DIAL: Did I just alert Lambda? A centralized security misconfiguration detection system

By Saransh Rana , Divyanshu Mehta , Harsh Varagiya on 04 Nov 2021 @ Ekoparty
πŸ’» Source Code πŸ“Ή Video πŸ”— Link
#aws #security-monitoring #iam #vulnerability-management #devsecops
Focus Areas: Security Operations & Defense , Application Security , Cloud Security , DevSecOps , Identity & Access Management , Vulnerability Management
This talk covers following tools where the speaker has contributed or authored
DIAL

Presentation Material

Abstract

DIAL: Did I just alert lambda?”, is a centralized monitoring and alerting system completely running stateless, which gives us end-to-end visibility on internal threats, security misconfigurations like database going public, over permissive IAM policies, happening across different AWS accounts. It runs on the top of AWS Lambda, thus making it infinitely scalable which is easily deployable across multiple AWS accounts.