AWS Builder Center

AWS Fundamentals — Beginner Article for Cybersecurity

Learning AWS with a cybersecurity-focused approach. Explored EC2, S3, IAM, VPC, Security Groups, CloudTrail, CloudWatch, and GuardDuty. Understanding cloud infrastructure, identity, networking, logging, monitoring, and threat detection is essential for a SOC Analyst. Continuing to build practical cloud security knowledge and strengthen my skills in security monitoring, threat detection, investigation, and incident response. ☁️🔐 #AWS #CyberSecurity #CloudSecurity #SOCAnalyst

  1. What is AWS?
    Amazon Web Services (AWS) is a cloud computing platform that provides infrastructure and services over the internet.
    Instead of a company buying physical servers, storage, networking equipment, and data centers, it can rent these resources from AWS and pay according to usage. �
    AWS +1
    Think of it like:
    Traditional IT
    Company → Physical Server → Storage → Network → Applications
    AWS
    Company → AWS Cloud → Compute + Storage + Network + Security
    AWS provides services for computing, storage, databases, networking, security, monitoring, AI, and many other workloads. �
    AWS Documentation
  2. AWS Global Infrastructure
    Before learning individual services, understand these three terms:
    Region
    A Region is a geographic AWS location containing multiple Availability Zones.
    Example:
    ap-south-1 → Mumbai Region
    Availability Zone (AZ)
    An Availability Zone is an isolated location within an AWS Region.
    A simplified architecture:
    AWS Region
    │
    ├── Availability Zone 1
    │ ├── EC2
    │ └── Database
    │
    ├── Availability Zone 2
    │ ├── EC2
    │ └── Database
    │
    └── Availability Zone 3
    └── Backup / Resources
    Using multiple AZs can improve availability and resilience.
  3. EC2 — Virtual Servers
    Amazon EC2 (Elastic Compute Cloud) provides virtual servers in AWS. �
    AWS Documentation
    Think of EC2 as:
    A virtual Linux/Windows machine running in the cloud.
    For example:
    AWS
    │
    └── EC2 Instance
    │
    ├── Linux
    ├── Applications
    ├── Processes
    └── Network Connections
    For a SOC Analyst, EC2 is important because you may investigate:
    Login activity
    SSH connections
    Running processes
    Network connections
    Malware execution
    Privilege escalation
    Suspicious outbound traffic
  4. S3 — Cloud Storage
    Amazon S3 (Simple Storage Service) is an object-storage service used to store data such as files, backups, images, logs, and other objects. �
    AWS Documentation
    Think:
    S3
    │
    ├── Bucket
    │ ├── file1.txt
    │ ├── backup.zip
    │ ├── logs/
    │ └── data/
    Important security concept
    A misconfigured S3 bucket can potentially expose sensitive data.
    For a security analyst, you should understand:
    Bucket permissions
    IAM policies
    Public access
    Encryption
    Access logging
    Suspicious downloads
    Data exfiltration
  5. IAM — Extremely Important for Security
    AWS IAM = Identity and Access Management.
    IAM controls who or what can access AWS resources and what actions they are allowed to perform. �
    AWS Documentation
    Think:
    User
    │
    ▼
    IAM
    │
    ├── Authentication
    │
    └── Authorization
    │
    ├── EC2
    ├── S3
    └── RDS
    IAM contains concepts such as:
    Users
    Groups
    Roles
    Policies
    Permissions
    Example
    Imagine an employee needs to read files from S3.
    Instead of giving that employee unlimited AWS permissions:
    User
    ↓
    IAM Policy
    ↓
    S3 Read
    The user receives only the permissions required.
    This is called the principle of least privilege.
    IAM policies are generally represented as JSON documents that define allowed or denied actions, resources, and conditions. �
    AWS Documentation
  6. VPC — AWS Networking
    Amazon VPC (Virtual Private Cloud) is your logical network inside AWS.
    Think of it as creating your own network environment in the cloud.
    AWS
    │
    └── VPC
    │
    ├── Public Subnet
    │ └── Web Server
    │
    └── Private Subnet
    └── Database
    A VPC can contain:
    Subnets
