Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
Windows Tipps & SecurityGrafikkarte vor Überhitzung schützen: So geht’s(25.09.2026 um 08:00 Uhr)
••••••••••
Windows Tipps & SecurityGrafikkarte vor Überhitzung schützen: So geht’s(25.09.2026 um 08:00 Uhr)
••••••••••
Intelligence View
⚡ tsecurity.de Intelligence

Introducción a Amazon GuardDuty: Generar hallazgos de prueba

¡Hola a todos! 🚀 Hoy quiero compartir con ustedes un laboratorio para crear hallazgos de prueba en Amazon GuardDuty, un servicio de Amazon Web Services (AWS) diseñado para fortalecer la seguridad de nuestros recursos en la nube. 🧐 ¿Por qué…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!

¡Hola a todos! 🚀 Hoy quiero compartir con ustedes un laboratorio para crear hallazgos de prueba en Amazon GuardDuty, un servicio de Amazon Web Services (AWS) diseñado para fortalecer la seguridad de nuestros recursos en la nube.



🧐 ¿Por qué generar hallazgos de prueba?



Si eres nuevo en los servicios de AWS o quieres mejorar tu monitoreo de seguridad, esta práctica te permitirá:



✅ Comprender mejor las alertas de GuardDuty y cómo se generan.

✅ Interpretar la severidad de los hallazgos (bajo, medio, alto) y su impacto en la seguridad.

✅ Familiarizarte con los diferentes tipos de amenazas



Este laboratorio es una excelente manera de conocer cómo funciona GuardDuty antes de que se presenten amenazas reales🔒💡



🔥 Pues ¡Comencemos! 🔥



Primero debes entender que Amazon GuardDuty no se crea dentro de una VPC ni en un entorno específico. En su lugar, se habilita a nivel de cuenta en AWS y opera de forma independiente de la infraestructura de red.🔐



Cuando activas GuardDuty, este comienza a analizar fuentes de datos como:

✅ AWS CloudTrail (eventos de gestión y eventos de datos de S3).

✅ VPC Flow Logs (tráfico de red dentro de las VPCs).

✅ DNS Logs (consultas a servicios DNS).



Al estar habilitado a nivel de cuenta y región, puede detectar amenazas en múltiples servicios y VPCs sin necesidad de instalar agentes o modificar configuraciones de red.



Para comenzar, ingresa a la consola de AWS y en la barra de búsqueda escribe "Amazon GuardDuty". 🔍



1



Una vez dentro del servicio, verás la pantalla principal de GuardDuty con una d*escripción general de sus funciones.* Para activarlo, simplemente haz clic en el botón "Empezar". 🚀



2



Luego veremos una pantalla con información sobre "Enable GuardDuty" . En este paso, AWS nos explica que al habilitar GuardDuty, le estaremos otorgando permisos para analizar diferentes fuentes de datos de seguridad, como por ejemplo:



✅ VPC Flow Logs : Para detectar tráfico sospechoso en la red.

✅ AWS CloudTrail : Para identificar accesos inusuales o no autorizados.

✅ DNS Logs : Para analizar consultas a servicios DNS y detectar posibles ataques.



Para continuar, simplemente hacemos clic en "Enable GuardDuty"



3



Ahora, nos dirigimos al menú de la izquierda y seleccionamos "Settings" ⚙️. Dentro de esta sección, encontraremos la opción "Sample Findings", la cual nos permite generar hallazgos de prueba. Hacemos clic en "Generate Sample Findings"



En unos segundos veremos un mensaje de confirmación :✅

4



En la parte superior izquierda, hacemos clic en "Findings" 🔎, donde podremos ver todos los hallazgos generados. Estos se organizan según su severidad, tipo de hallazgo y recurso afectado 📊



Aquí encontraremos una variedad de hallazgos simulados , lo que nos permite analizar cada uno en detalle y comprender mejor cómo interpretar las alertas de seguridad en un entorno real.



