Breaking free from the chains of fate - Bypassing AWSCompromisedKeyQuarantineV2 Policy
gl4ssesbo1, Opie
BSides NYC 2024 · Day 1 · Tech - Red
This talk, "Breaking free from the chains of fate - Bypassing AWSCompromisedKeyQuarantineV2 Policy," delivered by gl4ssesbo1 and Opie (with initial research collaboration from Andrew Kraut) at BSides NYC, delves into the critical shortcomings of AWS's automated response to leaked credentials. The speakers meticulously analyze the `CompromisedKeyQuarantineV2` policy, which AWS attaches to identities suspected of compromise, and demonstrate numerous methods to bypass its intended protections. This research originated from a practical scenario involving honeypot configuration, highlighting a real-world problem.
AI review
Solid, original cloud security research that systematically dismantles a specific AWS defensive control most practitioners incorrectly trust. The policy-by-policy teardown is methodical and the findings are directly actionable — this isn't 'cloud security is hard' hand-waving, it's a specific mechanism dissected with specific API actions called out.