AWS Security Teams Can Correlate CloudTrail, VPC and Route 53 Logs to Detect Attacks

AWS security teams can improve detection of multi-stage intrusions by correlating API activity in CloudTrail with network metadata in VPC Flow Logs and DNS activity in Route 53 Resolver query logs. The approach turns isolated alerts into an attack narrative spanning credential abuse, reconnaissance, privilege escalation, lateral movement and data exfiltration. A suspicious GetCallerIdentity request […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: