Category: Cyber Threat

Insider Threat UEBA from VPC Flow Logs — Network-only user behaviour analytics without endpoint telemetry
0 17
Posted in Cyber Threat

Insider Threat Detection from VPC Flow Logs (UEBA Without Endpoints)

Insider threat | UEBA | identity | peer baseline | VPC Flow Logs | behavioral

Kubernetes East-West Attack Hunting from VPC Flow Logs — Pod-to-pod attack detection with namespace and service-mesh awareness
0 20
Posted in Cyber Threat

Kubernetes East-West Attack Hunting from VPC Flow Logs

Kubernetes east-west | pod-to-pod | EKS | namespace boundary | VPC Flow

Tor and Anonymizer Egress Hunting on VPC Flow Logs — Exit-node enrichment and multi-hop circuit analysis
0 21
Posted in Cyber Threat

Tor and Anonymizer Egress Hunting on VPC Flow Logs

Tor egress | anonymizer | VPN | proxy | exit node | VPC Flow Logs

Cloud Cryptojacking Detection at Scale — Mining pool fingerprinting and sustained-traffic ML on AWS VPC Flow Logs
0 19
Posted in Cyber Threat

Cloud Cryptojacking Detection at Scale: Mining-Pool Hunting on AWS

Cryptojacking detection | XMRig | Monero | Stratum | mining pool | AWS VPC

TLS Fingerprinting for Encrypted C2 Hunting — JA3, JA4, JARM analysis on AWS VPC Flow Logs
0 18
Posted in Cyber Threat

TLS Fingerprinting (JA3, JA4, JARM) for Encrypted C2 Hunting

TLS fingerprinting | JA3 | JA4 | JARM | encrypted C2 | VPC Flow Logs