Category: Cyber Threat

AWS Organizations Compromise — hunting the multi-account federation attack · HackForLab AWS Threat Hunting Part 7
0 66
Posted in Cyber Threat

AWS Organizations Compromise: Hunting the Multi-Account Federation Attack

AWS Organizations centralises governance — and that centralisation creates a high-value attack target. This article covers the four most-exploited multi-account compromise patterns, the cross-account telemetry stitching required to detect them, and the response strategies for organisation-level incident response.

Athena and S3 Data Lake Exfiltration — hunting the SQL-powered data heist · HackForLab AWS Threat Hunting Part 6
0 63
Posted in Cyber Threat

Athena and S3 Data Lake Exfiltration: Hunting the SQL-Powered Data Heist

AWS Athena lets adversaries run massive SELECT queries against S3-stored data lakes — and the resulting data exfiltration leaves a trail that most cloud SOCs do not monitor. This article catalogues the three Athena exfiltration patterns and ships the detection queries that surface them.

EventBridge and SNS as Covert C2 — hunting AWS-native messaging abuse · HackForLab AWS Threat Hunting Part 5
0 61
Posted in Cyber Threat

EventBridge and SNS as Covert C2: Hunting Native AWS Messaging Abuse

Sophisticated adversaries are increasingly abusing native AWS messaging — EventBridge buses, SNS topics, and SQS queues — as command-and-control channels. The traffic blends with legitimate internal application messaging and produces no obvious external-network indicators. This article catalogues the patterns and ships the detection logic.

Hunting CI/CD Compromise in AWS — CodeBuild, CodePipeline, and the buildspec backdoor · HackForLab AWS Threat Hunting Part 4
0 64
Posted in Cyber Threat

Hunting CI/CD Compromise in AWS: CodeBuild, CodePipeline, and the Buildspec Backdoor

The AWS CI/CD attack surface — CodeBuild project configurations, CodePipeline triggers, buildspec.yml files, and build-runner IAM roles — is one of the most under-monitored layers in modern cloud environments. This article ships a focused hunt playbook for the four most exploited CI/CD compromise patterns observed in production incidents.

GuardDuty Evasion Hunt — 9 techniques adversaries use to stay silent on AWS · HackForLab AWS Threat Hunting Part 3
0 61
Posted in Cyber Threat

GuardDuty Evasion Hunt: 9 Techniques Adversaries Use to Stay Silent on AWS

GuardDuty is the default-on threat-detection service in AWS — and sophisticated adversaries actively engineer their operations to avoid triggering its findings. This article catalogues nine specific evasion techniques observed in cloud incident response, and ships the hunt patterns that surface the silence itself.