Home
Talks
CFP Guide
What is BSides?
About
Contact
Light
← All talks
Tool
BSides talks featuring AWS CloudTrail
84
talks mention this tool across
40
BSides chapters.
Talks featuring AWS CloudTrail
46:38
How to 10X Your Company's Security (Without a Series D)
Clint Gibler
BSidesSF
· 2020
Technical
Cloud IAM
DevSecOps
Threat Modeling
Blue
Talk
Open →
2020-03
28:23
AWS vs Azure Security
Paul Schwarzenberger
BSides London
· 2019
Technical
Cloud IAM
Talk
Open →
2019-06
20:01
Fantastic AWS Attacks and Where to Find Them
Georgios Kapoglis
BSidesSF
· 2020
Technical
Cloud IAM
Talk
Open →
2020-03
37:14
Understanding, Abusing and Monitoring AWS AppStream 2.0
Rodrigo Montoro
BSides Las Vegas
· 2022
Technical
Cloud IAM
Detection Engineering
Talk
Open →
2022-09
43:27
Threat Hunting AWS CloudTrail Logs with Microsoft Sentinel: Real-Time Attack Demo
Arijit Paul
BSides Sydney
· 2025
Technical
Cloud IAM
Detection Engineering
Threat Intel
Intermediary
Demo
Open →
2025-02
8:38:00
Cyber Crash Investigations: Seizing the Opportunity to Learn from Fast Crisis
Julia Wigton
David Stokes
BSides Las Vegas
· 2023
Research
Case Studies and Incidents Analysis
Methodology
Talk
Open →
2023-08
24:59
Logging, Monitoring, and Alerting in AWS (The TL;DR)
Jonathon Poling
BSidesSF
· 2018
Technical
Blue
Talk
Open →
2018-04
1:04:06
Inside Cloud Security Essentials with Shashank Dubey
Shashank Dubey
Karthik VMA
BSides Noida
· 2024
Career
Technical
Intro
Talk
Open →
2024-11
46:17
Let's Start Over!
Craig Chamberlain
BSides DC
· 2018
Technical
Demo
Open →
2018-11
24:30
Realtime Cyber Alerting with StreamAlert
Jeremy Stott
BSides Wellington
· 2017
Technical
Blue
Demo
Talk
Open →
2018-02
32:23
WhizBangLambdaFix: where AWS Misconfigurations meet Auto-Fix-It Antics
Lily Chau
Lakshmanan Murthy
BSidesSF
· 2024
Technical
Cloud IAM
Open →
2024-07
50:02
Hunting Supply Chain Threats Using Anomaly Detection
Craig Chamberlain
BSidesSF
· 2023
Technical
Cloud IAM
Detection Engineering
Supply Chain Security
Case Studies and Incidents Analysis
Methodology
Talk
Open →
2023-05
22:12
Launch Control — Automating a Security Baseline in the Cloud at Scale
David Levitsky
Olivia Hillman
BSidesSF
· 2023
Technical
Cloud IAM
Demo
Talk
Open →
2023-05
29:35
The Bucket List: Experiences Operating S3 Honeypots
Cameron Ero
BSidesSF
· 2018
Research
Cloud IAM
Threat Intel
Blue
Case Studies and Incidents Analysis
Technical Deep-dives
Talk
Open →
2018-04
5:42:35
BSides Prishtina 2025 - Day 2 Live
BSides Prishtina
· 2025
Technical
Talk
Open →
2025-04
30:06
BSidesSF 2024 - Effective Detection in Kubernetes Clusters (Shay Berkovich, Oren Ofer)
Shay Berkovich
Oren Ofer
BSidesSF
· 2024
Technical
Talk
Open →
2024-07
32:15
Security Lessons Learnt From The Cloud Frontline - Ben Fletcher
Ben Fletcher
BSides Belfast
· 2024
Technical
Cloud IAM
Detection Engineering
Threat Intel
Case Studies and Incidents Analysis
Talk
Open →
2024-03
36:45
BG - Lateral Movement and other Creative Steps Attackers Take in AWS
BSides Las Vegas
Open →
2022-09
52:41
Secure Key Management in the Cloud
Omer Farooq
BSides DC
· 2017
Technical
Cloud IAM
Cryptography
Talk
Open →
2017-10
56:03
Cassandra Young - The Complete Noobs Guide to Cloud Security
BSides Philly
Open →
2020-12
28:11
Home Labs Without Hardware: Building in the Cloud
Chris Myers
