Tag: AWS Security

Living-off-the-Land Kill Chain Detection — Markov chain + ensemble scoring on VPC Flow Logs — HACKFORLAB cover image
0 23
Posted in Cyber Threat

Living-off-the-Land Kill Chain Detection with Markov Chains

Detect blended LOTL attack chains by modelling network state transitions as Markov chains across MITRE ATT&CK phases on AWS VPC Flow Logs.

Adaptive C2 Beacon Detection at Scale — FFT spectral analysis and DBSCAN on VPC Flow Logs — HACKFORLAB cover image
0 26
Posted in Cyber Threat

Adaptive C2 Beacon Detection: FFT and DBSCAN on VPC Flow Logs

Detection playbook for jitter-evading C2 beacons (Cobalt Strike, Sliver, Mythic, Brute Ratel) using FFT spectral analysis and DBSCAN clustering on AWS VPC Flow Logs.

AWS Bedrock Threat Hunting: A CloudTrail Log Analysis Playbook — HACKFORLAB cover image
0 32
Posted in Cyber Threat

AWS Bedrock Threat Hunting: A CloudTrail Log Analysis Playbook

A SOC playbook for hunting AWS Bedrock abuse with CloudTrail logs — LLMjacking, Shadow AI, prompt exfiltration, guardrail tampering & more.