Introducing a mind map for AWS investigations

Expel AWS MITRE ATT&CK cheatsheet

Videos · Cole Finch · TAGS: Cloud security

Our SOC team remediates quite a few incidents in Amazon Web Services (AWS). When running these incidents down, some common themes emerged about when and why attackers use different AWS APIs – and they mapped nicely to the MITRE ATT&CK tactics. We decided to captured these AWS APIs in a mind map and loaded it into our Expel Workbench.

Our manager of, well, Engagement Management, Tyler Fornes, briefly discusses why we did it (and why we think you’ll find it useful). Learn more, and grab a link to download your own mind map kit: https://expel.com/mitre-attack-in-aws-toolkit/

Resources home