Behavior
Bypassing the GuardDuty Behavior checks can also be rather simple.
To bypass the Behavior:EC2/NetworkPortUnusual finding, which triggers when an EC2 instance is communicating with a remote host on an unusual port, we will just need to ensure that any malware command and control we are doing is using a common port, such as 80 (HTTP) or 443 (HTTPS), rather than some random high-numbered port.
The Behavior:EC2/TrafficVolumeUnusual GuardDuty finding triggers when there is an unusually large amount of network traffic being sent to a remote host. As a defender, this could be an indication of data exfiltration from within your internal network. As an attacker, we could bypass this finding when exfiltrating data by limiting our outbound ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access