YouTube2Text

AWS Security Arsenal Explained | GuardDuty, Inspector, Macie, WAF & Shield | Day 16 — Transcript

by Pawan Joshi · 4,097 words · 743 segments · language en · Watch on YouTube

Full transcript

  1. 0:00Hey everyone, welcome to day 16.
  2. 0:02Yesterday we learned how different parts
  3. 0:04of an application talk to each other
  4. 0:05using SQS, SNS, and EventBridge. Today
  5. 0:08we are switching gears completely and
  6. 0:10stepping into one of the most important
  7. 0:12and honestly one of the most heavily
  8. 0:13tested topics in the entire AWS Cloud
  9. 0:15Practitioner exam.
  10. 0:17That is security.
  11. 0:19Today's theme is what I like to call the
  12. 0:21AWS security arsenal.
  13. 0:23Think of it like a toolbox full of
  14. 0:25specialized weapons where each tool has
  15. 0:27one very specific job. Some detect
  16. 0:29threats, some protect your resources,
  17. 0:30and some help you respond when something
  18. 0:32goes wrong.
  19. 0:33Here's something important. This topic
  20. 0:35falls under domain two, that is security
  21. 0:37and compliance, and this domain is worth
  22. 0:3930% of your entire exam. And that's
  23. 0:42nearly one out of every three questions
  24. 0:44you will face.
  25. 0:45So if you only need to deeply understand
  26. 0:48one domain before
  27. 0:49your exam, honestly this would be the
  28. 0:51one of the top priorities, your top
  29. 0:53contenders.
  30. 0:55Now here's the thing about security
  31. 0:56services on this exam. AWS has a lot of
  32. 0:59them, and if you try to memorize them
  33. 1:00randomly, you will mix them up in
  34. 1:01seconds.
  35. 1:03GuardDuty, Inspector, Macie, Config,
  36. 1:06WAF, Shield, KMS, Secret Manager,
  37. 1:09Security Hub.
  38. 1:11That's nine services in one day.
  39. 1:14Sounds scary, right? But don't worry,
  40. 1:17there's a simple trick to master all of
  41. 1:18them.
  42. 1:19The exam almost never asks you to
  43. 1:21explain a service in detail. It gives
  44. 1:23you a one-line scenario and asks you to
  45. 1:25match it to the correct service.
  46. 1:27So today instead of just throwing
  47. 1:29definitions at you, I'm going to teach
  48. 1:31you exactly how to pattern match
  49. 1:32keywords in a question to the right
  50. 1:34service. Because that's the real skill
  51. 1:36that gets you marks in the exam.
  52. 1:38By the end of today's session, you will
  53. 1:39be able to clearly distinguish between
  54. 1:42GuardDuty,
  55. 1:44Inspector,
  56. 1:47Macie,
  57. 1:49and Config.
  58. 1:52Knowing exactly what each one detects.
  59. 1:55We will also compare AWS WAF
  60. 1:59and AWS
  61. 2:01Shield
  62. 2:02standard or advanced.
  63. 2:04And we will know when each applies.
  64. 2:07We will also explain how AWS KMS and AWS
  65. 2:11Secrets Manager work together for
  66. 2:14encryption and secrets.
  67. 2:17We will understand how uh AWS Security
  68. 2:20Hub brings everything together in one
  69. 2:23unified dashboard.
  70. 2:24And at the end we have got a real
  71. 2:26hands-on lab where you will enable
  72. 2:28GuardDuty in your own AWS account and
  73. 2:30generate uh sample security finding and
  74. 2:33we will explore what a real threat
  75. 2:35detection dashboard actually looks like.
  76. 2:37Let's dive in.
  77. 2:38Before we go service by service, let's
  78. 2:40zoom out and look at the big picture.
  79. 2:42Because once you see how these seven
  80. 2:44areas are organized, the whole day will
  81. 2:46feel much easier to follow.
  82. 2:48Think of AWS security like protecting a
  83. 2:50house. You need different types of
  84. 2:52protection for different types of
  85. 2:53threats.
  86. 2:54A camera to detect intruders, a lock to
  87. 2:56prevent break-ins, a fireproof safe for
  88. 2:59your valuables maybe, and maybe a
  89. 3:00security company that watches everything
  90. 3:02from one central control room.
