TrailShark: Understanding AWS API and Service Interactions
ID: 390b6a3a-9c4e-57e3-8d6e-259cdb71f512
STIX ID: report--390b6a3a-9c4e-57e3-8d6e-259cdb71f512
Feed Name: Aqua Security Blog
Threat Score
This blog introduces TrailShark, an open-source tool that feeds AWS CloudTrail events into Wireshark for near-real-time analysis and custom event detection; the authors used it during "Bucket Monopoly" research to uncover six AWS vulnerabilities (ranging from RCE and service takeover to data exposure and DoS) and demonstrate how inner API call visibility can reveal hidden resource creation and suspicious behaviors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