5



Como por ejemplo el siguiente hallazgo:



🛑 Creación de una Shell Sospechosa en un Clúster de EKS

6



📌 Descripción: GuardDuty ha detectado que en un clúster de Amazon EKS se ha iniciado una shell interactiva dentro de un contenedor en ejecución. Este comportamiento nos puede indicar que existe acceso manual no autorizado o de actividad potencialmente maliciosa.



⚠️ Detalles del hallazgo:



Tipo: Execution:Runtime/SuspiciousShellCreated

Recurso afectado: Clúster de Amazon EKS

Severidad: Baja

Cantidad de eventos: 1



🔍 Posibles causas:

✅ Acceso manual legítimo para tareas administrativas o debugging.

⚠️ Acceso no autorizado debido a credenciales comprometidas.

⚠️ Uso indebido de un contenedor explotado mediante vulnerabilidades.



Muy interesante, verdad? 😃👨

Te invito a seguir explorando y familiarizarte con la herramienta. ¡Entre más practiques, mejor entenderás la seguridad en AWS! 🔐🔥



¡Es una gran oportunidad para aprender y fortalecer la seguridad en AWS! 🚀🔐

1. Sofort-Triage & Abwehrmaßnahmen

SOC Incident Playbook: Vulnerability Remediation & Verification
Syntax validiert (0 Fehler)
title: Detect Exploitation - Introducción a Amazon GuardDuty: Generar hallazgos de prueba
id: 6545f473-3783-4bd9-83d1-ed9cafbb0c01
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
  - https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-25
logsource:
  category: network_connection
  product: any
detection:
  selection:
      CommandLine|contains:
        - 'exploit'
  condition: selection
falsepositives:
  - Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
  - attack.initial_access
Syntax validiert (0 Fehler)
rule CTI_Threat_Indicator {
    meta:
        author = "iShareStuff CTI Automated Detection Engine"
        date = "2026-09-25"
        description = "YARA Signature for "
    strings:
        $str = "Introducción a Amazon GuardDut" ascii wide
    condition:
        any of them
}
Syntax validiert (0 Fehler)
index=security sourcetype IN ("cisco:asa", "pan:traffic", "zeek_conn", "suricata", "WinEventLog:Security")
("Introduccin a Amazon GuardDuty Generar h")
| stats count earliest(_time) as first_seen latest(_time) as last_seen by src_ip, dest_ip, dest_host, signature
| eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S")
| sort - count
Syntax validiert (0 Fehler)
message: "*Introduccin a Amazon GuardDuty Generar h*"
Syntax validiert (0 Fehler)
CommonSecurityLog
| where Message has "Introduccin a Amazon GuardDuty Generar h"
| summarize EventCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by SourceIP, DestinationIP, DestinationPort, Activity
| extend DetectionRule = "iShareStuff-CTI-Compiled"
| sort by EventCount desc

2. Cyber Threat Intelligence & Forensik

CTI Threat Relationship Graph2 Knoten / 1 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
🎯
MITRE ATT&CK Matrix Navigator 14 Taktiken
Reconnaissance
-
Resource Development
-
Initial Access
Execution
Persistence
-
Privilege Escalation
Defense Evasion
Credential Access
-
Discovery
-
Lateral Movement
-
Collection
-
Command and Control
Exfiltration
-
Impact
tsecurity.de Cognitive Threat RAG
Fokus-Vektor:

Kognitive Analyse für identifizierte Bedrohung: Erhöhte Bedrohungslage im Bereich Introducción a Amazon GuardDuty: Generar.... Basierend auf 368k Vektor-Korrelationen werden sofortige Isolationsmaßnahmen für betroffene Endpunkte empfohlen.

🛡️ Angriffsfläche & Exposure

Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.

⚡ Empfohlene Sofortmaßnahmen
  • 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
  • 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
  • 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
🔗 Semantisch verwandte Zero-Days MariaDB 11.7 VEC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Introducción a Amazon GuardDuty: Generar hallazgos de prueba

Thematisch verwandte Begriffe: Introducción, Amazon, GuardDuty, Generar · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-61525 | Zammad is a web based open source helpdesk/customer support system. In 7…
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag