Overview
Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Explore the mysterious world of cloud security investigations through Amazon Detective, AWS's powerful threat investigation service, in this one-hour webinar that teaches you to uncover the "ghosts" in your infrastructure—those unexplained anomalies, phantom access patterns, and zombie processes that haunt your AWS environment. Master the core capabilities and investigative methodology of Amazon Detective, learning how it ingests and correlates security data from multiple AWS sources to create a comprehensive security graph. Navigate Detective's console interface, interpret entity-based timelines, and use the service's visualizations to understand the scope and timeline of potential security incidents. Develop practical investigation skills by learning how to respond to common security scenarios using Amazon Detective's tools and methodologies, including investigating GuardDuty findings by examining the full context of suspicious activities, user behavior baselines, resource access patterns, and network traffic anomalies. Ideal for cloud security professionals, security operations center (SOC) analysts, and incident responders who need to investigate suspicious activities in AWS environments, this session is perfect for those who understand fundamental AWS services and have basic security knowledge but want to enhance their cloud forensics and investigation capabilities through specialized tooling.
Syllabus
Haunted Infrastructure - An Amazon Detective Investigation
Taught by
AWS Events