Cloud Security Podcast cover image

AWS INCIDENT RESPONSE - Automate Containment

Cloud Security Podcast

00:00

How to Contain an EC2 Instance

The idea for me for containing something is to completely break it and make it on you. So of course, I'm pretty sure there are people who are probably not going to agree with me on that statement,. "You don't want anyone to have access to it at all, unless of course there's security protections," he says. If your EC2 instance has network connectivity, which in most cases it will be, you want to remove all of the security groups and attach the denial all security group to it. That stops the attacker from trying to clean up their mess automatically. The last thing is that you want to stop it from running so that when you take that snapshot, it's not

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app