This hands-on lab walks you through a threat emulation exercise on how to use Security Hub to investigate a hacking attempt.
Learning Objectives
Successfully complete this lab by achieving the following learning objectives:
- Enable AWS Security Hub and Deploy Honeypots (Logged in as cloud_user)
- Enable AWS Config
- Enable AWS Security Hub
- From CloudFormation, create a stack using the provided template
- Launch EC2 Instance (Logged in as Martina)
- Create VPC
- Select VPC and More
- From the EC2 console, create a key pair
- Launch an EC2 instance
- Enable Auto-assign public IP
- Use the default for security group of SSH ingress to
0.0.0.0/0
- Create VPC
- Create IAM Access Keys (Logged in as George)
- From the IAM console, select Users
- Select George, then create (and download) access keys
- From the IAM console, select Users
- Create IAM Access Keys (Logged in as Edward)
- From the IAM console, select Users
- Select Edward, then create (and download) access keys
- From the IAM console, select Users
- Connect to EC2 Instance and Perform Tasks (Logged in as Edward)
- In the EC2 console, connect to the instance using Instance Connect
- From the command line, run
aws configure
- Use the downloaded access keys
- For Region, enter
us-east-1
- Copy the contents of the S3 bucket to a
/tmp
directory - Perform of scan of the DynamoDB table