VPC Flow Logs capture information about IP traffic flowing through your VPC's network interfaces. Each flow log record includes source/destination IP, ports, protocol, packet count, byte count, and whether the traffic was accepted or rejected.
An isolated virtual network within AWS where you launch resources, with full control over IP addressing, subnets, route tables, and network gateways.
A chronological record of all activities in an AWS account (API calls, logins, configuration changes) used for security investigation and compliance evidence.
AWS managed threat detection service that continuously monitors your accounts for malicious activity using CloudTrail, VPC Flow Logs, and DNS logs.
Dividing a network into isolated segments (subnets, VPCs) to limit lateral movement and contain the blast radius of a security breach.
Toc Consulting: AWS Security & Cloud Architecture
Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.