Product
medium
advisory
Detection of Unauthorized AWS Route 53 Private Hosted Zone Associations
1 rule 3 TTPsAdversaries with high-level IAM permissions may associate unauthorized VPCs with AWS Route 53 private hosted zones to intercept internal DNS traffic, establish persistence, or perform reconnaissance.
AWS Route 53
aws
cloud
persistence
route53
1r
3t
high
advisory
AWS Security Services Impairment via Deletion Operations
3 rules 1 TTPAttackers attempt to impair or disable AWS security services such as GuardDuty, WAF, CloudWatch, Route 53 and CloudWatch Logs by deleting detectors, rule groups, IP sets, web ACLs, logging configurations, alarms and log streams, in order to evade detection and operate undetected.
AWS GuardDuty +4
aws
cloudtrail
defense-evasion
3r
1t