Feb. 5, 2024, 6:27 p.m. | Black Hat

Black Hat www.youtube.com

...In this talk I will explore the attack surface of the AWS API, and share multiple vulnerabilities I discovered that allowed me to bypass CloudTrail logging for different AWS services. These vulnerabilities have now been fixed by AWS....

By: Nick Frichette

Full Abstract and Presentation Materials: https://www.blackhat.com/us-23/briefings/schedule/#evading-logging-in-the-cloud-bypassing-aws-cloudtrail-32741

api attack attack surface aws aws cloudtrail bypass bypassing cloud cloudtrail logging logging in nick services share vulnerabilities

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

COMM Penetration Tester (PenTest-2), Chantilly, VA OS&CI Job #368

@ Allen Integrated Solutions | Chantilly, Virginia, United States

Consultant Sécurité SI H/F Gouvernance - Risques - Conformité

@ Hifield | Sèvres, France

Infrastructure Consultant

@ Telefonica Tech | Belfast, United Kingdom