  91. 3:05AWS security services work exactly the
  92. 3:07same way. So, let's map them out.
  93. 3:10The first one is threat detection,
  94. 3:12GuardDuty. This is like your security
  95. 3:14camera with AI built in. It constantly
  96. 3:16watches over your AWS account for
  97. 3:18suspicious behavior.
  98. 3:20Number two, vulnerability assessment,
  99. 3:23that is Inspector.
  100. 3:25This is like a home inspector who checks
  101. 3:27your home for weak locks, cracked
  102. 3:29windows, or outdated security systems.
  103. 3:32Except here it's scanning your servers
  104. 3:34and code for known weaknesses.
  105. 3:36We have third one that is sensitive data
  106. 3:38discovery, that is Macie.
  107. 3:40Think of this as someone going through
  108. 3:42your house and specifically searching
  109. 3:44for your most valuable, most sensitive
  110. 3:46documents like passport, bank details,
  111. 3:49and flagging if they are lying around
  112. 3:50unprotected.
  113. 3:52We have the fourth one, configuration
  114. 3:53compliance, that is config.
  115. 3:56This is your detailed history logbook.
  116. 3:57It remembers every single change made to
  117. 4:00your house setting, so you can always
  118. 4:01answer, "Was this door locked last
  119. 4:04Tuesday?"
  120. 4:06We have fifth one, that is network and
  121. 4:07application protection. WAF and Shield.
  122. 4:12These are your actual logs and
  123. 4:13reinforced walls, like stopping
  124. 4:15attackers from breaking in.
  125. 4:17Whether they are trying to sneak through
  126. 4:18the front door, that is application
  127. 4:20attacks, or trying to flood your entire
  128. 4:22state with traffic.
  129. 4:23We call it DDoS attack.
  130. 4:26Uh the sixth one we have, encryption and
  131. 4:28secrets. We have KMS and secrets
  132. 4:31manager. This is your safe and vault,
  133. 4:33protecting your most sensitive keys,
  134. 4:35passwords, and secrets.
  135. 4:37The seventh one we have, centralized
  136. 4:39visibility, that is security hub.
  137. 4:42This is your central security room, one
  138. 4:44dashboard, where every alarm, every
  139. 4:46camera feed, every alert from all other
  140. 4:48tools show up in one place.
  141. 4:50That's the entire landscape for today.
  142. 4:52Seven categories, nine services.
  143. 4:55Once we go through each one with
  144. 4:57example, this will all click together
  145. 4:59beautifully. Let's start with the first
  146. 5:01four, the detect, assess,
  147. 5:04classify,
  148. 5:05comply framework.
  149. 5:07This slide right here is probably the
  150. 5:08single most important slide of the
  151. 5:10entire day, because these four services
  152. 5:12get confused with each other constantly
  153. 5:14by beginners, and the exam knows that.
  154. 5:16So, it loves testing this exact
  155. 5:18confusion.
  156. 5:19Let's break each one down carefully and
  157. 5:21one at a time using a clear framework,
  158. 5:23that is detect, assess, classify, and
  159. 5:27comply.
  160. 5:29All right, so first one is detect
  161. 5:30threats, that is Amazon GuardDuty.
  162. 5:33GuardDuty is AWS' intelligent threat
  163. 5:35detection service. Think of it as a
  164. 5:37security guard powered by machine
  165. 5:38learning who never sleeps. It
  166. 5:40continuously and automatically analyzes
  167. 5:42three sources of information across your
  168. 5:44account.
  169. 5:45What are these three sources?
  170. 5:47The first one is
  171. 5:48CloudTrail logs.
  172. 5:51That is a records of every action taken
  173. 5:53in your AWS account.
  174. 5:56The next one is VPC flow logs, records
  175. 5:58of network traffic flowing in and out of
  176. 6:00your servers. The another source of
  177. 6:02information is DNS logs.
  178. 6:05That is a records of your domain name
  179. 6:07lookups.
  180. 6:08GuardDuty uses machine learning to spot
  181. 6:10pattern that looks suspicious.
  182. 6:12Patterns a human might completely miss.
  183. 6:14For example,
  184. 6:16imagine someone is suddenly making an
  185. 6:17API calls to your AWS account from a Tor
  186. 6:19exit node.
