Kennedy

1.8K posts

Kennedy banner
Kennedy

Kennedy

@run2obtain

Co-Founder & CTO @ https://t.co/xLzwrRqO9A ✨ AWS Community Builder.✨Cloud Attack Emulation 🌩️

Katılım Mayıs 2009
3K Takip Edilen845 Takipçiler
Sabitlenmiş Tweet
Kennedy
Kennedy@run2obtain·
🎊 Introducing: Mitigant Threat Catalog 🎊 Super excited to launch the Mitigant Threat Catalog ▶️ threats.mitigant.io If you've ever stared at a @MITREattack technique & wondered, "What does this actually look like in my @awscloud environment?", this is for you. 🧵👇
Kennedy tweet media
English
3
2
8
3.3K
Kennedy
Kennedy@run2obtain·
@PaloAltoNtwks @Unit42_Intel ⚙️ Path 3 - Code Interpreter Privilege Escalation: The agent can invoke any Code Interpreter, even in higher-privileged contexts. 🤖 Path 4 - Cross-Agent Invocation: Execution/invocation of any other agent in the account - the impact is left for imagination.
English
1
0
0
22
Kennedy
Kennedy@run2obtain·
AgentCore provides an agnostic layer for agentic infrastructure management across the major LLM providers. But this agnostic management layer could easily become a source of pain, as recently discovered by @PaloAltoNtwks @Unit42_Intel 🙀
English
1
0
0
28
Kennedy
Kennedy@run2obtain·
☠️ AgentCore or AgentSore: One Agent to Rule Them All ☠️ What happens when convenience + productivity become accelerators of attacker speed? 👀 That is exactly the scenario demonstrated by the recently discovered security issue in @awscloud Bedrock AgentCore. 👇👇
Kennedy tweet media
English
1
0
0
867
Kennedy
Kennedy@run2obtain·
@MITREattack Why now? 🤔 AI is multiplying the number of findings & vulnerabilities. The reflex answer is patch faster. The right answer is validate first. Turn the noise into the signals that REALLY matter. ⚔️ 👉 More in the release blog: mitigant.io/en/blog/featur…
English
0
0
0
19
Kennedy
Kennedy@run2obtain·
Numbers that matter: 🔥 85% noise reduction from posture to exploitable findings 🔥 ~5-minute Mean Time to Validate (MTTV) from pentest start to client-ready report 🔥 300+ cloud attacks available for deeper adversarial engagement, mapped to @MITREattack
English
1
0
1
55
Kennedy
Kennedy@run2obtain·
🎉 Mitigant Cloud Pentest Now Supports Wiz & Prowler 🎉 Excited to announce Mitigant Cloud Pentest now supports @wiz_io and @prowlercloud, driven by strong demand from our customers and partners. What you get: 👇
Kennedy tweet media
English
1
0
1
48
Kennedy
Kennedy@run2obtain·
🎊 Introducing: Mitigant Threat Catalog 🎊 Super excited to launch the Mitigant Threat Catalog ▶️ threats.mitigant.io If you've ever stared at a @MITREattack technique & wondered, "What does this actually look like in my @awscloud environment?", this is for you. 🧵👇
Kennedy tweet media
English
3
2
8
3.3K
Kennedy
Kennedy@run2obtain·
SCPs are a double-edged sword. Use it well, and you are protected. Make a mistake, and it bites back. 😵 See how to avoid the common mistakes 👇 x.com/run2obtain/sta…
Kennedy@run2obtain

🛡️ SCP Effectiveness: Don't Fall on Your Sword 🗡️ SCPs are among the most powerful preventive controls in @awscloud. They allow centralized access control across multi-account environments. However, deploying SCPs is one thing. 🥳 Trusting them is another. 🤔

English
1
0
1
80
Kennedy
Kennedy@run2obtain·
@awscloud 💥 Concrete example: Modify Cloud Resource Hierarchy: Leave Organization is an AWS-specific @MITREattack technique in which attackers remove member accounts from AWS Organizations. Two API calls, and a huge chunk of security control eroded. 🙀 -> threats.mitigant.io/techniques/?id…
Kennedy tweet media
English
1
0
0
18
Kennedy
Kennedy@run2obtain·
🛡️ SCP Effectiveness: Don't Fall on Your Sword 🗡️ SCPs are among the most powerful preventive controls in @awscloud. They allow centralized access control across multi-account environments. However, deploying SCPs is one thing. 🥳 Trusting them is another. 🤔
GIF
English
1
0
1
108