Category: Cyber Threat

The AWS Threat Hunting Library — 7 hunts every cloud SOC should run · HackForLab AWS Threat Hunting series hub
0 11
Posted in Cyber Threat

The Complete AWS Threat Hunting Library: 27 Cloud Hunts, 7 Flagship Playbooks, and the Full Archive (2026)

The definitive AWS threat hunting reference — indexing all 27 published AWS hunting posts on hackforlab.com. 7 flagship 2026 hunts (CloudTrail blind spots, KMS ransomware, GuardDuty evasion, CI/CD compromise, native messaging C2, Athena data lake exfiltration, multi-account federation), plus 19 archive posts covering AWS identity attacks, Bedrock CloudTrail playbook, VPC Flow Log analytics, cloud malware case studies, and the foundational AWS attack-chain detection content.

AWS Organizations Compromise — hunting the multi-account federation attack · HackForLab AWS Threat Hunting Part 7
0 10
Posted in Cyber Threat

AWS Organizations Compromise: Hunting the Multi-Account Federation Attack

AWS Organizations centralises governance — and that centralisation creates a high-value attack target. This article covers the four most-exploited multi-account compromise patterns, the cross-account telemetry stitching required to detect them, and the response strategies for organisation-level incident response.

Athena and S3 Data Lake Exfiltration — hunting the SQL-powered data heist · HackForLab AWS Threat Hunting Part 6
0 9
Posted in Cyber Threat

Athena and S3 Data Lake Exfiltration: Hunting the SQL-Powered Data Heist

AWS Athena lets adversaries run massive SELECT queries against S3-stored data lakes — and the resulting data exfiltration leaves a trail that most cloud SOCs do not monitor. This article catalogues the three Athena exfiltration patterns and ships the detection queries that surface them.

EventBridge and SNS as Covert C2 — hunting AWS-native messaging abuse · HackForLab AWS Threat Hunting Part 5
0 9
Posted in Cyber Threat

EventBridge and SNS as Covert C2: Hunting Native AWS Messaging Abuse

Sophisticated adversaries are increasingly abusing native AWS messaging — EventBridge buses, SNS topics, and SQS queues — as command-and-control channels. The traffic blends with legitimate internal application messaging and produces no obvious external-network indicators. This article catalogues the patterns and ships the detection logic.

Hunting CI/CD Compromise in AWS — CodeBuild, CodePipeline, and the buildspec backdoor · HackForLab AWS Threat Hunting Part 4
0 9
Posted in Cyber Threat

Hunting CI/CD Compromise in AWS: CodeBuild, CodePipeline, and the Buildspec Backdoor

The AWS CI/CD attack surface — CodeBuild project configurations, CodePipeline triggers, buildspec.yml files, and build-runner IAM roles — is one of the most under-monitored layers in modern cloud environments. This article ships a focused hunt playbook for the four most exploited CI/CD compromise patterns observed in production incidents.