  187. 6:21That's a part of the dark web network
  188. 6:23people use to hide their identity. A
  189. 6:25normal human admin has no any reason to
  190. 6:27be logging in through Tor. GuardDuty
  191. 6:29would immediately flag this as an
  192. 6:31unusual API calls finding, warning you
  193. 6:33that your account might be compromised.
  194. 6:36Here the keyword to remember is whenever
  195. 6:38you see a phrase unusual activity,
  196. 6:40suspicious API calls, ML-based threat
  197. 6:43detection, and or compromised instance.
  198. 6:45The answer is GuardDuty.
  199. 6:48Remember that, and we have another
  200. 6:51assess vulnerabilities. That is Amazon
  201. 6:54Inspector.
  202. 6:56Now, GuardDuty watches for behavior
  203. 6:57things happening in the real time.
  204. 6:59Inspector is completely different.
  205. 7:01It does automated vulnerability
  206. 7:03scanning, meaning it checks your actual
  207. 7:05software and system for known
  208. 7:06weaknesses, even if nothing suspicious
  209. 7:08is currently happening.
  210. 7:10Inspector automatically scans your EC2
  211. 7:12instances, Lambda functions, and
  212. 7:14container images looking for known CVs,
  213. 7:17which stands for common vulnerabilities
  214. 7:19and exposures.
  215. 7:20These are publicly documented security
  216. 7:22flaws found in popular software.
  217. 7:25Let us take a real example. Remember the
  218. 7:27massive Log4j vulnerability that
  219. 7:29affected thousands of companies
  220. 7:30worldwide a few years back?
  221. 7:32If you might have heard about this
  222. 7:33vulnerability,
  223. 7:35if a vulnerable version of that Log4j
  224. 7:37software was sitting on one of your EC2
  225. 7:39instances, Inspector would automatically
  226. 7:42detect it and flag it even though no
  227. 7:44attacker has actually exploited it yet.
  228. 7:46It's proactive, not reactive.
  229. 7:48Keyword to remember here,
  230. 7:50whenever you see vulnerability
  231. 7:51assessment, CVE scanning, that is common
  232. 7:54vulnerabilities and exposures scanning,
  233. 7:57outdated software packages or known
  234. 7:59software vulnerabilities, the answer is
  235. 8:02Inspector.
  236. 8:03Remember that. So, we have detected and
  237. 8:06assessed. Now, it's time for classify,
  238. 8:09that is classify sensitive data.
  239. 8:11That is Amazon Macie.
  240. 8:14Uh so, let's talk about it. It has a
  241. 8:16very specific and narrow job. It uses
  242. 8:18machine learning to automatically
  243. 8:20discover and classify and protect
  244. 8:23sensitive data specifically inside the
  245. 8:25Amazon S3 buckets.
  246. 8:27So, what kind of sensitive data are we
  247. 8:29talking about?
  248. 8:30Things like credit card numbers, social
  249. 8:32security number, passport numbers, and
  250. 8:35other types of personally identifiable
  251. 8:36information commonly abbreviated as PII.
  252. 8:40Imagine a careless developer
  253. 8:42accidentally uploads a spreadsheet full
  254. 8:44of customer credit card numbers to an S3
  255. 8:46bucket and forgets to encrypt it.
  256. 8:49Macie's ML models will scan through that
  257. 8:51bucket, recognize the pattern of the
  258. 8:52data. It knows what a credit card
  259. 8:55typically looks like, and it raises an
  260. 8:57alert saying something like S3 bucket
  261. 8:59contains unencrypted credit card
  262. 9:01numbers.
  263. 9:03Whenever you see PII discovery,
  264. 9:06sensitive data in S3, credit card
  265. 9:08numbers, classified data, the answer is
  266. 9:11always Macie. Remember this simple link,
  267. 9:15Macie equal to S3 plus PII.
  268. 9:18Finally, Config.
  269. 9:20This one is completely different from
  270. 9:21the other three. It's not about
  271. 9:23detecting threats or scanning for
  272. 9:25vulnerabilities.
  273. 9:26Config's job is to record and track
  274. 9:28every single configuration change made
  275. 9:30to your AWS resources over time, and it
  276. 9:33lets you check whether your resources
  277. 9:34comply with the rules you have set.
  278. 9:37Imagine your security team ask was
  279. 9:38multi-factor authentication turned off
  280. 9:40for this IAM user last Tuesday?
