
Join Jenko Hwong at DEF CON 32 Cloud Village for the session, “Cloud Tripwires: fighting stealth with stealth”. Cloud attacks continue to evolve with advanced techniques such as unlogged enumeration techniques, phishing using OAuth applications, and abuse of Cloud Shells for persistence, with current defensive approaches lagging further behind. This talk covers research and tooling to improve cloud defenses in AWS, Azure, and GCP, using more stealthy detection measures to complement existing techniques. This approach of “cloud tripwires” uses stealthy defensive techniques including compute instance credential tracking, resource honey tokens and IAM false flags, to provide low-FP detections of malicious actors.
