – describes potential malicious activity (ex. NetworkPortUnusual)
        • DetectionMechanism – method GuardDuty used to detect finding (ex. TCP, UDP)
        • Artifact – describes resources used in malicious activity (ex. DNS)
      • You can use EventBridge to automate responses to security findings. SNS (Simple Notification Service) to send emails or Slack alerts.

    More reading:

    ,
  • I had my first exposure to cybersecurity 14 years ago – when I first saw the Watch Dogs trailer at E3 2012.

    I remember this was the first game that truly excited me, but I wasn’t sure exactly what it was that stood out to me. It may have been the idea of controlling an entire city from your phone which I had never seen as a feature in any other mainstream game. Remotely controlling vehicles, hacking lights, and causing traffic pile-ups by hacking traffic lights was an incredibly exciting concept and something that ended up becoming a reality written about just a few years later.

    As I got older, I played through the remaining Watch Dogs games in the series (including Legion – although I like to pretend that one didn’t exist) and came to enjoy them thoroughly.

    Once I turned 18 and my time at sixth form was coming to an end, I was faced with a few options: university or the world of work. I was never going to go into work right out of sixth form, and so university was going to be my next step. Had a different avenue not become available, I would have gone on to study Computer Science at Northumbria University.

    Three months before the end of sixth form, an opportunity in the form of a degree apprenticeship appeared at one of the UK’s top banks, offering a Level 6 degree in Digital & Technology Solutions (also known as a DTS degree). I had to go for it.

    I went through a few stages of interviews and eventually I got the job. I spent some time in a role completely different to cybersecurity as the members of our apprentice cohort were assigned roles and teams at random, but after a one-year long placement at the team I was originally in, I asked my manager if I could try a new team – the software engineering team.

    When the placement opportunity with the software development team fell through, the door to joining the cybersecurity team was opened up for me and I’m grateful that it did. I’ve now spent over 2 years in the cybersecurity field and I’ve learned so much.

    I’m hoping I’ll get to share more of that here on my blog.

    Thanks for reading.

    -J