  281. 9:42GuardDuty can't answer that. It's not
  282. 9:44tracking configuration history.
  283. 9:46Inspector can't answer it either. It's
  284. 9:48scanning for vulnerabilities, not
  285. 9:50settings history.
  286. 9:51But Config can answer this instantly
  287. 9:53because it keeps a full historical
  288. 9:55timeline of every configuration change
  289. 9:57ever made.
  290. 9:59Whenever you see configuration history,
  291. 10:01complies auditing, drift detection, or
  292. 10:03was this setting changed? The answer is
  293. 10:05always Config.
  294. 10:07Let's lock in the full exam pattern
  295. 10:08together.
  296. 10:09PII in S3, that is Macie.
  297. 10:12Unusual activity, suspicious behavior,
  298. 10:14that is GuardDuty.
  299. 10:16Software vulnerabilities or CV,
  300. 10:19Inspector.
  301. 10:21Configuration compliance or change
  302. 10:23history,
  303. 10:24Config.
  304. 10:26So, we have done four aspect, that is
  305. 10:28detect, assess, classify, and comply.
  306. 10:32Say these four mappings out loud a few
  307. 10:34times. Seriously, this single pattern
  308. 10:35alone will help you answer a huge chunk
  309. 10:37of domain two questions correctly.
  310. 10:39Now, let's move from detection services
  311. 10:41to active protection services.
  312. 10:43This slide covers two services that
  313. 10:45people confuse constantly, that is AWS
  314. 10:47WAF and AWS Shield.
  315. 10:50The trick to telling them apart is
  316. 10:52understanding which layer of the network
  317. 10:54each one protects.
  318. 10:57Think of network traffic like layers of
  319. 10:59onions. You must have seen onion?
  320. 11:01The deepest layer handle the raw network
  321. 11:04connections and the outer layer handle
  322. 11:05the actual content of a web request.
  323. 11:08Like a login form or search box.
  324. 11:11WAF and Shield each guard a different
  325. 11:13layer.
  326. 11:14WAF operates at layer seven, which is
  327. 11:16the application layer.
  328. 11:18Basically, the layer where actual web
  329. 11:20request like someone submitting a login
  330. 11:22form or a search query happen.
  331. 11:24WAF is designed to catch web specific
  332. 11:27attacks, including SQL injections. It is
  333. 11:30a way an attacker tries to sneak
  334. 11:32malicious database commands into a web
  335. 11:34form tricking your database into leaking
  336. 11:36or destroying data.
  337. 11:38We you must have heard about XSS or that
  338. 11:40is or cross-site scripting.
  339. 11:43In this attacker injects malicious
  340. 11:45scripts into a web page that then runs
  341. 11:47in the others users browser.
  342. 11:50We have geographic restrictions that is
  343. 11:52blocking traffic from a specific
  344. 11:54countries entirely.
  345. 11:56The next is IP rate limiting and bot
  346. 11:58control.
  347. 12:00That is stopping a single IP address
  348. 12:01from hammering your website with
  349. 12:02thousands of requests per second or
  350. 12:05blocking automated bots.
  351. 12:07WAF directly plugs into services like
  352. 12:09Amazon CloudFront, application load
  353. 12:11balancer, API Gateway, and AWS AppSync
  354. 12:14and basically anywhere your web traffic
  355. 12:16passes through.
  356. 12:18Whenever you see protect against SQL
  357. 12:21injection, block XSS attacks, or web
  358. 12:24application firewall, the answer is AWS
  359. 12:26WAF and WAF stands for web application
  360. 12:30firewall. We have another service that
  361. 12:33is AWS Shield. Shield operates one level
  362. 12:35deeper at a layer three and four, the
  363. 12:37network and transport layer.
  364. 12:39Its entire job is protecting you from
  365. 12:41DDoS attacks. DDoS means distributed
  366. 12:44denial of service attacks where
  367. 12:45attackers try to overwhelm your servers
  368. 12:47with a massive flood of junk traffic
  369. 12:49like SYN floods or UDP reflection
  370. 12:50attacks hoping to knock your service
  371. 12:53fully offline.
  372. 12:54Shield actually comes in two tiers.
  373. 12:56This distinction is favorite exam trap.
