Advertisement

AWS Log Forensics & Incident Response

Mar. 6, 2023
Advertisement

More Related Content

Similar to AWS Log Forensics & Incident Response(20)

Advertisement

AWS Log Forensics & Incident Response

  1. AWS Log Forensics & Incident Response Cado Security | 1
  2. What is Cloud Trail? https://docs.aws.amazon.com/IAM/latest/UserGuide/security-logging-and-monitoring.html AWS CloudTrail captures all API calls for IAM and AWS STS as events, including calls from the console and API calls.
  3. https://www.chrisfarris.com/talks/SEC339-Final-Deck.pdf What is CloudTrail?
  4. What is CloudWatch? https://docs.aws.amazon.com/IAM/latest/UserGuide/security-logging-and-monitoring.html Amazon CloudWatch monitors your AWS resources and the applications that you run on AWS in real time. You can collect and track metrics, create customized dashboards, and set alarms that notify you or take actions when a specified metric reaches a threshold that you specify. For example, you can have CloudWatch track CPU usage or other metrics of your Amazon EC2 instances and automatically launch new instances when needed. Amazon CloudWatch Logs helps you monitor, store, and access your log files from Amazon EC2 instances, CloudTrail, and other sources. CloudWatch Logs can monitor information in the log files and notify you when certain thresholds are met. You can also archive your log data in highly durable storage.
  5. CloudWatch vs CloudTrail? CloudWatch CloudTrail Performance Monitoring Auditing Log events across AWS Services - operations Log API activity across AWS Services - Activities Higher Level Monitoring Lower Level Granular Data
  6. Why are there So Many Logs? Great Resource “AWS Logging Types” - https://bit.ly/3XidVm3 Cloud Watch: API Gateway Access Logs AppSync Debug Logs Chime SIP Message Logs CloudHSM Audit Logs Connect Contact Flow Logs DataSync Task Logging DirectoryService AWS Managed Microsoft AD Logs DMS Migration Logs DocDB Profiler Logs EC2 Instance Logs EKS Control Plane Logs ElasticBeanstalk Instance Logs FirehoseDelivery Error Logs Greengrass Debug Logs Imagebuilder Build Logs Kendra Data Source Logs Kinesis Data Analytics Task, Application, and Operator Logs Lambda Application Logs Lex Conversation Logs Lightsail All MQ ActiveMQ and RabbitMQ Logs OpsWorks Instance Logs RDS Database Logs Route53 Query Logs SageMaker Jupyter Job Logs SNS SMS Status Logs StepFunctions Workflow Logs WorkMail Email Event Logs
  7. So Many Logs, So Little Standards?
  8. What AWS Log Analysis is in Cado?
  9. How do you analyze AWS Logs in Cado?
  10. Cado Response Free 14-day trial Receive unlimited access to the Cado Response Platform for 14 days. www.cadosecurity.com/free-investigation/
Advertisement