Talk

Battle in the Clouds: Attacker vs Defender on AWS

conf 2019-11-08 14:00 – 14:50 TR1 EN

Battle in the Clouds: Attacker vs Defender on AWS

The interaction between attackers and defenders is like a ping pong game, and that is exactly how we did this research. On the offensive, Mo will share his tools and tactics attacking AWS Infrastructures from Recon to Attacks to Post Exploitation on different services with a focus on Elastic Container Service(ECS). After each attack step, Dani will explain the defensive side and tools and tactics for hardening the AWS Infrastructure from Designing a secure Cloud Architecture to Detection to Hardening specific services like Docker containers on ECS.

One of the most important lessons from our research is the importance of the interaction between pentesters and developers/DevOps engineers, and how a few days of working side by side can help us secure our current systems and learn to develop future systems with security in mind.