  374. 12:59Shield standard and Shield advanced. The
  375. 13:01Shield standard is completely free and
  376. 13:03it's automatically active for every
  377. 13:05single AWS customer with zero setup
  378. 13:06required. It protects against the most
  379. 13:09common layer three and layer four DDoS
  380. 13:10attacks right out of the box. The
  381. 13:12another one is AWS advanced. This is a
  382. 13:14paid tier starting at a minimum of
  383. 13:17$3,000 per month. For that price you get
  384. 13:19access to AWS 24/7 DDoS response team
  385. 13:22often abbreviated as the DRT, a team of
  386. 13:25real security expert who actively help
  387. 13:27you during a live attack.
  388. 13:29You also get financial protection,
  389. 13:30meaning if a DDoS attack causes your
  390. 13:32bill to spike and due to extra traffic
  391. 13:34and scaling, AWS will credit you back
  392. 13:37for those unexpected cost. Plus, you get
  393. 13:39an SLA guarantee for on protection.
  394. 13:42And here are some exam patterns to
  395. 13:43remember.
  396. 13:44Protect web application from SQL
  397. 13:46injection attacks. AWS WAF.
  398. 13:50DDoS protection with a dedicated expert
  399. 13:52response team.
  400. 13:54That is AWS Shield Advanced.
  401. 13:57Free automatic DDoS protection for all
  402. 13:59customers. We have AWS Shield Standard.
  403. 14:02Now, let's move into our third category.
  404. 14:05Encryption, secrets, and centralized
  405. 14:07visibility.
  406. 14:09This slide covers four services
  407. 14:10actually. Even though the title only
  408. 14:12mentions three, we will also touch on
  409. 14:14AWS Certificate Manager.
  410. 14:16Let's discuss about AWS KMS, Key
  411. 14:18Management Service.
  412. 14:22KMS lets you centrally create, manage,
  413. 14:24and control the graphic keys used to
  414. 14:27encrypt your data across AWS. Here's the
  415. 14:29most important part beginners often
  416. 14:31miss. You rarely interact with KMS
  417. 14:33directly and obviously. Instead, it
  418. 14:35works quietly behind the scenes. When
  419. 14:37you flip on encryption for services like
  420. 14:39S3, EBS, that is EBS is EC2 storage
  421. 14:42volumes, RDS, or DynamoDB, AWS is
  422. 14:46actually using KMS customer managed
  423. 14:47keys, often abbreviated as CMKs
  424. 14:52to perform that encryption under the
  425. 14:53hood. KMS also keeps a full audit trail
  426. 14:56meaning every single time a key is used
  427. 14:59to encrypt or decrypt something, that
  428. 15:01action gets logged, so you always know
  429. 15:03what exactly who used which key and
  430. 15:05when. Here are some keywords to
  431. 15:07remember. Encryption key management,
  432. 15:10customer managed key, CMKs envelope
  433. 15:13encryption
  434. 15:14that is KMS.
  435. 15:16Now, let's discuss about AWS Secrets
  436. 15:18Manager, the service with a very
  437. 15:19specific, very memorable job, securely
  438. 15:22storing secrets.
  439. 15:24Things like database passwords, API
  440. 15:26keys, and OAuth tokens. So, they are
  441. 15:28never hard-coded directly into your
  442. 15:30application source code, which by the
  443. 15:31way is the huge security risk many
  444. 15:33beginner developers accidentally make.
  445. 15:35But, here's the star feature that makes
  446. 15:37Secret Manager stand out on the exam.
  447. 15:39Automatic rotation.
  448. 15:41Secret Manager can automatically rotate
  449. 15:43your RDS database credentials on a
  450. 15:44schedule you configure. Let's say you
  451. 15:46configured every 30 days.
  452. 15:48Completely on its own without any human
  453. 15:51manually typing a new password. And this
  454. 15:53dramatically reduces the risk of leaked
  455. 15:55password being useful to any attacker
  456. 15:56for a long time.
  457. 15:58So, what are the keywords to remember
  458. 15:59here?
  459. 16:00Automatic secret rotation, database
  460. 16:02credential management, API key storage.
  461. 16:06Select Secret Manager.
  462. 16:08Just a quick mention here. Since it's
  463. 16:10related to security, too, ACM provides
  464. 16:12free SSL TLS certificates for AWS
  465. 16:14services like CloudFront and Application
  466. 16:16Load Balancer.
