top of page

AWS Forensics: Strategies for Effective Incident Response

Pages Count

9 Pages

Links for the courses

Article

Link

Speaking AWS — The Language Every IR Investigator Needs to Know

CloudTrail — Your Primary Source of Evidence in AWS

Hunting in CloudTrail — Finding the Attack in the Noise

EC2, EBS, and Snapshots — Capturing Cloud Evidence

AWS Networking for IR — VPCs, Flow Logs, and the Load Balancer Blind Spot

S3 Buckets — Evidence Collection and Log Analysis

GuardDuty, CloudTrail Insights, and AWS Detective

Event-Driven DFIR — Automating Your AWS Response

In-Cloud IR — Memory, Containers, and the Metadata Service Attack


Your Instructor

Dean

Dean
bottom of page