news.mlab.sh
Back to the feed
threat-intel

Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility

High
Summary

This article from Palo Alto Unit 42 details how attackers are exploiting cloud logging services, specifically AWS CloudTrail and Google Cloud Logging, to evade detection and gain continuous visibility into target environments. Attackers achieve this by manipulating logging configurations, transferring logs to their own accounts, and disrupting the flow of information to security monitoring systems. Organizations need to understand these techniques to implement appropriate configurations and detect misuse of these services.

The report highlights two primary attack techniques: Defense Evasion, where attackers modify cloud logging service configurations to bypass detection, and Continuous Visibility, where attackers transfer logs to their own accounts to maintain ongoing surveillance of a target's environment. The analysis focuses on AWS CloudTrail and Google Cloud Logging, examining how attackers can manipulate these services to obscure their activities and extend their presence within a compromised cloud environment. The article explains the core components of each service – CloudTrail's trails and S3 buckets, and Google Cloud Logging's sinks and log buckets – and how attackers can leverage these to their advantage. It emphasizes the importance of robust security monitoring and incident response strategies to counter these evolving threats.

Read the full article at Palo Alto Unit 42