๐ฟ ๐๐ข๐ฃ๐๐๐ค๐ข๐ง๐ ๐๐ฆ๐๐ณ๐จ๐ง ๐๐ฏ๐๐ง๐ญ๐๐ซ๐ข๐๐ ๐ ๐๐จ๐ซ ๐ฅ๐๐ฎ๐ง๐๐ก๐ข๐ง๐ ๐๐ซ๐จ๐ฌ๐ฌ-๐๐๐๐จ๐ฎ๐ง๐ญ ๐๐ญ๐ญ๐๐๐ค๐ฌ
Square's Ramesh Ramani describes six attack patterns leveraging EventBridge's cross-account capabilities for infiltration and exfiltration.
AWS EventBridge is a serverless event bus service that enables powerful integrations across multiple AWS accounts.
The attacks:
1. Persistent beaconing
2. Command and control
3. Reconnaissance
4. Data smuggling
5. Account hopping
6. API borrowing
The post provides code examples for each attack and recommends multi-layered security controls, including Service Control Policies, IAM permissions, EventBridge resource policies, VPC endpoints with restrictive policies, and event content validation, along with detection strategies using CloudWatch, CloudTrail, and behavioral analytics.
developer.squareup.com/blog/โฆ
#cybersecurity