Cloud security encounters attacks that elude standard detection. In AWS, unauthorized access keys are a common cause of breaches. The vastness of AWS, over 450 services and 19,000 API actions, complicates threat visibility and exposes gaps in traditional tools. This workshop empowers participants with direct, hands-on experience using the AWS Threat Hunter tool to improve threat detection.
Attendees will focus on building behavioral baselines and leveraging data-driven analysis to detect subtle AWS principal anomalies, enabling more precise detection than traditional event monitoring. Attendees will move beyond standard techniques by building multi-stage detection pipelines that create individualized baselines for each IAM principal and systematically flag personalized deviations, linking outliers directly to risks.
Presented at BSides Las Vegas 2026