Open cardosec

Case E11F99 · Blue team / DFIR · L3 Applied

Incident Response in the Cloud

Practise as: Deep dive · Explain it
  1. 01 Context
  2. 02 Mechanism
  3. 03 Lessons
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Identity is the perimeter: investigate CloudTrail / Entra sign-in logs for API calls, not just host artifacts.
  2. Common signals: new access keys (CreateAccessKey), disabled logging (StopLogging), unusual regions.
  3. Contain by revoking sessions and keys, attaching deny policies, and isolating instances with restrictive SGs.
  4. Preserve evidence: EBS snapshots, memory captures before termination, and export logs past default retention.
  5. Shared responsibility: investigating your tenant is mostly on you; provider IR help is limited. Pre-stage IR roles and access.

If the interviewer pushes back

  • An attacker used a leaked access key to call AssumeRole into production. How do you scope what they touched?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.