Intro to forensics in the cloud: A container was compromised. What’s next?
ID: 0bc4ca3d-c010-5ef1-a688-b08e0e7afb08
STIX ID: report--0bc4ca3d-c010-5ef1-a688-b08e0e7afb08
Feed Name: Wiz Blog
This report is a cloud-forensics primer that walks through a simulated breach where weak WordPress credentials and an uploaded web shell led to a reverse shell, container escape via a privileged pod and docker.sock, creation of a privileged backdoor container for persistence, lateral movement to a data-fetcher pod, and exfiltration of sensitive S3 data. It emphasizes preparation and comprehensive logging (cloud provider audit logs, VPC flow logs, Kubernetes audit logs, workload snapshots, and runtime events) and illustrates investigation steps and prevention lessons.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
