Shared Responsibility Model
AWS DDoS Protection
AWS Shield
AWS WAF
AWS Network Firewall
protect your VPC overall
AWS Firewall Manager
Penetration Testing
AWS KMS
Key Management Service
CloudHSM
Types of KMS Keys
AWS ACM
Amazon Certificate Manager
AWS Secrets Manager
AWS Artifact
Not really a service, but presented as one
Support compliance and audit
Amazon GuardDuty
Threat discover using ML
* one click enable, 30 day trial
* * looks at CloudTrail event logs, management events, S3 data events
* * VPC flow logs
* * DNS logs
* * optional analysis of EKS, RDS, etc.
* Set up EventBridge rules with findings (Lambda SNS)
* can protect against crypto attack
Amazon Inspector
Config
Macie
Looks for PII
AWS Security Hub
Config, GuardDuty, Inspector, Macie, IAM access analyzer, AWS system manager, AWS firewall manager, AWS health, AWS partner network solutions
Amazon Detective
AWS Abuse
abuse@amazonaws.com
Root user priviledges
IAM Access Analyzer