BSides Philly
· 2020
Technical
Talk
Open →
2020-12
39:44
Honeypot Boo Boo: Better Breach Detection With Deception Inception
Justin Varner
BSides Dundee
· 2022
Technical
Blue
Talk
Open →
2022-08
24:38
Cloudy With a Chance of Purple Rain: Leveraging Stratus Red Team to Secure Your Clouds
Luciano Avendano
BSides PDX
· 2022
Technical
Cloud IAM
Detection Engineering
Threat Modeling
Purple
Demo
Talk
Open →
2022-10
23:29
The Dark Side of Cloud-Based Database Engines
Ofir Balassiano
Ofir Shaty
BSides TLV
· 2023
Technical
Cloud IAM
Red
Talk
Open →
2023-07
28:51
JIT Happens: How Instacart Uses AI to Keep Doors Open and Risks Closed
Dominic Zanardi
Matthew Sullivan
BSides Las Vegas
Technical
AI Security
Cloud IAM
Blue
Demo
Open →
2024-09
21:55
How to Secure Cloud Machine Identities
Komal Dhull
Nathan Brahms
BSidesSF
· 2024
Technical
Cloud IAM
Talk
Open →
2024-07
28:31
AiIAM: Transforming the Democratized AWS IAM Architecture with LLMs
Anthony Scheller
Jorge L Gomez
BSidesSF
· 2024
Technical
Cloud IAM
Talk
Open →
2024-07
13:14
Metabadger: Automating IMDS Protection at Scale in AWS
Ashish Patel
BSidesSF
· 2022
Technical
Cloud IAM
Talk
Open →
2022-07
18:40
Everyday AI: Leveraging LLMs for Simple, Effective Security Automation
Matthew Sullivan
Dominic Zanardi
BSidesSF
· 2025
Technical
AI Security
Cloud IAM
Detection Engineering
Talk
Open →
2025-10
51:44
Zero Trust — Attack and Defend
Aaron Jewitt
BSides Frankfurt
· 2024
Technical
Cloud IAM
Detection Engineering
Purple
Talk
Open →
2025-05
49:19
Who Goes There? Actively Detecting Intruders With Cyber Deception Tools
Dwayne Mcdaniel
BSides Boulder
· 2024
Technical
Talk
Open →
2024-09
49:11
Rami McCarthy - AWS Security: Easy Wins and Enterprise Scale
Rami McCarthy
BSides Boston
· 2020
Technical
Cloud IAM
Supply Chain Security
Talk
Open →
2020-11
31:52
BSidesSLC 2015 -- Pragmatic Cloud Security -- Joshua Danielson
BSides SLC
Open →
2015-04
41:13
Automating disk and memory evidence collection in AWS
Ryan Tick
Vaishnav Murthy
BSides SATX
· 2020
Technical
Purple
Talk
Open →
2020-08
49:49
Cloud Breach Incident Response & Forensics
Michael T. Raggo
Bsides CT
· 2020
Technical
Cloud IAM
Case Studies and Incidents Analysis
Talk
Open →
2020-11
46:27
Whose Encryption Key Is This? It's a Secret to Everybody
David Levitsky
Matthew J Lorimor
BSides Las Vegas
· 2022
Technical
Cloud IAM
Cryptography
Talk
Open →
2022-09
39:59
Cloud Warfare: Grappling With Scattered Spider - Abian Morina and Andi Ahmeti
Abian Morina
Andi Ahmeti
BSides Tirana
· 2025
Technical
Talk
Open →
2024-10
52:52
BSidesAugusta 2017 - Track2: Security Automation in the cloud by Toni de la Fuente
BSides Augusta
Open →
2017-09
25:23
How Attackers Can Use KMS to Ransomware S3 Buckets - Bleon Proko
Bleon Proko
BSides Prishtina
Technical
Cloud IAM
Talk
Open →
2024-09
37:30
Chasing a red team from the dressing room into the cloud
Tyler Fornes
BSides Dallas/Fort Worth
· 2020
Technical
Cloud IAM
DFIR
Detection Engineering
Blue
Purple
Case Studies and Incidents Analysis
Talk
Open →
2020-11
39:18
Big SIEM Energy at Micro-SIEM Cost
Kenneth Kaye
BSides Las Vegas
Technical
Cloud IAM
Detection Engineering
Demo
Talk
Open →
2023-10
27:04
BSides Toronto 2019 Harish Ramadoss
BSides Toronto
Open →
2019-10
46:18
Home Alone isn’t scary, it’s inspiration - Dev Dua, Tyron Kemp, Denver Abrey
