Silence of the Logs: Detecting Defense Impairment in AWS and Azure
Details
When attackers get their hands on privileged credentials in cloud environments, their first move is rarely the big flashy action we expect. Instead, they're quietly turning off the alarms. Defense impairment has become a go-to tactic for adversaries who want to operate undetected in AWS and Azure environments, and it's working because teams aren't watching for it.
This talk will walk through real-world defense impairment techniques across AWS and Azure. We'll dig into what it looks like when attackers suppress their own IPs in GuardDuty, redirect CloudTrail logs to buckets they control, tamper with Azure diagnostic settings, or disable Defender entirely. More importantly, we'll focus on how to catch them doing it.
Attendees will leave with practical detections they can implement immediately and a better understanding of the logging bottlenecks that matter most when adversaries are trying to go dark in your cloud environment.
Speaker bio:
Ryan Thompson is a Certified Instructor at SANS Institute and Senior Cloud Security Researcher at CrowdStrike. His role involves researching and emulating adversary activity across AWS and Azure, building proof-of-concept solutions for threat hunting, and developing innovative detection capabilities within the cloud control plane. With a strong foundation in cybersecurity, marked by a long list of GIAC certifications, Ryan’s expertise and educational approach make him exceptionally qualified to teach and mentor the current and next generation of cybersecurity professionals.
6:00 - 6:30 pm: Mix, mingle, announcements and intro
6:40 - 8:00 pm: Main talk (let's go!)
8:00+ pm: (Optional) Dinner/drinks at Union
