From 215b81cba5394c066beaed5db76361dc73a43bab Mon Sep 17 00:00:00 2001 From: Sanjeev Jaiswal Date: Thu, 22 Oct 2020 18:02:56 +0530 Subject: [PATCH 1/4] Update README.md Crossed our broken links. --- README.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/README.md b/README.md index dcd94dc..2962aa7 100644 --- a/README.md +++ b/README.md @@ -10,7 +10,7 @@ AWS has awesome lists of whitepapers related to AWS Security. We are adding few And don't forget to **bookmark AWS Security bulletin** for new vulenrabilities news from [here](https://aws.amazon.com/security/security-bulletins/) 1. [AWS Overview](https://d1.awsstatic.com/whitepapers/aws-overview.pdf) - One of the important whitepaper to understand an overview of AWS -2. [AWS Security Best Practices](http://d0.awsstatic.com/whitepapers/Security/AWS_Security_Best_Practices.pdf) +2. ~~[AWS Security Best Practices]~~(http://d0.awsstatic.com/whitepapers/Security/AWS_Security_Best_Practices.pdf) 3. [AWS Security Pillar](https://d1.awsstatic.com/whitepapers/architecture/AWS-Security-Pillar.pdf) 4. [Introduction to Security By Design](https://d1.awsstatic.com/whitepapers/compliance/Intro_to_Security_by_Design.pdf) 5. [AWS Overview of Security Processes](https://d0.awsstatic.com/whitepapers/aws-security-whitepaper.pdf) @@ -27,7 +27,7 @@ And don't forget to **bookmark AWS Security bulletin** for new vulenrabilities n 16. [AWS Cloud Adoption Framework](https://d1.awsstatic.com/whitepapers/aws_cloud_adoption_framework.pdf) 17. [AWS CAF Security perspective](https://d1.awsstatic.com/whitepapers/AWS_CAF_Security_Perspective.pdf) 18. [AWS Auditing Security Checklist](https://d1.awsstatic.com/whitepapers/compliance/AWS_Auditing_Security_Checklist.pdf) -19. [Introduction to AWS Security Processes](https://d0.awsstatic.com/whitepapers/Security/Intro_Security_Practices.pdf) +19. ~~[Introduction to AWS Security Processes]~~(https://d0.awsstatic.com/whitepapers/Security/Intro_Security_Practices.pdf) 20. [AWS CIS Foundation benchmark](https://d1.awsstatic.com/whitepapers/compliance/AWS_CIS_Foundations_Benchmark.pdf) 21. [Security overview of AWS Lambda](https://aws.amazon.com/lambda/security-overview-of-aws-lambda/) From 5cdd3c071d85006dab8d20af6b31e78c029aa86f Mon Sep 17 00:00:00 2001 From: Sanjeev Jaiswal Date: Tue, 1 Dec 2020 11:22:29 +0530 Subject: [PATCH 2/4] added conformance packs details. --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index 2962aa7..52a8ccf 100644 --- a/README.md +++ b/README.md @@ -96,6 +96,7 @@ And don't forget to **bookmark AWS Security bulletin** for new vulenrabilities n * 1.11 **AWS WAF:** AWS WAF is a web application firewall that helps protect your web applications or APIs against common web exploits that may affect availability, compromise security, or consume excessive resources * 1.12 **AWS Macie:** Macie is all about protecting data. It is a machine learning service that watches data access trends and finds anomalies to spot data leaks and unauthorized data access. * 1.13 **AWS Detective:** Amazon Detective automatically collects log data from your AWS resources and uses machine learning, statistical analysis, and graph theory to build a linked set of data that enables you to easily conduct faster and more efficient security investigations. + * 1.14 **AWS Conformance Packs:** A conformance pack is a collection of AWS Config rules and remediation actions that can be easily deployed as a single entity in an account and a Region or across an organization in AWS Organizations. [conformance packs on github](https://github.com/awslabs/aws-config-rules/tree/master/aws-config-conformance-packs) 2. [Arsenal of AWS Security Tools](https://github.com/toniblyx/my-arsenal-of-aws-security-tools) - Collection of all security category tools and products 3. [AWS Security Automation](https://github.com/awslabs/aws-security-automation) - Collection of scripts and resources for DevSecOps and Automated Incident Response Security 4. [Security Monkey](https://github.com/Netflix/security_monkey) - Monitors AWS, GCP, OpenStack, and GitHub orgs for assets and their changes over time. From d8501cc8710a3709545eccacf3f3c9b8e9a1d17c Mon Sep 17 00:00:00 2001 From: Sanjeev Jaiswal Date: Mon, 7 Dec 2020 22:14:58 +0530 Subject: [PATCH 3/4] Added Securing DevOps in books list --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index 52a8ccf..aaeebb1 100644 --- a/README.md +++ b/README.md @@ -39,6 +39,7 @@ And don't forget to **bookmark AWS Security bulletin** for new vulenrabilities n 5. [AWS Automation Cookbook](https://www.packtpub.com/in/virtualization-and-cloud/aws-automation-cookbook) 6. [AWS Lambda Security Best Practices](http://www.aliencoders.org/wp-content/uploads/2020/01/AWS-Lambda-Security-eBook-1.pdf) - It's published by Puresec and it has a good overview on AWS Lambda Security Best Practices which we should follow 7. [AWS Security by Manning](https://www.manning.com/books/aws-security) - Very nice book in Progress, yet to release. +8. [Securing DevOps](https://www.manning.com/books/securing-devops) - A book which has real-world examples for Cloud Security. Must read book for any Cloud Security Professionals. ## Videos 1. [The fundamentals of AWS Security](https://www.youtube.com/watch?v=-ObImxw1PmI) - Youtube From 39eccf3c6d128b9ec83e9b046d6974156408ecb9 Mon Sep 17 00:00:00 2001 From: Sanjeev Jaiswal Date: Sat, 26 Dec 2020 20:39:54 +0530 Subject: [PATCH 4/4] buttons 21 s3 data breach added buttons 21data breach due to S3 misconfiguration added --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index aaeebb1..7aa79f8 100644 --- a/README.md +++ b/README.md @@ -138,6 +138,7 @@ And don't forget to **bookmark AWS Security bulletin** for new vulenrabilities n 4. [Tesla's Amazon cloud account was hacked and used to mine cryptocurrency](https://www.businessinsider.in/finance/teslas-amazon-cloud-account-was-hacked-and-used-to-mine-cryptocurrency/articleshow/63003345.cms) 5. [10 worst Amazon S3 breaches](https://businessinsights.bitdefender.com/worst-amazon-breaches) 6. [Lion Air the Latest to Get Tripped Up by Misconfigured AWS S3](https://www.darkreading.com/attacks-breaches/lion-air-the-latest-to-get-tripped-up-by-misconfigured-aws-s3-/d/d-id/1335864) +7. [Online Fashion App 21 buttons Exposes Financial Records of Top European Influencers due to S3 misconfiguration](https://www.vpnmentor.com/blog/report-21-buttons-breach/) ## Contributors [Please refer the guidelines at contribute.md for details](Contribute.md).