Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Automating IMDS Protection at Scale in AWS - Metabadger Tool Overview

OWASP Foundation via YouTube

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Discover how to automate IMDS protection at scale in AWS environments with Metabadger in this 33-minute conference talk by Ashish Patel, Product Security Engineer at Salesforce. Learn about the vulnerabilities associated with AWS Instance Metadata Service (IMDS) and how attackers have exploited them in previous breaches. Explore the benefits of upgrading to IMDSv2 and the challenges of implementing it across thousands of EC2 instances without causing downtime. Gain insights into Metabadger, an open-source tool developed by Salesforce, which enables rapid and safe upgrading of EC2 instances to use IMDSv2, preventing SSRF-based theft of EC2 Metadata Credentials. Understand the components of AWS Instance Metadata Service, security and operational recommendations for upgrading to IMDSv2, and automation strategies for simplifying the migration process. Watch a demonstration of Metabadger in action and explore future architecture goals for enhancing AWS compute infrastructure security.

Syllabus

Introduction
What is Metadata
V2 Attack Chain
Why should we use it
Tooling
Discovery
Metabadger
Problem Statement
Metabadger Overview
Future Architecture Goals
Demo

Taught by

OWASP Foundation

Reviews

Start your review of Automating IMDS Protection at Scale in AWS - Metabadger Tool Overview

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.