So this turned into build an environment to run in.
I wrote a script to deploy all the resources with guidance:
Tested and deployed so far:
Org root user and role
Root policies
Root permission boundary
ou
accounts
- iam
- KMS
- dns
- jobs
- work
- backup (archive)
- security (in prod)
- org (in prod)
Multi region support to deploy to specified regions
Admin roles (MFA/IP to assume)
Admin policies
Lambdas
- deploy bucket
- deploy key
- deploy VPC (testing)
- add AWS prefix lists (testing)
Buckets - regional, protected name
KMS keys policies
Upload KMS configurations to S3
Add keys to buckets
Create VPC config file
Upload to bucket
Defined so far:
VPC
How many IPs?
Recommend available CIDR
FlowLogs
Encrypted y/n
Select KMS account
List keys
Choose key
Subnets -public or private
Cidr
FlowLogs
KMS key
Choose AZ
- NAT (optional)
- Select from list of VPC endpoints
Still testing code:
prefix list
- share w/ram
Security Group
Add rule
- Select CIDR/SGID/prefix list for rule
- select from list of prefix lists
- select from list of sgs
- select from list of CIDRs or add new
- upload config to bucket
- lambda deploys VPC components
- deploy auth lambdas
- register
- list jobs
- deploy jobs
- auth Yubikey
- deploy s3 website
- archive account
- deploy job
Yubikey Push To Run A Lambda Function 🔒☁️🤖 Leveraging a framework to kick off deterministic or AI agent batch jobs and workflows
teriradichel.substack.com/p/…
Just to ensure we are on the same page, is this the example you are referring to (msft.it/6016U7LCY)? Are you looking for similar FlowLogs table by table list? ^TC
Discover the hidden potential of flow logs to replace outdated DPI systems & enhance security across your multi-cloud network. @Mroesch explains how Netography aggregates & enriches #flowlogs for real-time threat detection in his latest blog post: okt.to/f1CEar
VPC FlowlogsのCustom format で ECS 情報を出力できるようになってからのこのアプデ👏 / Amazon OpenSearch Service zero-ETL integration with Amazon S3 now available - AWS aws.amazon.com/about-aws/wha…
Our latest blog post provides an introduction to #AWS detection engineering. We present the main log sources #CloudTrail#FlowLogs#GuardDuty for AWS, as well as some relevant events that defenders could use to detect attackers
blog.sekoia.io/aws-detection…
"Pipes" library is behind Grafana Beyla and RedHat's Network Observability agent and Flowlogs-Pipeline projects.
It's a convenient library to create flexible data extraction-processing-exporting pipelines, written and maintained for you with all my love.
github.com/mariomac/pipes/tr…
Curious to know if anyone uses SiLK in a cloud environment? I saw one vendor sells a translation of VPC flow logs to standard FlowLogs so you can use it but anyone using that or doing their own conversion?