Logging, Monitoring, and Alerting in AWS (The TL;DR) - SANS DFIR Summit 2018

With AWS’ ever-increasing number services and ever-growing complexity, individuals and organizations are desperately seeking the “TL;DR” of what services are available to protect them from and respond to attacks, and how to best configure them for effective and efficient monitoring, alerting, and incident response. The first part of this presentation will walk the audience through the core services and capabilities that are critical to logging, monitoring, alerting, and responding to threats. The second part will walk the audience through specific monitoring and alerting configurations that the audience can immediately apply to their infrastructure to begin and/or improve their path toward securing their AWS infrastructure. Whether you’re just starting out in AWS or have been using it for years, there is something for everyone to learn or brush up on in ensuring your org is best prepared to monitor for and respond to a compromise. Jonathan Poling (@JPoForenso), Managing Principal Consultant, SecureWork

Incident Response in the Cloud (AWS) - SANS Digital Forensics & Incident Response Summit 2017
▶︎

Incident Response in the Cloud (AWS) - SANS Digital Forensics & Incident Response Summit 2017

Finding and Decoding Malicious Powershell Scripts - SANS DFIR Summit 2018
▶︎

Finding and Decoding Malicious Powershell Scripts - SANS DFIR Summit 2018

AWS re:Inforce 2019: Threat Detection on AWS: An Introduction to Amazon GuardDuty (FND216)
▶︎

AWS re:Inforce 2019: Threat Detection on AWS: An Introduction to Amazon GuardDuty (FND216)

How to Disappear Online and Become Untraceable
▶︎

How to Disappear Online and Become Untraceable

AWS re:Invent 2022 - Threat detection and incident response using cloud-native services (SEC309)
▶︎

AWS re:Invent 2022 - Threat detection and incident response using cloud-native services (SEC309)

ShimCache and AmCache enterprise-wide hunting - SANS Threat Hunting Summit 2017
▶︎

ShimCache and AmCache enterprise-wide hunting - SANS Threat Hunting Summit 2017

Attacking AWS: the full cyber kill chain | SANS Cloud & DevOps Security Summit 2020
▶︎

Attacking AWS: the full cyber kill chain | SANS Cloud & DevOps Security Summit 2020

Every Step You Take: Application and Network Usage in Android - SANS DFIR Summit 2018
▶︎

Every Step You Take: Application and Network Usage in Android - SANS DFIR Summit 2018

The Biggest Lies in Cybersecurity
▶︎

The Biggest Lies in Cybersecurity

Trump Gets Booed & Falls Asleep During NBA Finals, Claims War is Almost Over & Goodbye Spencer Pratt
▶︎

Trump Gets Booed & Falls Asleep During NBA Finals, Claims War is Almost Over & Goodbye Spencer Pratt

Threat Intelligence At Microsoft: A Look Inside - Cyber Threat Intelligence Summit 2017
▶︎

Threat Intelligence At Microsoft: A Look Inside - Cyber Threat Intelligence Summit 2017

AWS re:Inforce 2019: The Fundamentals of AWS Cloud Security (FND209-R)
▶︎

AWS re:Inforce 2019: The Fundamentals of AWS Cloud Security (FND209-R)

Hunting on Amazon Web Services (AWS) - SANS Threat Hunting Summit 2017
▶︎

Hunting on Amazon Web Services (AWS) - SANS Threat Hunting Summit 2017

Learn Microsoft Active Directory (ADDS) in 30mins
▶︎

Learn Microsoft Active Directory (ADDS) in 30mins

Mac_apt –The Smarter and Faster Approach to macOS Processing - SANS DFIR Summit 2018
▶︎

Mac_apt –The Smarter and Faster Approach to macOS Processing - SANS DFIR Summit 2018

Something is jamming GPS over Europe. Here's what we found
▶︎

Something is jamming GPS over Europe. Here's what we found

Tracking Threat Actors through YARA Rules and Virus Total - SANS DFIR Summit 2016
▶︎

Tracking Threat Actors through YARA Rules and Virus Total - SANS DFIR Summit 2016

Attacking AI - Jason Haddix - NDC Security 2026
▶︎

Attacking AI - Jason Haddix - NDC Security 2026

Cloud Security Monitoring and Threat Detection in AWS
▶︎

Cloud Security Monitoring and Threat Detection in AWS

Open-Source DFIR Made Easy: The Setup  - SANS Digital Forensics & Incident Response Summit 2017
▶︎

Open-Source DFIR Made Easy: The Setup - SANS Digital Forensics & Incident Response Summit 2017