Uncovering Hybrid Cloud Attacks Part 3 – The Response
ID: 479ff2af-dd45-5cad-9358-cd600823919e
STIX ID: report--479ff2af-dd45-5cad-9358-cd600823919e
Feed Name: Wiz Blog
### Executive summary This case study describes a sophisticated hybrid attack in which attackers gained and repeatedly reused a privileged AWS IAM account to retrieve instance passwords, install reverse shells on EC2 and a corporate jump server, and exfiltrate sensitive data from RDS and S3; investigators resolved the incident by combining forensic analysis, SIEM/VPC flow logs, and public threat intelligence to identify C2 infrastructure and the initial phishing compromise of an employee home PC.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