BSides Cape Town
Open →
2023-09
37:36
Breaking The Cloud: A Tale Of 3 Breaches
Ashish Rajan
BSides London
Technical
Talk
Open →
2024-02
25:57
How Attackers Can Use KMS To Ransomware S3 Buckets
Bleon Proko
BSides Tirana
· 2023
Technical
Cloud IAM
Talk
Open →
2023-11
37:04
Terraform Security: Attacking and Defending Infrastructure as Code
Michael McCabe
BSides Philly
· 2023
Technical
Cloud IAM
DevSecOps
Vulnerability Research
Technical Deep-dives
Talk
Open →
2024-01
24:43
Building Real-Time AWS Guardrails: A Serverless, Homegrown Engineering Blueprint
Aleksei Denisov
BSides Seattle 2026
Technical
Cloud IAM
DevSecOps
Intermediary
Blue
Technical Deep-dives
Talk
Open →
2026-04
37:12
BSides Sofia 2022: Common security pitfalls in AWS Public cloud for highly regulated industries
Daniel Rankov
BSides Sofia
· 2022
Technical
Talk
Open →
2022-04
52:10
Cloud Security
Scott Arveseth
BSides SLC
· 2015
Technical
Talk
Open →
2015-04
36:47
Tim Crothers - Living off the (land)cloud: Scattered Spider and the cloud control plane
Tim Crothers
BSides Augusta
· 2025
Technical
Cloud IAM
Blue
Red
Demo
Talk
Open →
2025-10
55:29
Trust Chain: How to imagine and realize multi-organization Cloud Environment
Omer Farooq
BSides DC
· 2018
Technical
Cloud IAM
Talk
Open →
2018-11
45:11
Attacking Modern SaaS Companies
Sean Cassidy
BSidesROC
· 2017
Technical
Talk
Open →
2018-01
17:10
From Keyless to Careless: Abusing Misconfigured OIDC Authentication in Cloud Environments
Christophe Tafani-Dereeper
BSides Las Vegas
· 2024
Technical
CI/CD Security
Cloud IAM
Vulnerability Research
Intermediary
Red
Case Studies and Incidents Analysis
Technical Deep-dives
+1
Open →
2024-09
30:53
Building an Auto-Remediation Platform for the Cloud
Taylor Wilson
BSides SLC
· 2022
Technical
Talk
Open →
2023-01
32:20
Secure(r) Cloud Development
Christo Goosen
Toufeeq Ockards
BSides Cape Town
· 2017
Technical
Cloud IAM
Detection Engineering
DevSecOps
Talk
Open →
2017-12
37:35
When Cloud Infrastructure Provisioned With Someone in Marketing's Credit Card Is Compromised
Aaron Shelmire
BSides Peru
· 2023
Technical
Cloud IAM
DFIR
Blue
Talk
Open →
2023-08
38:33
Cloud Storage and Ransomware Attacks
Velizar Demirev
BSidesROC
· 2025
Technical
Cloud IAM
DFIR
Malware Analysis
Talk
Open →
2025-03
47:47
Hiding Malware in Docker Images for AWS Hardcore Persistence and Defense Evasion
Santiago Abastante
BSides Zagreb
Technical
Cloud IAM
Container Security
Malware Analysis
Advanced
Red
Talk
Open →
2025-03
44:22
Guardrails in the Cloud
Rohini Sulatycki
BSides Tampa
· 2021
Technical
Cloud IAM
Talk
Open →
2021-04
24:44
Cloud IR: A Rapid Guide For AWS, Azure & GCP
Erblind Morina
BSides Munich
· 2025
Technical
Cloud IAM
DFIR
Detection Engineering
Blue
Talk
Open →
2026-02
22:34
The Phantom of the Infrastructure: Investigating Hidden IAM Risks in Bedrock API Keys
Sergio Garcia
BSides Seattle
· 2026
Technical
AI Security
Cloud IAM
Technical Deep-dives
Talk
Open →
2026-03
46:56
Building Castles in the Cloud: AWS Security and Self-Assessment
Rami McCarthy
Bsides CT
· 2019
Technical
Cloud IAM
Talk
Open →
2019-11
43:50
Considering Cloud Coverage in SIEM/XDR Design
Chris Beckman
BSides SLC
· 2025
Technical
Cloud IAM
Detection Engineering
Threat Modeling
Blue
Talk
Open →
2025-06
16:42
