BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Understanding\, Abusing and Monitoring AWS AppStream
  2.0\n   When: Sunday\, Aug 14\, 10:00 - 10:40 PDT\n   Where: Flamingo - S
 unset-Scenic Ballroom (Cloud Village) - [1]Map\n\n   SpeakerBio:Rodrigo Mo
 ntoro\n   Rodrigo "Sp0oKeR" Montoro has more than 20 years of experience i
 n\n   Information Technology and Computer Security. Most of his career\n  
  worked with open source security software (firewalls\, IDS\, IPS\, HIDS\,
 \n   log management\, endpoint monitoring)\, incident detection & response
 \,\n   and Cloud Security. Currently\, he is a Senior Threat Detection\n  
  Engineer at Tempest Security. Before that\, he worked as Cloud\n   Resear
 cher at Tenchi Security\, Head of Research and Development at\n   Apura Cy
 ber Intelligence\, SOC/Researcher at Clavis\, Senior Security\n   Administ
 rator at Sucuri\, Researcher at Spiderlabs. Author of 2\n   patented techn
 ologies involving innovation in the detection field. One\n   is related to
  discovering malicious digital documents. The second one\n   is in how to 
 analyze malicious HTTP traffic. Rodrigo has spoken at\n   several open-sou
 rce and security conferences (OWASP AppSec\, SANS (DFIR\n   \,SIEM Summit 
 and CloudSecNext)\, Defcon Cloud Village\, Toorcon (USA)\,\n   H2HC (Sπo 
 Paulo and Mexico)\, SecTor (Canada - 5x)\, CNASI\, SOURCE\n   Boston & Sea
 ttle\, ZonCon (Amazon Internal Conference)\, Blackhat\n   Brazil\, BSides 
 (Las Vegas e Sπo Paulo)).\n   Twitter: [2]@spookerlabs\n\n   Description:
 \n   Amazon Web Services (AWS) is a complex ecosystem with hundreds of\n  
  different services. In the case of a security breach or compromised\n   c
 redentials\, attackers look for ways to abuse the customer's\n   configura
 tion of services with their compromised credentials\, as the\n   credentia
 ls are often granted more IAM permissions than is usually\n   needed. Most
  research to date has focused on the core AWS services\,\n   such as \, S3
 \, EC2\, IAM\, CodeBuild\, Lambda\, KMS\, etc. In our research\,\n   we pr
 esent our analysis on a previously overlooked attack surface that\n   is r
 ipe for abuse in the wrong hands - an AWS Service called Amazon\n   AppStr
 eam 2.0. Amazon AppStream 2.0 is a fully managed desktop service\n   that 
 provides users with instant access to their desktop applications\n   from 
 anywhere. Using AppStream 2.0\, you can add your desktop\n   applications 
 to a virtual machine and share access to the VM by\n   sharing a link - wi
 thout requiring any credentials\, you can share an\n   image (an attack to
 olset) with a target account without needing any\n   approval from the oth
 er side or attach some privileged role to an\n   image and get those crede
 ntials.\n\n   In this talk\, you'll learn about how AppStream works\, how\
 n   misconfigurations and excessive IAM permissions can be abused to\n   c
 ompromise your AWS environment and allow attackers to control your\n   ent
 ire AWS account. We'll cover tactics such as persistence\, lateral\n   mov
 ement\, exfiltration\, social engineering\, and privilege escalation.\n   
 We will also cover the key indicators of compromise for security\n   incid
 ents in AppStream and how to prevent these abuse cases\, showing\n   how e
 xcessive privileges without great monitoring could become a\n   nightmare 
 in your Cloud Security posture\, making possible attackers\n   control you
 r AWS account.\n\n   '\n\n   1. https://defcon.outel.org/consolidated_page
 .html#FlamingoThirdFloor\n   2. https://twitter.com/spookerlabs\n\n\n
DTEND:20220814T174000Z
DTSTART:20220814T170000Z
LOCATION:CLV - Flamingo - Sunset-Scenic Ballroom  (Cloud Village)
SUMMARY:Understanding\, Abusing and Monitoring AWS AppStream 2.0
END:VEVENT
END:VCALENDAR
