
HANDS-ON WORKSHOP | Cloud Security Forensics & Incident Response: Aviata Chapter 9
Source: YouTube · SANS Cloud Security · published Jan 1, 2025 · 1:19:43
This workshop covered Google Cloud fundamentals, IAM structure, and logging mechanisms, followed by a hands-on investigation of a simulated supply chain attack using Soft Elk to trace lateral movement and privilege escalation.
Key Takeaways:
• Google Cloud IAM relies on binding principals (users/service accounts) to roles via policies applied to resources, with default service accounts being a primary attack vector 10:45
• Audit logs are categorized into control plane (Admin Activity) and data plane (Data Access); Data Access logs are disabled by default, creating visibility gaps for investigators 35:20
• Attackers exploit default compute service accounts with Editor roles to impersonate users, create API keys, and laterally move via snapshots or container deployments 45:10
• Investigation pivoting involves tracing failed API key creations to source IPs, then to Artifact Registry interactions, and finally to Kubernetes deployment events 55:30
• Parsing limitations in external SIEMs can obscure nested JSON data; raw logs or native Cloud Logging are often required for complete attribution 60:15
The session demonstrated that proactive IAM auditing and robust log parsing are essential for detecting sophisticated cloud-based supply chain attacks.
Sources:
- 10:45 Introduction to Google Cloud IAM structure and service account risks
- 35:20 Overview of Admin Activity, System Event, Login Audit, and Data Access logs
- 45:10 Explanation of lateral movement techniques via default service accounts and snapshots
- 55:30 Live demonstration of tracing an attack chain using Soft Elk filters
- 60:15 Discussion on log parsing challenges and the importance of raw data analysis
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cloud Security. Commonly maps to: Security Architecture and Engineering, Communication and Network Security. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Okay, well, I will go ahead and kick it off. So, my name's Megan Roddy Fonseca. I am a security engineer at Datadog and I also co-author and teach forensic 509. I am looking forward to this workshop today. So, we hopped in for the last one of the year. So, hopefully we end on a strong note for those of you who've been coming to the workshops. Terrance, do you want to introduce yourself quick? Yes, I am Terrance Williams. I am a certified instructor for SANS teaching the 4509 course that Megan mentioned that she's a co-author on. By day, I am a security engineer at AWS. So, I'm excited to start. I'm going to go ahead and turn my camera off and let Megan start the show. Perfect. Okay, so today what we're going to do, let me go back. Our plans for today, we're going to start I'm going to give…