Building Secure Machine Learning Environments in Amazon SageMaker
Uendi Hoxha
BSides Tirana
· 2024
Technical
AI Security
Cloud IAM
Talk
Open →
2024-10
34:00
Oops, I Leaked It Again — How We Found PII in Exposed RDS Snapshots
Doron Karmi
Ariel Szarf
BSides Las Vegas
Research
Case Studies and Incidents Analysis
Empirical Research
Talk
Open →
2023-10
51:33
DIY Cyber Threat Intelligence
Mark Hahn
Thomas Hahn
BSides Seattle
· 2025
Technical
Cloud IAM
DevSecOps
Threat Intel
Demo
Open →
2025-06
20:36
Essential Logs Pyramid SIEM
Eric Goldstrom
BSides PDX
· 2023
Technical
Detection Engineering
Threat Intel
Blue
Talk
Open →
2023-10
51:04
The Hole in Your SOC: How a compromise of your SIEM could be a disaster for your organization
Michael Music
BSides Tampa
· 2021
Technical
Active Directory
Cloud IAM
Detection Engineering
Kerberos
Threat Intel
Talk
Open →
2021-04
37:17
Improving Response by being "Data Wrangling" Amateurs in AWS
Swetha Balla
BSides Budabest
· 2021
Technical
Cloud IAM
Case Studies and Incidents Analysis
Talk
Open →
2022-03
46:38
Getting started with Security in AWS
Zack Glick
BSides Buffalo
· 2022
Technical
Cloud IAM
Intro
Talk
Open →
2022-06
17:55
Vector Search for Security Operations Centers: Yay or Nay?
Filip Žagar
BSides Zagreb
· 2025
Technical
Detection Engineering
Threat Intel
Talk
Open →
2025-03
33:38
GF - The Art of Letting Go: Secure delegation of permissions in AWS environments
BSides Las Vegas
Open →
2023-10
23:12
Breaking free from the chains of fate: Bypassing AWSCompromisedKeyQuarantineV2 Policy
Andrew Kraut
BSides Albuquerque
Technical
Cloud IAM
Talk
Open →
2024-08
27:52
The Perks And Perils Of Persistence: AWS Attacker Techniques
Oisin Brennan
BSides Munich
· 2025
Technical
Cloud IAM
Red
Technical Deep-dives
Talk
Open →
2026-02
1:03:38
Hunting Supply Chain Threats
Craig Chamberlain
BSidesROC
· 2023
Technical
Supply Chain Security
Case Studies and Incidents Analysis
Talk
Open →
2024-09
37:00
A Shock to the System: Static Analysis for Real AppSec
Ochaun Marshall
BSides RDU
· 2021
Technical
Web AppSec
Talk
Open →
2021-10
41:39
Threat Detection Across All Environments with Snowflake Data Security Lake
Andy Bryan
Shannon Taylor
BSides Huntsville
Technical
Blue
Demo
Open →
2021-02
45:06
Does Serverless Mean Harmless?
Tal Melamed
BSides Barcelona
· 2021
Technical
Talk
Open →
2022-01
30:38
Bridging the gap among Cloud Engineers and Incident Responders with Open Source
BSides CDMX
Open →
2024-10
34:15
The Log Rings Don't Lie: Historical Enumeration in Plain Sight
Bleon Proko
BSides NYC
· 2025
Technical
Cloud IAM
OSINT
Threat Intel
Red
Talk
Open →
2025-11
30:38
Approaching Parity: Considerations for Adapting Enterprise Monitoring to IaaS
BSides RDU
· 2018
Technical
Cloud IAM
Intermediary
Blue
Talk
Open →
2018-10
28:14
Six Hundred Degrees of IAM Admin: Battles with a Cloud Conscious Adversary
Suril Desai
BSides Seattle 2026
Technical
Cloud IAM
Detection Engineering
Intermediary
Blue
Talk
Open →
2026-04
19:49
Casting Light on Shadow Cloud Deployments
Chapin Bryce
Brittney Argirakis
BSides Las Vegas
· 2025
Technical
Cloud IAM
DFIR
Threat Intel
Blue
Talk
Open →
2025-12
30:57
Streamlining Threat Hunting in Cloud Environments with Jupyter: Chi Phong Huynh and Kai Iyer
Chi Phong Huynh
Kai Iyer
BSides Edmonton
· 2024
Technical
Cloud IAM
Talk
Open →
2025-10