How to build a useful (and entertaining) threat emulation exercise for AWS
ID: 97c6b04f-e950-59ad-aa08-1283c115cef8
STIX ID: report--97c6b04f-e950-59ad-aa08-1283c115cef8
Feed Name: Expel Blog
**Executive summary:** This article provides a step-by-step guide to building and running AWS threat emulation exercises to train SOC analysts, covering goals and scope, building realistic AWS infrastructure and benign user activity, crafting a plausible attack (compromised credentials, EC2 metadata role credential retrieval, Secrets Manager access, RDS data dump and exfiltration), executing the simulation, guiding investigators, and capturing lessons learned to improve detections and playbooks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
