I Collected all the Crown Jewels in the AWS Cloud
I recently wrote an article (link above) about a project I worked on and also spoke about it at the BSides San Diego 2022.
Here is a summary — some of the slides — that I spoke about which are worth mentioning…
Managing Thousands of root credentials for AWS AccountsDo Credentials Management and Ownership right from the StartWho else knows that this information is required to reset the MFA?AWS Organization Service Control Policy Saves the DaySecurity Wins — Decreased Time To Respond and Attack SurfaceEveryone Loves TakeawaysThank you all who attended and gave me feedback!