<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>GuardDuty &#8211; Noise</title>
	<atom:link href="https://noise.getoto.net/tag/guardduty/feed/" rel="self" type="application/rss+xml" />
	<link>https://noise.getoto.net</link>
	<description>The collective thoughts of the interwebz</description>
	<lastBuildDate>Mon, 28 Jul 2025 15:45:16 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>
	<item>
		<title>How to automatically disable users in AWS Managed Microsoft AD based on GuardDuty findings</title>
		<link>https://noise.getoto.net/2025/07/28/how-to-automatically-disable-users-in-aws-managed-microsoft-ad-based-on-guardduty-findings/</link>
		
		<dc:creator><![CDATA[Tim Kingdon]]></dc:creator>
		<pubDate>Mon, 28 Jul 2025 15:45:16 +0000</pubDate>
				<category><![CDATA[Advanced (300)]]></category>
		<category><![CDATA[Amazon GuardDuty]]></category>
		<category><![CDATA[GuardDuty]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<category><![CDATA[Technical How-to]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=e3789531490ee01f4c1a3f9a9b8e13e3</guid>

					<description><![CDATA[Organizations are facing an increasing number of security threats, especially in the form of compromised user accounts. Manually monitoring and acting on suspicious activities is not only time-consuming but also prone to human error. The lack of automated responses to security incidents can lead to disastrous consequences, such as data breaches and financial loss. In […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Mapping AWS security services to MITRE frameworks for threat detection and mitigation</title>
		<link>https://noise.getoto.net/2025/05/13/mapping-aws-security-services-to-mitre-frameworks-for-threat-detection-and-mitigation/</link>
		
		<dc:creator><![CDATA[Pratima Singh]]></dc:creator>
		<pubDate>Tue, 13 May 2025 15:49:20 +0000</pubDate>
				<category><![CDATA[Advanced (300)]]></category>
		<category><![CDATA[Amazon GuardDuty]]></category>
		<category><![CDATA[GuardDuty]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<category><![CDATA[threat detection]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=f23730ab7e14dc4f7512c1090de4956a</guid>

					<description><![CDATA[In the cloud security landscape, organizations benefit from aligning their controls and practices with industry standard frameworks such as MITRE ATT&#38;CK®, MITRE EngageTM, and MITRE D3FENDTM. MITRE frameworks are structured, openly accessible models that document threat actor behaviors to help organizations improve threat detection and response. Figure 1: Interaction between the various MITRE frameworks Figure […]]]></description>
		
		
		<enclosure url="https://archive.org/details/Shmoocon-2022/Shmoocon2022-Karen_Lamb%2C_Gabby_Raymond%2C_%26_Maretta_Morovitz-She_doesn%E2%80%99t_even_go_here.mp4" length="0" type="video/mp4" />

			</item>
		<item>
		<title>How to generate security findings to help your security team with incident response simulations</title>
		<link>https://noise.getoto.net/2024/04/01/how-to-generate-security-findings-to-help-your-security-team-with-incident-response-simulations/</link>
		
		<dc:creator><![CDATA[Jonathan Nguyen]]></dc:creator>
		<pubDate>Mon, 01 Apr 2024 16:00:03 +0000</pubDate>
				<category><![CDATA[Amazon GuardDuty]]></category>
		<category><![CDATA[Amazon Inspector]]></category>
		<category><![CDATA[AWS Security Hub]]></category>
		<category><![CDATA[GuardDuty]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[Intermediate (200)]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security Hub]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<category><![CDATA[siem]]></category>
		<category><![CDATA[Technical How-to]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=8c97075f59c231e83f871edc4bc3b704</guid>

					<description><![CDATA[Continually reviewing your organization’s incident response capabilities can be challenging without a mechanism to create security findings with actual Amazon Web Services (AWS) resources within your AWS estate. As prescribed within the AWS Security Incident Response whitepaper, it’s important to periodically review your incident response capabilities to make sure your security team is continually maturing […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Security at multiple layers for web-administered apps</title>
		<link>https://noise.getoto.net/2023/11/28/security-at-multiple-layers-for-web-administered-apps/</link>
		
		<dc:creator><![CDATA[Guy Morton]]></dc:creator>
		<pubDate>Tue, 28 Nov 2023 14:26:37 +0000</pubDate>
				<category><![CDATA[Advanced (300)]]></category>
		<category><![CDATA[Amazon CloudFront]]></category>
		<category><![CDATA[Amazon GuardDuty]]></category>
		<category><![CDATA[Amazon Virtual Private Cloud (Amazon VPC)]]></category>
		<category><![CDATA[Amazon VPC]]></category>
		<category><![CDATA[AWS GuardDuty]]></category>
		<category><![CDATA[AWS IAM]]></category>
		<category><![CDATA[AWS VPC]]></category>
		<category><![CDATA[Best practices]]></category>
		<category><![CDATA[Elastic Load Balancing]]></category>
		<category><![CDATA[GuardDuty]]></category>
		<category><![CDATA[IAM]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<category><![CDATA[VPC]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=2f247f1df2ae5bc9939bae8a0304267e</guid>