  467. 16:18These certificates are what make your
  468. 16:19website secure. That little padlock icon
  469. 16:21in the browser confirming your
  470. 16:22connection is encrypted. ACM's best
  471. 16:24feature is automatic certificate
  472. 16:26renewal.
  473. 16:27No more scrambling to manually renew an
  474. 16:29expiring certificate before your website
  475. 16:31breaks.
  476. 16:32And the final we have AWS Security Hub.
  477. 16:36Finally, the service that ties
  478. 16:37everything together. This is what's
  479. 16:39called a CSPM tool that stands for
  480. 16:42cloud
  481. 16:44security
  482. 16:45posture
  483. 16:48management. Its job is simple,
  484. 16:51but incredibly valuable. It takes all
  485. 16:53the security findings generated by
  486. 16:55GuardDuty, Inspector, Macie, and Config
  487. 16:58and aggregates them into a single
  488. 17:00unified dashboard.
  489. 17:02Instead of jumping between four or five
  490. 17:04different service consoles every morning
  491. 17:05to check for security issues, a security
  492. 17:08team can just open the Security Hub and
  493. 17:10see everything in one place. This is
  494. 17:12often described as a single pane of
  495. 17:14glass.
  496. 17:15Security Hub also comes with built-in
  497. 17:17compliance against well-known industry
  498. 17:19standards like CIS, PCI DSS, and NIST,
  499. 17:22automatically telling you how well your
  500. 17:24AWS environment aligns with these
  501. 17:25frameworks. So, what are the keywords to
  502. 17:27remember for this?
  503. 17:29Centralized security findings,
  504. 17:31single pane of glass,
  505. 17:33aggregates GuardDuty, Inspector, and
  506. 17:35Macie findings, that is Security Hub.
  507. 17:40All right, time to get hands-on. Today's
  508. 17:42lab is all about GuardDuty. We are going
  509. 17:44to enable it in your real AWS account,
  510. 17:46generate some sample security findings.
  511. 17:49Don't worry, these are just safe example
  512. 17:51findings, not the real threats, and we
  513. 17:52will learn how to read and interpret a
  514. 17:54real security dashboard.
  515. 17:56I want you to give a one important
  516. 17:58heads-up before we start. At the very
  517. 18:01end of this lab, we are going to disable
  518. 18:03GuardDuty.
  519. 18:04I will explain exactly why when we get
  520. 18:07there. Please don't skip that step.
  521. 18:10So, in the AWS console,
  522. 18:12you need to search for GuardDuty. As I
  523. 18:14can see GuardDuty over here, I will
  524. 18:16simply open it.
  525. 18:18And once you open it,
  526. 18:20as I currently I can see this screen,
  527. 18:22but if you are new to this GuardDuty,
  528. 18:25you will see a welcome screen, where the
  529. 18:27button says get started.
  530. 18:29What you need to do is click on get
  531. 18:31started, and you need to enable
  532. 18:33GuardDuty.
  533. 18:34All right. I guess there was a first
  534. 18:37option that says activate all the
  535. 18:39services. You need to select that, and
  536. 18:41enable GuardDuty.
  537. 18:43So, GuardDuty will actually what it will
  538. 18:45do is it will automatically create
  539. 18:47something called service-linked role.
  540. 18:49This is simply a special permission role
  541. 18:51that allows GuardDuty to read your
  542. 18:53CloudTrail, VPC flow,
  543. 18:55and DNS logs on your behalf. So, go
  544. 18:57ahead and accept these permission, and
  545. 18:59then the moment you enable it, your
  546. 19:0130-day free trial begins immediately.
  547. 19:03Meaning GuardDuty starts analyzing your
  548. 19:05account logs right away, at absolutely
  549. 19:08no cost for the first 30 days.
  550. 19:10You will land on this findings dashboard
  551. 19:14and it will likely show zero findings in
  552. 19:16your case.
  553. 19:17And yeah, that means it is 100% correct.
  554. 19:20It's because
  555. 19:21as you have a brand new account, it's so
  556. 19:23there is no suspicious activity so it
  557. 19:25will show zero. It means nothing bad has
  558. 19:27been detected yet and which is a good
  559. 19:29thing.
  560. 19:30And since we don't have any real
  561. 19:32threats,
  562. 19:33so what I will do is let me generate
  563. 19:37some sample finding.
  564. 19:41Go to this sample finding tab and I will
  565. 19:43click on generate finding.
