This shows you the differences between two versions of the page.
Both sides previous revision Previous revision Next revision | Previous revision | ||
bucket_monitoring [2023/01/27 16:41] kaduuwikiadmin |
bucket_monitoring [2023/05/22 20:40] (current) |
||
---|---|---|---|
Line 1: | Line 1: | ||
- | ====== Bucket Monitoring ====== | + | ====== Bucket |
===== Introduction ===== | ===== Introduction ===== | ||
AWS S3 is an object storage service in the Amazon cloud. S3 allows both users and applications to save and retrieve practically any type of data that can be stored in its digital form. S3 data is saved in buckets. These are containers of software in which data can be stored and retrieved on an as-needed basis. Many enterprises continue to leave cloud storage buckets unprotected, | AWS S3 is an object storage service in the Amazon cloud. S3 allows both users and applications to save and retrieve practically any type of data that can be stored in its digital form. S3 data is saved in buckets. These are containers of software in which data can be stored and retrieved on an as-needed basis. Many enterprises continue to leave cloud storage buckets unprotected, | ||
+ | |||
+ | **The main S3 security risks** | ||
+ | |||
+ | Some of the most important S3 risks include: | ||
+ | |||
+ | - Configuration errors or failures that allow malicious users to access sensitive data in S3 buckets | ||
+ | - Lack of understanding of what data is stored in S3 buckets and if protection for that specific data is adequate | ||
+ | - Configuration problems that allow bad actors to upload malware to S3 buckets, and potentially create a baseline that they can use for further attacks | ||
===== How to search and monitor cloud storage? ===== | ===== How to search and monitor cloud storage? ===== | ||
Line 10: | Line 18: | ||
{{:: | {{:: | ||
+ | |||
+ | We suggest using the company name rather than the domain (example instead of example.com). But if the company name is too generic, you might end up with more than 5000 results. This is the limit we display per keyword. | ||
+ | |||
+ | |||
+ | ===== How can you see the results? ===== | ||
+ | |||
+ | After clicking on " | ||
+ | |||
+ | {{:: | ||
+ | |||
+ | ===== What data should you look for? ===== | ||
+ | |||
+ | Basically any senstive data. Ususally only the own company knows best what is considered senstive according to the data classification. In general it can be said that sensitive data is any data that should not be accessible to unauthorized persons. Sensitive data may include personally identifiable information (PII), such as social security numbers, financial information, | ||
+ | |||