Threat Hunting AWS CloudTrail with Sentinel: Part 1
ID: af4b567d-1a7e-58bd-95ef-c4f9377af2d2
STIX ID: report--af4b567d-1a7e-58bd-95ef-c4f9377af2d2
Feed Name: Binary Defense Blog
This four-part blog introduction explains how to perform threat hunting on AWS CloudTrail data using Microsoft Sentinel. It describes simulated attacks in a test AWS environment (credential theft from misconfigured S3, creation of backdoor IAM keys and new users/groups), maps those simulations to MITRE ATT&CK cloud techniques, and demonstrates using Kusto Query Language (KQL) and Sentinel detections; the post also lists offensive toolkits used (cloud_enum, Pacu, Atomic Red Team) and provides extensive references for further hunting and detection work.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
