Coder Social home page Coder Social logo

aws_eks_cluster_forensics's Introduction

 _____         _         _____                      _  _           __     _      _ 
|     | ___  _| | ___   |   __| ___  ___  _ _  ___ |_|| |_  _ _   |  |   | |_  _| |
|   --|| .'|| . || . |  |__   || -_||  _|| | ||  _|| ||  _|| | |  |  |__ |  _|| . |
|_____||__,||___||___|  |_____||___||___||___||_|  |_||_|  |_  |  |_____||_|  |___|
                                                           |___|                   
                                                           
==================================================================================
==================================================================================
==================================================================================
======Cado Security Presentation - Evidence Files SANS DFIR Conference 2021=======
==================================================================================

Attached are the files associated with the Cado Security SANS Presentation "buff
your cloud game".

Where James Campbell and Allan Carchrie presented the value of forensically
analysing multiple data sources when it comes to cloud investigations.

This investigation
is based on a AWS Kubernetes that has been compromised, and the associated log sources
that can be made available through AWS Cloud. For the full presentation, and outline
please refer to the blog and presentation at cadosecurity.com

===================================================================================
===================================================================================

This data has been provided to the digital forensics community to provide a resource
where people can learn how to do forensics in Amazon Cloud environments, and the useful
data sources that can be captured. This is intended for training all levels from students
to active incident response experts/consultants and is not for commercial use.

====================================================================================
====================================================================================

The data sources made avaliable within the 7zip file, include,
1) cado_cloud_collector_i-06308..._20GB_1625678779.dd.gz (which is the raw forensic
AWS EKS node image collected by Cado Response. This is a raw DD file Gzipped)
2) AWS Log files
---a) kube-apiserver* (Kube api audit logs)
---b) eni-* (AWS VPC flow logs for the AWS EKS cluster)
---c) cloudtrial* - (AWS Cloud Trail Logs)
---d) Authenticator* (AWS authentication logs for AWS EKS role/cluster)
SHA256 - 2b865d36bf7295adae5545d40be389803a841808a162d603e18a92da38a6c2ed  CadoSecurity-CloudForensics-SANS_DFIR2021-Files.7z
MD5SUM - 4f486a34ad478a33f5df94dde1a3c6b3  CadoSecurity-CloudForensics-SANS_DFIR2021-Files.7z
7z files are associated with the 7zip application, other utilities like WinRAR will work to.

------------------------------------------------------------------------------------
For a full description of the data, and key events to get you started checkout the
presentation linked via the blog on cadosecurity.com
After being decompressed, all log files can be viewed either by your favourite text editor,
or be parsed into your favourite solution.

====================================================================================

Have Fun! From The Cado Security Team! @CadoSecurity

You can download these files from:

We will be presenting on how to solve/analyse the disk and memory of this compromised system at:

aws_eks_cluster_forensics's People

Contributors

chrisdoman avatar

Watchers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.