  566. 19:46All right.
  567. 19:48So wait for 1 to 2 minutes and then head
  568. 19:50back to the finding section using the
  569. 19:51left hand menu.
  570. 19:53And yes, we are here. And then let's go
  571. 19:55to the findings menu. You will see a
  572. 19:57whole list of sample finding pop up
  573. 19:59representing different types of threat
  574. 20:01GuardDuty is designed to catch such as
  575. 20:04we have unauthorized access, we have EC2
  576. 20:07instance,
  577. 20:08user fault FD uses usage detected.
  578. 20:12Kubeflow dashboard was exposed to the
  579. 20:13internet, you can see. And container was
  580. 20:16mounted to the host directory. Yes, we
  581. 20:17have a lot of things.
  582. 20:19You can click on any of these. Let's
  583. 20:21say, let me click on this. And you can
  584. 20:23see
  585. 20:24the type of severity it is medium. You
  586. 20:27can see the reason, count, account ID.
  587. 20:31You will see each and everything like
  588. 20:32finding type, security level, affected
  589. 20:35resource, which is specific I am user
  590. 20:37EC2 instance or other resource finding
  591. 20:39relates to the reason, the source IP and
  592. 20:41the recommended action as well.
  593. 20:43GuardDuty doesn't just alert you, it
  594. 20:45actually suggest what you should do
  595. 20:47about it.
  596. 20:49A useful trick here.
  597. 20:51So you will find
  598. 20:52this
  599. 20:54section. Let me show you this.
  600. 20:56I will close this and we have this
  601. 20:58severity tab. Use this severity filter
  602. 21:01so only high and critical findings. In a
  603. 21:04real production environment, these are
  604. 21:06findings your security team needs to
  605. 21:07jump on immediately. All right, so you
  606. 21:10can see there are many critical, high,
  607. 21:13these type of alerts.
  608. 21:15So, these things are the things that I
  609. 21:18need to resolve immediately. Now, here's
  610. 21:20the step I promised to circle back to.
  611. 21:22Head back to setting in the navigation
  612. 21:25bar
  613. 21:26and scroll all the way to the bottom and
  614. 21:28click on suspend GuardDuty or you can
  615. 21:33delete it. Since I am I have already
  616. 21:35suspended, you can click on suspend and
  617. 21:37it suspends or you can disable the
  618. 21:39GuardDuty as well.
  619. 21:41All right, as you can see yeah, this is
  620. 21:43the page you will see when you are
  621. 21:46as you open the GuardDuty for the first
  622. 21:49time. I don't know why it is showing me
  623. 21:51this now.
  624. 21:52Some error has been occurred. All right,
  625. 21:54yeah.
  626. 21:55So, this is the page you will see.
  627. 21:58You can click on get it started and you
  628. 22:00can click on enable
  629. 22:02GuardDuty if you are a new account.
  630. 22:05Why does this matter so much?
  631. 22:07GuardDuty gives you a generous 30-day
  632. 22:08free trial, but after that period ends,
  633. 22:10AWS start charging you based on the
  634. 22:12volume events analyzed. Meaning the more
  635. 22:14CloudTrail events, VPC flow log entries,
  636. 22:17DNS queries your account generates, the
  637. 22:20more it costs.
  638. 22:21If you forget about this lab account and
  639. 22:23leave GuardDuty running indefinitely
  640. 22:26without realizing it, it could end up
  641. 22:28with an unexpected bill down the line.
  642. 22:31So, if you want to do it, you can do it.
  643. 22:33You can try this lab. Or if you don't
  644. 22:36want to do it, yeah. But But if you do
  645. 22:39it, remember to disable this GuardDuty.
  646. 22:42One very important real-world note, uh
  647. 22:45though in an actual production
  648. 22:47environment like a real company AWS
  649. 22:49account handling real customer data, you
  650. 22:51should almost always keep GuardDuty
  651. 22:54permanently enabled.
  652. 22:55The cost of running it is genuinely
  653. 22:58small compared to the massive value of
  654. 23:00catching a real security breach early.
  655. 23:02We are only disabling it because this is
  656. 23:05a practice lab account and not a real
  657. 23:07life production system.
