AWS Security - Staying On Top of The Cloud
AWS Security - Staying On Top of The Cloud
• truffleHog
• https://github.com/dxa4481/truffleHog
• AWS-Recipes
• https://github.com/nccgroup/AWS-recipes
• Scout2
• https://github.com/nccgroup/Scout2
• ...and custom code!
truffleHog
• Goal is to find high-entropy strings that might be used for
authentication or crypto.
• Helps to locate things that developers should not be putting
into version control.
• Goes through Git repositories including all commits and
branches to find high entropy strings.
• Great for finding AWS secret keys and finding some other
interesting strings.
• Enables covering a lot of ground very quickly.
• Mostly false positives, unfortunately.
• Absolutely requires a human to operate, every time.
• Your mileage may vary.
truffleHog Examples
AWS-Recipes
DEMO
Yeah! Everything is Great!
Can I get
new keys?
Sure thing!
The Tale of Alice and Bob
• Alice sends the new keys to Bob as a Secure Message,
using Solution.
• According to Solution, only Alice and Bob have
permission to view the Secure Message.
• Alice views the Secure Message once, after submission.
Confirmed.
All set!
The Tale of Alice and Bob
Chicago Cheltenham
Copenhagen
New York
Edinburgh
San Francisco
Glasgow
Seattle
Leatherhead
Sunnyvale
London
Luxembourg
Milton Keynes
Munich
Zurich