Joined April 2014
Photos and videos
Ramesh.8901 retweeted
๐Ÿ‘ฟ ๐‡๐ข๐ฃ๐š๐œ๐ค๐ข๐ง๐  ๐€๐ฆ๐š๐ณ๐จ๐ง ๐„๐ฏ๐ž๐ง๐ญ๐๐ซ๐ข๐๐ ๐ž ๐Ÿ๐จ๐ซ ๐ฅ๐š๐ฎ๐ง๐œ๐ก๐ข๐ง๐  ๐‚๐ซ๐จ๐ฌ๐ฌ-๐€๐œ๐œ๐จ๐ฎ๐ง๐ญ ๐š๐ญ๐ญ๐š๐œ๐ค๐ฌ Square's Ramesh Ramani describes six attack patterns leveraging EventBridge's cross-account capabilities for infiltration and exfiltration. AWS EventBridge is a serverless event bus service that enables powerful integrations across multiple AWS accounts. The attacks: 1. Persistent beaconing 2. Command and control 3. Reconnaissance 4. Data smuggling 5. Account hopping 6. API borrowing The post provides code examples for each attack and recommends multi-layered security controls, including Service Control Policies, IAM permissions, EventBridge resource policies, VPC endpoints with restrictive policies, and event content validation, along with detection strategies using CloudWatch, CloudTrail, and behavioral analytics. developer.squareup.com/blog/โ€ฆ #cybersecurity
9
30
1,814
Ramesh.8901 retweeted
๐Ÿ›Ž๏ธ AWS Security Digest 216 is out! 1๏ธโƒฃ AWS Account ID Enumeration Through Root User MFA by Michael Magyar 2๏ธโƒฃ Hijacking Amazon EventBridge for launching Cross-Account attacks by Ramesh Ramani 3๏ธโƒฃ Sign in with your eID: Using AWS IAM Roles Anywhere with a SmartCard Reader by Ben Bridts 4๏ธโƒฃ The Future of Threat Emulation: Building AI Agents that Hunt Like Cloud Adversaries by Eduard Agavriloae 5๏ธโƒฃ Profiling TradeTraitor: Tactics, History & Defenses Bonus: Stealthy Persistence in AWS - A Practical Simulation for Defenders awssecuritydigest.com/past-iโ€ฆ

4
7
1,385
Ramesh.8901 retweeted
๐Ÿ”Ž Threat Hunting with #Kubernetes Audit Logs by @square Using ATT&CK for Containers * Execution: Finding repeated exec failures * Persistence: Unusual cronjob creation failures * PrivEsc: Users being given "cluster-admin" access * more developer.squareup.com/blog/โ€ฆ
6
16
Ramesh.8901 retweeted
The promised part 2๏ธโƒฃ of Threat Hunting with Kubernetes Audit Logs is here! @8901Ramesh explains how to use the @MITREattack Framework to hunt for attackers in your @kubernetesio audit logs ๐ŸŽฏ #CNCF #Kubernetes developer.squareup.com/blog/โ€ฆ
7
8