Learn the ins and outs of the uniqueness of performing incident response in the AWS environment. We will be covering performing IR with native AWS services and technologies such as GuardDuty, Security Hub, Detective, Macie, Inspector, and a selection of open-source tools. We will also cover forensics preservation and cloud evidence management techniques.
At the end of this course, students will be able to:
* Demonstrate knowledge of AWS evidence sources.
* Preserve evidence in the AWS environment.
* Use Amazon AWS tools to detect threat actor TTPs.
* Perform analysis of AWS network logs using 3rd party tools.
* Demonstrate techniques to locate threat actors in an AWS environment.
Recommended Knowledge or Skills Prior to Taking this Course
* INE Cloud Fundamentals
* Incident Response Essentials
* Digital Forensics Essentials