SecureShop Pvt Ltd required a cloud-native threat detection solution to identify and investigate suspicious activity within its AWS environment.
This project demonstrates the implementation of AWS GuardDuty for continuous threat monitoring and incident investigation.
- Enable AWS GuardDuty
- Generate and analyze sample security findings
- Investigate critical security alerts
- Perform incident response analysis
- Document remediation recommendations
- AWS GuardDuty
- AWS IAM
- AWS CloudTrail
AttackSequence:IAM/CompromisedCredentials
GuardDuty detected a potential compromise of IAM user credentials.
Indicators included:
- Connection from a Tor Exit Node
- CloudTrail deletion attempt
- IAM role creation
- IAM policy attachment
- IAM user enumeration activity
Severity: Critical
Potential Impact:
- Privilege Escalation
- Persistence
- Defense Evasion
- Unauthorized Access
- Reviewed GuardDuty findings
- Analyzed attack sequence signals
- Identified suspicious API activity
- Assessed potential impact
- Recommended remediation actions
- Disable compromised credentials
- Rotate access keys
- Enable MFA
- Review IAM permissions
- Audit CloudTrail activity
- Monitor future GuardDuty findings
- | Finding | Severity | Status | |---|---|---| | AttackSequence:IAM/CompromisedCredentials | CRITICAL | Investigated | | UnauthorizedAccess:IAMUser/TorIPCaller | HIGH | Documented |
Project screenshots are included in this repository.
- Cloud Security Monitoring
- Threat Detection
- Incident Response
- AWS Security Services
- Security Analysis
- IAM Security
Siri Chandana Aspiring Cloud Security Engineer