EKS Incident Response and Forensic Analysis

  Рет қаралды 2,467

SANS Digital Forensics and Incident Response

SANS Digital Forensics and Incident Response

Күн бұрын

How does Incident Response differ for EKS? What types of data, logs, and artifacts are involved from both the host as well as the service/control plane (AWS)? How do you effectively collect and analyze data from your EKS environment in AWS to perform a comprehensive investigation and root cause analysis (RCA)? This session will walk you through a variety of specific EKS security scenarios to help you understand what capabilities you need to respond to and analyze possible EKS security incidents, including options for cloud-native tooling to effectively search and analyze service/control plane logs as well as forensic tooling to analyze EKS evidence (disk and memory).
SANS DFIR Summit 2023
Speaker: Jonathon Poling, Principal Consultant -Threat Detection/Incident Response, Amazon Web Services (AWS)
View upcoming Summits: www.sans.org/u/DuS

Пікірлер: 2
@scurvylogs
@scurvylogs 11 ай бұрын
thanks for simplifying EKS forensics in almost 30 minutes. really actionable!
@AutomateTon
@AutomateTon 10 ай бұрын
Definitely making notes from it. Added to my really good IR list. Thanks!
A New Perspective on Resource-Level Cloud Forensics
28:11
SANS Digital Forensics and Incident Response
Рет қаралды 581
Incident Response in the Cloud (AWS) - SANS Digital Forensics & Incident Response Summit 2017
28:02
SANS Digital Forensics and Incident Response
Рет қаралды 20 М.
Секрет фокусника! #shorts
00:15
Роман Magic
Рет қаралды 99 МЛН
Самое неинтересное видео
00:32
Miracle
Рет қаралды 2,5 МЛН
How Strong is Tin Foil? 💪
00:26
Preston
Рет қаралды 61 МЛН
Kubernetes Attack and Defense: Break Out and Escalate!
36:00
SANS Cloud Security
Рет қаралды 1,7 М.
AWS ECS vs EKS vs Fargate
14:21
Cloud With Raj
Рет қаралды 107 М.
Webinar - Advanced Threat Analysis with OpenCTI
39:05
Filigran
Рет қаралды 3,9 М.
SANS Threat Analysis Rundown (STAR)
59:41
SANS Digital Forensics and Incident Response
Рет қаралды 1,3 М.
What I Wish I Knew Before Pentesting AWS Environments
32:57
SANS Offensive Operations
Рет қаралды 4,3 М.
The Five Most Dangerous New Attack Techniques and How to Counter Them
46:51
Attacking and Defending Kubernetes Cluster: Kubesploit vs KubiScan
42:02
Секрет фокусника! #shorts
00:15
Роман Magic
Рет қаралды 99 МЛН