Glossary

    Security Incident

    Incident Response

    A Security Incident is any event that actually or potentially jeopardizes the confidentiality, integrity, or availability of your information systems or data.

    Common AWS Security Incidents

    • Credential Compromise: leaked access keys, stolen session tokens
    • Data Exposure: public S3 buckets, misconfigured security groups exposing databases
    • Unauthorized Access: root account usage, privilege escalation, lateral movement
    • Malware/Cryptomining: compromised EC2 instances running unauthorized workloads
    • DDoS Attacks: volumetric or application-layer attacks on public endpoints
    • Supply Chain: compromised dependencies, malicious Lambda layers, container image tampering

    AWS Resources for Incident Response

    • AWS Security Incident Response: managed service (launched re:Invent 2024) with triage and investigation support
    • AWS Abuse Reports: report compromise to AWS via the abuse form
    • GuardDuty: automated threat detection and initial triage
    • Detective: investigation and root cause analysis
    • CloudTrail: forensic evidence of API activity

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.