					<description><![CDATA[In this post, I will show you how to apply security at multiple layers of a web application hosted on AWS. Apply security at all layers is a design principle of the Security pillar of the AWS Well-Architected Framework. It encourages you to apply security at the network edge, virtual private cloud (VPC), load balancer, […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Now available: Building a scalable vulnerability management program on AWS</title>
		<link>https://noise.getoto.net/2023/10/12/now-available-building-a-scalable-vulnerability-management-program-on-aws/</link>
		
		<dc:creator><![CDATA[Anna McAbee]]></dc:creator>
		<pubDate>Thu, 12 Oct 2023 16:35:05 +0000</pubDate>
				<category><![CDATA[Amazon Inspector]]></category>
		<category><![CDATA[announcements]]></category>
		<category><![CDATA[AWS security]]></category>
		<category><![CDATA[cloud security]]></category>
		<category><![CDATA[cybersecurity program]]></category>
		<category><![CDATA[Foundational (100)]]></category>
		<category><![CDATA[GuardDuty]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security Hub]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<category><![CDATA[Technical How-to]]></category>
		<category><![CDATA[Vulnerability management]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=ee2ebc73aa75c1831ef198f7c1b1c183</guid>

					<description><![CDATA[Vulnerability findings in a cloud environment can come from a variety of tools and scans depending on the underlying technology you’re using. Without processes in place to handle these findings, they can begin to mount, often leading to thousands to tens of thousands of findings in a short amount of time. We’re excited to announce […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>How to investigate and take action on security issues in Amazon EKS clusters with Amazon Detective – Part 2</title>
		<link>https://noise.getoto.net/2022/12/05/how-to-investigate-and-take-action-on-security-issues-in-amazon-eks-clusters-with-amazon-detective-part-2/</link>
		
		<dc:creator><![CDATA[Marshall Jones]]></dc:creator>
		<pubDate>Mon, 05 Dec 2022 18:05:29 +0000</pubDate>
				<category><![CDATA[Containers]]></category>
		<category><![CDATA[Detective]]></category>
		<category><![CDATA[EKS]]></category>
		<category><![CDATA[GuardDuty]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[Intermediate (200)]]></category>
		<category><![CDATA[Kubernetes]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<category><![CDATA[Technical How-to]]></category>
		<category><![CDATA[threat detection]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=18dc4c919f857ca53cc9cb1dacd9028b</guid>

					<description><![CDATA[In part 1 of this of this two-part series, How to detect security issues in Amazon EKS cluster using Amazon GuardDuty, we walked through a real-world observed security issue in an Amazon Elastic Kubernetes Service (Amazon EKS) cluster and saw how Amazon GuardDuty detected each phase by following MITRE ATT&#38;CK tactics. In this blog post, […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>How to detect security issues in Amazon EKS clusters using Amazon GuardDuty – Part 1</title>
		<link>https://noise.getoto.net/2022/11/22/how-to-detect-security-issues-in-amazon-eks-clusters-using-amazon-guardduty-part-1/</link>
		
		<dc:creator><![CDATA[Marshall Jones]]></dc:creator>
		<pubDate>Tue, 22 Nov 2022 18:39:46 +0000</pubDate>
				<category><![CDATA[Containers]]></category>
		<category><![CDATA[Detective]]></category>
		<category><![CDATA[EKS]]></category>
		<category><![CDATA[GuardDuty]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[Intermediate (200)]]></category>
		<category><![CDATA[Kubernetes]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<category><![CDATA[Technical How-to]]></category>
		<category><![CDATA[threat detection]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=a59d7f245cd747cc901180d64ede7006</guid>

					<description><![CDATA[In this two-part blog post, we’ll discuss how to detect and investigate security issues in an Amazon Elastic Kubernetes Service (Amazon EKS) cluster with Amazon GuardDuty and Amazon Detective. Amazon Elastic Kubernetes Service (Amazon EKS) is a managed service that you can use to run and scale container workloads by using Kubernetes in the AWS […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 58/167 objects using Memcached
Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Database Caching using Memcached

Served from: noise.getoto.net @ 2025-12-05 10:15:51 by W3 Total Cache
-->