No video

Attack & Detection of a Cloud Security Breach w/

This video covers an attack scenario very similar to how the US Bank Capital One got breached. ‪@0xd4y‬ goes over the attack scenario using CloudGoat by Rhino Security Labs, I detect his activities using AWS CloudTrail Lake.
_____________
🧬 VIDEO RESOURCES
🔹 Segev's KZread Channel: ‪@0xd4y‬
🔹 Segev's walkthrough: • Hacking in the Cloud -...
🔹 Former AWS engineer convicted over hack that cost Capital One $270m: techmonitor.ai...
🔹 CloudGoat: github.com/Rhi...
🔹 Instance Metadata: docs.aws.amazo...
🔹 Sneaky Endpoints: github.com/Fri...
🔹 AWSealion: github.com/0xd...
🔹 GuarDuty Findings: docs.aws.amazo...
🔹 CloudTrail Lake: docs.aws.amazo...
_____________
💼 CAREER RESOURCES
🔹Check out these Cybersecurity Notion Templates for planning your career: daycyberwox.gu...
🔹The Best Entry-Level Cybersecurity Resume Template: daycyberwox.gu...
🔹My Notion Tutorial for Beginners: • Notion Tutorial for Be...
_____________
⏰ TIMESTAMPS
00:00 Intro
00:34 Attack Scenario
00:51 Key Terminology
01:41 Cloud Attack Walkthrough - CloudGoat
10:06 Attack Detection Walkthrough - CloudTrail Lake
13:44 Remediation & Final Thoughts
_____________
⚡️JOIN CYBERWOX ACADEMY ON DISCORD!
/ discord
_____________
📱 LET'S CONNECT
IG: / daycyberwox​
Twitter: / daycyberwox​
Linkedin: / dayspringjohnson
Email: day@cyberwoxacademy.com
_____________
#️⃣ Relevant Hashtags
#cybersecurity #cloudsecurity #cloudcomputing #aws #awscloud

Пікірлер: 20

  • @DayCyberwox
    @DayCyberwox Жыл бұрын

    Thanks to Segev for collaborating with me on this! Would y’all like a full series like this? 🤓

  • @0xd4y

    @0xd4y

    Жыл бұрын

    It was a pleasure making this video with you!

  • @jacobssmall2793

    @jacobssmall2793

    Жыл бұрын

    Yeah, I like the tech news coverage!

  • @jerrymartins6917

    @jerrymartins6917

    Жыл бұрын

    Sure!

  • @tadii
    @tadii Жыл бұрын

    Sat through 14 minutes of technical content without flinching. I would usually having to mentally prepare myself for such👏

  • @DayCyberwox

    @DayCyberwox

    Жыл бұрын

    Glad you liked it!

  • @user-kr4wf7lh7n
    @user-kr4wf7lh7n6 ай бұрын

    So cool!

  • @FreshWillBoy302
    @FreshWillBoy302 Жыл бұрын

    Day has outdone himself again 🏋🏾‍♂️ 📈💯🔥 Shout 0xday too, this is what the community wants 🗣️

  • @DayCyberwox

    @DayCyberwox

    Жыл бұрын

    Glad you like it!

  • @0xd4y

    @0xd4y

    Жыл бұрын

    Thank you!

  • @DedicatedCheapSkater
    @DedicatedCheapSkater Жыл бұрын

    Nice job. Worth noting that most people are not going to have S3 dataevents turned on in Cloudtrail. In other words, seeing the objects calls in the Cloudtrail logs is not on by default.

  • @DayCyberwox

    @DayCyberwox

    Жыл бұрын

    Great point. That just gave me an idea for a video, thanks!

  • @spokentruth5909
    @spokentruth5909 Жыл бұрын

    I started my career at capital one during that breach 😅

  • @DayCyberwox

    @DayCyberwox

    Жыл бұрын

    Wow, that must have been an interesting time 😅

  • @ksriharsha2911
    @ksriharsha2911 Жыл бұрын

    🔥🔥🔥🔥🔥🔥

  • @israelisrael5134
    @israelisrael5134 Жыл бұрын

    I just wrote a paper on this for a virtualization class.

  • @DayCyberwox

    @DayCyberwox

    Жыл бұрын

    Goood stuff!

  • Жыл бұрын

    Discord invite link is expired.

  • @DayCyberwox

    @DayCyberwox

    Жыл бұрын

    Thanks for pointing that out, just fixed it.