WS3 - AWS Principal Threat Hunting: Behavioral Baselining for Malicious Activity
Description
Instructed by: Rodrigo “Sp0oKeR” Montoro
Level of Difficulty: Intermediate, Advanced
Abstract:
Cloud security encounters attacks that elude standard detection. In AWS, unauthorized access keys are a common cause of breaches. The vastness of AWS—over 450 services and 20,000 API actions - complicates threat visibility and exposes gaps in traditional tools.
This workshop empowers participants with direct, hands-on experience using the AWS Threat Hunter tool to improve threat detection. Attendees will focus on building behavioral baselines and leveraging data-driven analysis to detect subtle AWS principal anomalies, enabling more precise detection than traditional event monitoring.
Attendees will move beyond standard techniques by building multi-stage detection pipelines that create individualized baselines for each IAM principal and systematically flag personalized deviations, linking outliers directly to risks.
Pre-Requisites:
Participants should understand AWS IAM (managing user permissions and access policies) and be able to review CloudTrail logs (lists of AWS activity). Experience with Jupyter Notebooks (a data analysis tool) and basic Python knowledge are recommended but not mandatory. If you are unsure, make sure you are comfortable reviewing AWS IAM permissions and CloudTrail logs on your own, as these skills are necessary for exercises.
Tickets for good, not greed Humanitix dedicates 100% of profits from booking fees to charity