    Route tables
    Internet Gateway
    NAT Gateway
    Security Groups
    Network ACLs
    AWS describes VPC as a logically isolated virtual network where you can configure IP ranges, subnets, routing, gateways, and security controls. �
    AWS Documentation
  7. Security Groups
    A Security Group acts like a virtual firewall for resources such as EC2.
    Example:
    Internet
    │
    ▼
    Security Group
    │
    ├── TCP 22 → SSH
    ├── TCP 80 → HTTP
    └── TCP 443 → HTTPS
    Suppose your EC2 server has:
    Port 22 → 0.0.0.0/0
    That means SSH is exposed to the internet.
    From a security perspective, that's something you should investigate carefully.
  8. CloudTrail — VERY Important for SOC
    For your career as a SOC Analyst, pay special attention to AWS CloudTrail.
    CloudTrail records AWS API activity.
    For example:
    User
    ↓
    AWS Console / CLI / API
    ↓
    AWS Service
    ↓
    CloudTrail
    ↓
    Security Monitoring
    Imagine someone performs:
    CreateUser
    DeleteBucket
    CreateAccessKey
    StopInstance
    ModifySecurityGroup
    These activities can be investigated through AWS logging and monitoring.
    This is where AWS starts becoming directly relevant to SOC work.
  9. CloudWatch
    Amazon CloudWatch is used for monitoring and observability.
    You can think of:
    AWS Resources
    ↓
    CloudWatch
    ↓
    Metrics + Logs + Alarms
    A SOC/security team can use AWS monitoring data alongside security logs to investigate suspicious activity.
  10. AWS Security Architecture
    A simplified security architecture could look like this:
    INTERNET
    │
    ▼
    ┌───────────┐
    │ VPC │
    └─────┬─────┘
    │
    ┌─────────┴─────────┐
    │ │
    ▼ ▼
    Public Subnet Private Subnet
    │ │
    ▼ ▼
    EC2 RDS
    │
    │
    ▼
    CloudWatch
    │
    ▼
    CloudTrail
    │
    ▼
    SOC / SIEM
    This is the kind of architecture you should learn to read and investigate, not just memorize.
  11. AWS + SOC Analyst
    For your SOC career, focus on this path:
    Level 1 — AWS Fundamentals
    Learn:
    Cloud Computing
    ↓
    AWS Regions / AZ
    ↓
    EC2
    ↓
    S3
    ↓
    IAM
    ↓
    VPC
    Level 2 — AWS Security
    Then learn:
    IAM
    Security Groups
    NACL
    CloudTrail
    CloudWatch
    AWS KMS
    GuardDuty
    Security Hub
    AWS Config
    Level 3 — SOC Investigation
    Finally:
    AWS Event
    ↓
    Log
    ↓
    SIEM
    ↓
    Alert
    ↓
    Investigation
    ↓
    Threat Hunting
    ↓
    Incident Response
    This fits very well with the SOC workflow you've already been practicing:
    Alert → Investigation → Threat Hunting → Detection → Incident Response.
  12. AWS Attack Scenario — SOC Perspective
    Imagine an attacker obtains an AWS access key.
    They use it to:
    Attacker
    ↓
    Compromised Access Key
    ↓
    AWS API
    ↓
    List S3 Buckets
    ↓
    Access Sensitive Data
    ↓
    Download Data
    A SOC analyst might investigate:
    Who performed the action?
    → IAM identity
    What action was performed?
    → AWS API event
    When?
    → Timestamp
    From where?
    → Source IP
    What resource was accessed?
    → S3 bucket / EC2 / IAM etc.
    Was the behavior legitimate?
    → Compare with normal activity
    What should happen next?
    → Containment → Credential rotation → Investigation → Recovery
  13. AWS Services You Should Remember
    Service
    Simple meaning
    SOC importance
    EC2
    Virtual server
    ⭐⭐⭐⭐⭐
    S3
    Cloud storage
    ⭐⭐⭐⭐⭐
    IAM
    Identity & permissions
    ⭐⭐⭐⭐⭐
    VPC
    Cloud network
    ⭐⭐⭐⭐⭐
    CloudTrail
    AWS activity/API logging
    ⭐⭐⭐⭐⭐
    CloudWatch
    Monitoring/logs
    ⭐⭐⭐⭐
    GuardDuty
    Threat detection
    ⭐⭐⭐⭐⭐
    Security Hub
    Security findings
    ⭐⭐⭐⭐⭐
    KMS
    Encryption/key management
    ⭐⭐⭐
    RDS
    Managed database
    ⭐⭐⭐
    Lambda
    Serverless compute
    ⭐⭐⭐
Any opinions in this article are those of the individual author and may not reflect the opinions of AWS.
Enjoyed reading this content? Let the author know!

Your likes, comments, shares, and saves help creators reach more builders.

Loading recommendations

Loading article