April 2019
Intermediate to advanced
508 pages
11h 57m
English
This section is going to focus on a single GuardDuty finding type: UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration. The AWS documentation describes that this finding will be triggered when credentials that were created exclusively for an EC2 instance through an instance launch role are being used from an external IP address (https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_unauthorized.html#unauthorized11). Basically, when an EC2 instance is launched and an IAM instance profile is attached to it, GuardDuty expects the credentials for that role to only ever be used within that single instance, or at least that's what it makes it sound like, but we'll get into that soon. ...
Read now
Unlock full access