26 lines
6.9 KiB
JSON
26 lines
6.9 KiB
JSON
{
|
||
"schema_version": 1,
|
||
"saved_at": "2026-08-07T05:32:55.2153611Z",
|
||
"content_sha256": "0eb84414259a65367459c494c20b0d72a837327554d042aa914154a35347e67d",
|
||
"result": {
|
||
"title": "docs.aws.amazon.com",
|
||
"url": "https://docs.aws.amazon.com/solutions/automated-forensics-orchestrator-for-amazon-ec2/",
|
||
"snippet": "This Guidance demonstrates how to establish a comprehensive, automated forensics orchestration workflow for Security Operations Centers using AWS services. It helps organizations rapidly respond to potential security breaches by automating critical forensics processes for Amazon EC2 instances and EKS clusters. The solution shows how to implement automated isolation of affected resources ...",
|
||
"content": "Overview\n\nThis Guidance demonstrates how to establish a comprehensive, automated forensics orchestration workflow for Security Operations Centers using AWS services. It helps organizations rapidly respond to potential security breaches by automating critical forensics processes for Amazon EC2 instances and EKS clusters. The solution shows how to implement automated isolation of affected resources, capture essential forensics evidence including memory and disk images, and streamline investigation workflows across multi-account and multi-region environments. Through its serverless architecture and integrated security features, this Guidance enables SOC teams to efficiently conduct forensic analysis, continuously monitor for threats, and maintain a robust security posture while reducing manual overhead and accelerating incident response times.\n\nBenefits\n\nAccelerate incident response and investigation\n\nReduce investigation time from hours to minutes with automated forensic workflows that capture and analyze both memory and disk data when security issues are detected. Maintain business continuity while thoroughly investigating potential threats.\n\nStrengthen security with automated containment\n\nAutomatically isolate potentially compromised instances while preserving forensic evidence for investigation. Protect your infrastructure by implementing consistent, automated response procedures for security findings.\n\nStreamline forensic data management\n\nMaintain complete chain of custody with automated evidence collection and secure storage. Query forensic timelines and investigation results through a centralized interface while ensuring compliance requirements.\n\nHow it works\n\nThese technical details feature an architecture diagram to illustrate how to effectively use this solution. The architecture diagram shows the key components and their interactions, providing an overview of the architecture's structure and functionality step-by-step.\n\nDownload the architecture diagram\n\nStep 1\n\nPrior to running the workflow, you will need a forensic Amazon Machine Image (AMI). You can use Amazon EC2 Image Builder to build a new forensic AMI or an existing forensic AMI.\n\nStep 2\n\nAWS Step Functions leverages the forensic AMI to perform memory and disk investigation.\n\nStep 3\n\nIn the AWS application account, AWS Config managed rules, Amazon GuardDuty, and third-party tools detect malicious activities that are specific to Amazon Elastic Compute Cloud (Amazon EC2) resources. For example, an EC2 instance queries a low reputation domain name that is associated with known abused domains. The findings are sent to AWS Security Hub in the security account through their native or existing integration.\n\nStep 4\n\nBy default, all Security Hub findings are then sent to Amazon EventBridge to invoke automated downstream workflows.\n\nStep 5\n\nFor a specified event, EventBridge provides an instance ID for the forensics process to target, and initiates the Step Functions workflow.\n\nStep 6\n\nStep Functions triages the request through the following approach: It first gets the instance information. It then determines if isolation is required based on the Security Hub action and if acquisition is required based on tags associated with the instance. Finally, it initiates the acquisition flow based on triaging output.\n\nStep 6a\n\nAmazon DynamoDB stores triaging details.\n\nStep 6b\n\nTwo acquisition flows are initiated in parallel: The Memory Forensics Flow is a Step Functions workflow that captures the memory data and stores it in Amazon Simple Storage Service (Amazon S3). Post memory acquisition, the instance is isolated using security groups. To help ensure the chain of custody, a new security group gets attached to the targeted instance and removes any access for users, admins, or developers. Isolation is initiated based on the selected Security Hub action. The Disk Forensics Flow is a Step Functions workflow that takes a snapshot of an Amazon Elastic Block Store (Amazon EBS) volume and shares it with the forensic account.\n\nStep 6c\n\nDynamoDB stores acquisition details.\n\nStep 6d\n\nOnce the disk or memory acquisition process is complete, a notification is sent to an investigation Step Functions state machine to begin the automated investigation of the captured data.\n\nStep 6e\n\nWhen the Step Functions jobs are complete, DynamoDB stores the state of forensic tasks and their results.\n\nStep 7\n\nInvestigation Step Functions starts a forensic instance from an existing forensic AMI loaded with customer forensic tools. Step Functions loads the memory data from Amazon S3 for investigation, creates an EBS volume from the snapshot, and attaches the EBS volume for disk analysis.\n\nStep 8\n\nAWS Systems Manager documents (SSM documents) run forensic investigation.\n\nStep 9\n\nAmazon Simple Notification Service (Amazon SNS) shares investigation details with customers.\n\nStep 10\n\nAWS AppSync can query the forensic timeline. For more details, refer to Sample AppSync API to query forensic details.\n\nDeploy with confidence\n\nEverything you need to launch this Guidance in your account is right here.\n\nWe'll walk you through it\n\nDive deep into the implementation guide for additional customization options and service configurations to tailor to your specific needs.\n\nOpen guide\n\nLet's make it happen\n\nReady to deploy? Review the sample code on GitHub for detailed deployment instructions to deploy as-is or customize to fit your needs.\n\nGo to sample code\n\nRead usage guidelines",
|
||
"content_type": "text/html",
|
||
"query": "How are evidence artifacts documented in AWS EKS during incident response?",
|
||
"language": "en-US",
|
||
"round": 1,
|
||
"fetched": true,
|
||
"relevant": true,
|
||
"relevance": 0.9733333333333334,
|
||
"source_quality": "primary",
|
||
"source_quality_score": 0.9760000000000001,
|
||
"actionable": true,
|
||
"covered_gap_ids": [
|
||
"KG-002"
|
||
],
|
||
"assessment_reason": "Wiederverwendete semantisch äquivalente Recherche: The source outlines an automated forensics orchestration workflow for AWS EKS, including specific steps for capturing memory and disk images, isolating instances, and maintaining chain of custody. It directly addresses the question with actionable steps."
|
||
}
|
||
}
|