AWS Security Blog

Tag: HAQM S3

Using HAQM GuardDuty Malware Protection to scan uploads to HAQM S3

HAQM Simple Storage Service (HAQM S3) is a widely used object storage service known for its scalability, availability, durability, security, and performance. When sharing data between organizations, customers need to treat incoming data as untrusted and assess it for malicious files before ingesting it into their downstream processes. This traditionally requires setting up secure staging […]

Enhance container software supply chain visibility through SBOM export with HAQM Inspector and QuickSight

In this post, I’ll show how you can export software bills of materials (SBOMs) for your containers by using an AWS native service, HAQM Inspector, and visualize the SBOMs through HAQM QuickSight, providing a single-pane-of-glass view of your organization’s software supply chain. The concept of a bill of materials (BOM) originated in the manufacturing industry […]

HAQM Macie

Detect Stripe keys in S3 buckets with HAQM Macie

Many customers building applications on HAQM Web Services (AWS) use Stripe global payment services to help get their product out faster and grow revenue, especially in the internet economy. It’s critical for customers to securely and properly handle the credentials used to authenticate with Stripe services. Much like your AWS API keys, which enable access […]

HAQM Macie

How to use HAQM Macie to reduce the cost of discovering sensitive data

April 3, 2023: This post had been edited to get Figure 3 updated. HAQM Macie is a fully managed data security service that uses machine learning and pattern matching to discover and help protect your sensitive data, such as personally identifiable information (PII), payment card data, and HAQM Web Services (AWS) credentials. Analyzing large volumes […]

The anatomy of ransomware event targeting data residing in HAQM S3

Ransomware events have significantly increased over the past several years and captured worldwide attention. Traditional ransomware events affect mostly infrastructure resources like servers, databases, and connected file systems. However, there are also non-traditional events that you may not be as familiar with, such as ransomware events that target data stored in HAQM Simple Storage Service […]

How to query and visualize Macie sensitive data discovery results with Athena and QuickSight

February 21, 2023: We’ve updated the CREATE TABLE DDL to add the new originType field introduced as part of the Automated Sensitive Data Discovery feature of Macie. HAQM Macie is a fully managed data security service that uses machine learning and pattern matching to help you discover and protect sensitive data in HAQM Simple Storage Service (HAQM S3). With […]

AWS CIRT announces the release of five publicly available workshops

Greetings from the AWS Customer Incident Response Team (CIRT)! AWS CIRT is dedicated to supporting customers during active security events on the customer side of the AWS Shared Responsibility Model. Over the past year, AWS CIRT has responded to hundreds of such security events, including the unauthorized use of AWS Identity and Access Management (IAM) […]

Figure 1: Architecture diagram of the export function

How to export AWS Security Hub findings to CSV format

December 22, 2022: We are working on an update to address issues related to cloudformation stack deployment in regions other than us-east-1, and Lambda timeouts for customers with more than 100,000 findings. AWS Security Hub is a central dashboard for security, risk management, and compliance findings from AWS Audit Manager, AWS Firewall Manager, HAQM GuardDuty, […]

Top 2021 AWS service launches security professionals should review – Part 2

In Part 1 of this two-part series, we shared an overview of some of the most important 2021 HAQM Web Services (AWS) Security service and feature launches. In this follow-up, we’ll dive deep into additional launches that are important for security professionals to be aware of and understand across all AWS services. There have already […]

Top 10 security best practices for securing data in HAQM S3

With more than 100 trillion objects in HAQM Simple Storage Service (HAQM S3) and an almost unimaginably broad set of use cases, securing data stored in HAQM S3 is important for every organization. So, we’ve curated the top 10 controls for securing your data in S3. By default, all S3 buckets are private and can […]