BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Tales from a detection engineering in AWSland\n   Wh
 en: Sunday\, Aug 13\, 12:00 - 12:40 PDT\n   Where: Flamingo - Mesquite - C
 loud Village - [1]Map\n\n   SpeakerBio:Rodrigo Montoro \, Head of Threat &
  Detection Research at\n   Clavis Security\n   Rodrigo Montoro has over 23
  years of experience in Information\n   Technology and Computer Security. 
 For most of his career\, he has\n   worked with open-source security softw
 are (firewalls\, IDS\, IPS\, HIDS\,\n   log management\, endpoint monitori
 ng)\, incident detection & response\,\n   and Cloud Security. Currently is
  Head of Threat & Detection Research\n   at Clavis Security. Before that\,
  he worked as Cloud Researcher at\n   Tenchi Security\, Head of Research a
 nd Development at Apura Cyber\n   Intelligence\, SOC/Researcher at Tempest
  Security\, Senior Security\n   Administrator at Sucuri\, and Researcher a
 t Spiderlabs. Author of 2\n   patented technologies involving innovation i
 n the detection field. One\n   is related to discovering malicious digital
  documents. The second one\n   is in how to analyze malicious HTTP traffic
 . Rodrigo has spoken at\n   several open source and security conferences (
 Defcon Cloud Village\,\n   OWASP AppSec\, SANS (DFIR\, SIEM Summit & Cloud
 SecNext)\, Toorcon (USA)\,\n   H2HC (São Paulo and Mexico)\, SecTor (Canad
 a)\, CNASI\, SOURCE\, ZonCon\n   (Amazon Internal Conference)\, Blackhat B
 razil\, BSides (Las Vegas e\n   SP)).\n   Twitter: [2]@spookerlabs\n\n   D
 escription:\n   Cloud providers' ecosystems have brought a lot of new chal
 lenges to\n   the Security Operations Center (SOC). We now have a lot of a
 ttack\n   vectors that create known and still unknown attack vectors\, gen
 erating\n   a considerable need for further research and detection in this
  field.\n\n   Specifically\, in AWS\, we are talking about more than three
  hundred\n   (300+) services that an attacker could have their specific at
 tack path\n   to achieve their goal. Considering that chaotic scenario and
  leading a\n   Detection Engineering Team that monitors hundreds of custom
 ers\, we\n   developed new and innovative ways to improve customer detecti
 on in\n   three paths:\n\n   First\, the largest market for cloud security
  is associated with Cloud\n   Security Posture Management (CSPM)\, a tool 
 that monitors\n   misconfigurations in cloud accounts. We converted the to
 p 10 results\n   based on the CSPM vendor's statistics reports. The findin
 gs are\n   prioritized from informational to critical\, helping to fix the
 \n   misconfiguration and making the attacker path more difficult.\n\n   S
 econd\, we examined the standard tools' behavior and built detections\n   
 based on those. In particular\, PACU (comprehensive AWS\n   security-testi
 ng toolkit designed for offensive security\n   practitioners)\, Endgame\, 
 and Cloudfox. The main goal is to have\n   tool-agnostic detections using 
 a combination of them to better fit\n   into the AWS scenario.\n\n   Third
 \, and just as important\, are uncommon paths that abuse services\n   that
  are not commonly used or have enough research on it but could\n   lead to
  data exfiltration\, resource exposure\, privilege escalation\,\n   and so
  on.\n\n   By the end of this talk\, attendees will be able to acquire new
 \n   detection ideas\, improve their cloud security posture\, and mitigate
 \n   attack surfaces.\n\n   '\n\n   1. #FlamingoThirdFloor\n   2. https://
 twitter.com/spookerlabs\n\n\n
DTEND:20230813T194000Z
DTSTART:20230813T190000Z
LOCATION:CLV - Flamingo - Mesquite - Cloud Village
SUMMARY:Tales from a detection engineering in AWSland
END:VEVENT
END:VCALENDAR
