Open cardosec

Case 4B448B · Cloud · L2 Practitioner

AWS Keys Pushed to GitHub

Practise as: Incident drill · Interview

Live alertA developer pushed an AWS access key to a public repo 25 minutes ago. GitHub secret scanning just alerted, and CloudTrail shows calls from an unknown IP.

Interview questionA key was leaked publicly and is already being used. What are your first 30 minutes?

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Deactivate the key immediately; deleting the commit is not enough because bots scrape public repos within minutes
  2. Pull CloudTrail for that access key ID: which APIs, regions and resources were touched
  3. Look for persistence: new IAM users, keys, roles, trust policy changes, and Lambda or EC2 in unused regions
  4. Crypto-mining is common: check for GPU instances in every region and set billing alarms
  5. Afterwards: move to short-lived credentials and add pre-commit secret scanning

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.