AWS Detective
Forensics & Incident
Response
Cado Security | 1
What is AWS Detective?
What are Example Use Cases?
https://pages.awscloud.com/rs/112-TZM-766/images/2020_0122-SID_Slide-Deck.pdf
What are Investigation Playbooks?
https://maturitymodel.security.aws.dev/en/4.-optimized/detective/
How do you Search?
https://aws.amazon.com/blogs/aws/amazon-detective-rapid-security-investigation-and-analysis/
How do you review a Guard Duty Finding?
https://aws.amazon.com/blogs/aws/amazon-detective-rapid-security-investigation-and-analysis/
How do you review Connections?
https://aws.amazon.com/blogs/aws/amazon-detective-rapid-security-investigation-and-analysis/
How do you analyze detailed
VPC Flow Logs?
https://aws.amazon.com/blogs/security/investigate-vpc-flow-with-amazon-detective/
How do you use GeoIP?
https://aws.amazon.com/blogs/aws/amazon-detective-rapid-security-investigation-and-analysis/
Cado Response
Free 14-day trial
Receive unlimited access to
the Cado Response Platform
for 14 days.
www.cadosecurity.com/free-investigation/

AWS Detective Forensics & Incident Response.pdf

  • 1.
    AWS Detective Forensics &Incident Response Cado Security | 1
  • 2.
    What is AWSDetective?
  • 3.
    What are ExampleUse Cases? https://pages.awscloud.com/rs/112-TZM-766/images/2020_0122-SID_Slide-Deck.pdf
  • 4.
    What are InvestigationPlaybooks? https://maturitymodel.security.aws.dev/en/4.-optimized/detective/
  • 5.
    How do youSearch? https://aws.amazon.com/blogs/aws/amazon-detective-rapid-security-investigation-and-analysis/
  • 6.
    How do youreview a Guard Duty Finding? https://aws.amazon.com/blogs/aws/amazon-detective-rapid-security-investigation-and-analysis/
  • 7.
    How do youreview Connections? https://aws.amazon.com/blogs/aws/amazon-detective-rapid-security-investigation-and-analysis/
  • 8.
    How do youanalyze detailed VPC Flow Logs? https://aws.amazon.com/blogs/security/investigate-vpc-flow-with-amazon-detective/
  • 9.
    How do youuse GeoIP? https://aws.amazon.com/blogs/aws/amazon-detective-rapid-security-investigation-and-analysis/
  • 10.
    Cado Response Free 14-daytrial Receive unlimited access to the Cado Response Platform for 14 days. www.cadosecurity.com/free-investigation/