  658. 23:09Also, keep a note of that to not show
  659. 23:12any real security findings in the
  660. 23:14LinkedIn or anywhere that exists in your
  661. 23:16personal AWS account. Only show the
  662. 23:19sample findings we generated together in
  663. 23:21the lab if you want to post anything in
  664. 23:23the LinkedIn or anywhere.
  665. 23:24All right. Fantastic work today. That
  666. 23:27was a lot of services actually.
  667. 23:29So, let's bring it all together with one
  668. 23:31final recap.
  669. 23:33Uh detection and assessment, we have
  670. 23:35GuardDuty, Inspector, Macie, Config.
  671. 23:38GuardDuty
  672. 23:39threat detection It is ML-powered and it
  673. 23:41watches for unusual and suspicious
  674. 23:43activity.
  675. 23:45Inspector is used for vulnerability
  676. 23:47scanning. It finds known CVs in your EC2
  677. 23:49instances, Lambda functions, and
  678. 23:51containers.
  679. 23:52Talking about Macie
  680. 23:54PII discovery in S3. It finds sensitive
  681. 23:56data like credit card numbers or SSNs.
  682. 24:00Config
  683. 24:02uh it tracks your compliance in history.
  684. 24:04It tracks every configuration change
  685. 24:06over the time.
  686. 24:07And talking about network defense, we
  687. 24:09have WAF
  688. 24:12Shield Standard, Shield Advanced.
  689. 24:15WAF is layer 7 web attack protection. It
  690. 24:18blocks SQL injection, XSS, and bad bots.
  691. 24:22Shield Standard, it is free automatic
  692. 24:24DDoS protection for everyone.
  693. 24:26And talking about Shield Advanced, it is
  694. 24:28a paid tier with a 24/7 DDoS response
  695. 24:31team and financial protection, as well.
  696. 24:34And we also discussed about encryption
  697. 24:36and invisibility thing. Encryption and
  698. 24:38invisibility, we have three services:
  699. 24:40KMS, Secrets Manager, and Security Hub.
  700. 24:43KMS is encryption key management, the
  701. 24:44engine behind encryption on S3, EBS,
  702. 24:47RDS, and more.
  703. 24:49Secrets Manager, it is automatically
  704. 24:51rotating secure storage for password and
  705. 24:53API keys.
  706. 24:54And we have Security Hub that is a
  707. 24:56centralized aggregator that pulls all
  708. 24:59these finding into one dashboard.
  709. 25:02So your homework for tonight, go
  710. 25:04complete 10 practice questions focus
  711. 25:05specifically on identifying the correct
  712. 25:07security service from the scenario.
  713. 25:10As you go through them, actively
  714. 25:11practice the keyword matching skill we
  715. 25:13built today. Look for the words like
  716. 25:15PII, unusual activity, vulnerability,
  717. 25:17SQL injection, DDoS rotation, and
  718. 25:20aggregated dashboard. These all things.
  719. 25:22Recognizing these trigger word instantly
  720. 25:24is what separates the confident exam day
  721. 25:26pass from a stressful guessing game.
  722. 25:28And take a look ahead to tomorrow.
  723. 25:31Day 17 takes us into the monitoring and
  724. 25:33infrastructure as code. We will be
  725. 25:34covering CloudWatch, CloudTrail, and
  726. 25:37CloudFormation.
  727. 25:38This is another AWS topic where
  728. 25:40beginners often confuse two very
  729. 25:43similarly named service, CloudWatch vs.
  730. 25:45CloudTrail.
  731. 25:46So we will make sure that distinction is
  732. 25:48also clear to
  733. 25:49Uh so that's a wrap for day 16. You now
  734. 25:52have a genuinely solid mental map of AWS
  735. 25:55entire security toolkit. You know
  736. 25:57exactly which tool detects what and
  737. 25:59which tool protects what. And also which
  738. 26:01tool ties it all together. And that's a
  739. 26:03huge exam critical skill you just built
  740. 26:05today. Great effort. Go get those
  741. 26:08practice question done and I will see
  742. 26:09you tomorrow for day 17. Keep pushing.
  743. 26:11You're doing brilliantly.

About this transcript

This page contains the full transcript of AWS Security Arsenal Explained | GuardDuty, Inspector, Macie, WAF & Shield | Day 16 by Pawan Joshi, generated from the public captions YouTube serves with the video. The transcript has 4,097 words across 743 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.

What you can do with it

Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.

Free YouTube transcript tool

YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.