AWS Fundamentals — Beginner Article for Cybersecurity
Learning AWS with a cybersecurity-focused approach. Explored EC2, S3, IAM, VPC, Security Groups, CloudTrail, CloudWatch, and GuardDuty. Understanding cloud infrastructure, identity, networking, logging, monitoring, and threat detection is essential for a SOC Analyst. Continuing to build practical cloud security knowledge and strengthen my skills in security monitoring, threat detection, investigation, and incident response. ☁️🔐 #AWS #CyberSecurity #CloudSecurity #SOCAnalyst
- What is AWS?
Amazon Web Services (AWS) is a cloud computing platform that provides infrastructure and services over the internet.
Instead of a company buying physical servers, storage, networking equipment, and data centers, it can rent these resources from AWS and pay according to usage. �
AWS +1
Think of it like:
Traditional IT
Company → Physical Server → Storage → Network → Applications
AWS
Company → AWS Cloud → Compute + Storage + Network + Security
AWS provides services for computing, storage, databases, networking, security, monitoring, AI, and many other workloads. �
AWS Documentation - AWS Global Infrastructure
Before learning individual services, understand these three terms:
Region
A Region is a geographic AWS location containing multiple Availability Zones.
Example:
ap-south-1 → Mumbai Region
Availability Zone (AZ)
An Availability Zone is an isolated location within an AWS Region.
A simplified architecture:
AWS Region
│
├── Availability Zone 1
│ ├── EC2
│ └── Database
│
├── Availability Zone 2
│ ├── EC2
│ └── Database
│
└── Availability Zone 3
└── Backup / Resources
Using multiple AZs can improve availability and resilience. - EC2 — Virtual Servers
Amazon EC2 (Elastic Compute Cloud) provides virtual servers in AWS. �
AWS Documentation
Think of EC2 as:
A virtual Linux/Windows machine running in the cloud.
For example:
AWS
│
└── EC2 Instance
│
├── Linux
├── Applications
├── Processes
└── Network Connections
For a SOC Analyst, EC2 is important because you may investigate:
Login activity
SSH connections
Running processes
Network connections
Malware execution
Privilege escalation
Suspicious outbound traffic - S3 — Cloud Storage
Amazon S3 (Simple Storage Service) is an object-storage service used to store data such as files, backups, images, logs, and other objects. �
AWS Documentation
Think:
S3
│
├── Bucket
│ ├── file1.txt
│ ├── backup.zip
│ ├── logs/
│ └── data/
Important security concept
A misconfigured S3 bucket can potentially expose sensitive data.
For a security analyst, you should understand:
Bucket permissions
IAM policies
Public access
Encryption
Access logging
Suspicious downloads
Data exfiltration - IAM — Extremely Important for Security
AWS IAM = Identity and Access Management.
IAM controls who or what can access AWS resources and what actions they are allowed to perform. �
AWS Documentation
Think:
User
│
▼
IAM
│
├── Authentication
│
└── Authorization
│
├── EC2
├── S3
└── RDS
IAM contains concepts such as:
Users
Groups
Roles
Policies
Permissions
Example
Imagine an employee needs to read files from S3.
Instead of giving that employee unlimited AWS permissions:
User
↓
IAM Policy
↓
S3 Read
The user receives only the permissions required.
This is called the principle of least privilege.
IAM policies are generally represented as JSON documents that define allowed or denied actions, resources, and conditions. �
AWS Documentation - VPC — AWS Networking
Amazon VPC (Virtual Private Cloud) is your logical network inside AWS.
Think of it as creating your own network environment in the cloud.
AWS
│
└── VPC
│
├── Public Subnet
│ └── Web Server
│
└── Private Subnet
└── Database
A VPC can contain:
Subnets
Route tables
Internet Gateway
NAT Gateway
Security Groups
Network ACLs
AWS describes VPC as a logically isolated virtual network where you can configure IP ranges, subnets, routing, gateways, and security controls. �
AWS Documentation - Security Groups
A Security Group acts like a virtual firewall for resources such as EC2.
Example:
Internet
│
▼
Security Group
│
├── TCP 22 → SSH
├── TCP 80 → HTTP
└── TCP 443 → HTTPS
Suppose your EC2 server has:
Port 22 → 0.0.0.0/0
That means SSH is exposed to the internet.
From a security perspective, that's something you should investigate carefully. - CloudTrail — VERY Important for SOC
For your career as a SOC Analyst, pay special attention to AWS CloudTrail.
CloudTrail records AWS API activity.
For example:
User
↓
AWS Console / CLI / API
↓
AWS Service
↓
CloudTrail
↓
Security Monitoring
Imagine someone performs:
CreateUser
DeleteBucket
CreateAccessKey
StopInstance
ModifySecurityGroup
These activities can be investigated through AWS logging and monitoring.
This is where AWS starts becoming directly relevant to SOC work. - CloudWatch
Amazon CloudWatch is used for monitoring and observability.
You can think of:
AWS Resources
↓
CloudWatch
↓
Metrics + Logs + Alarms
A SOC/security team can use AWS monitoring data alongside security logs to investigate suspicious activity. - AWS Security Architecture
A simplified security architecture could look like this:
INTERNET
│
▼
┌───────────┐
│ VPC │
└─────┬─────┘
│
┌─────────┴─────────┐
│ │
▼ ▼
Public Subnet Private Subnet
│ │
▼ ▼
EC2 RDS
│
│
▼
CloudWatch
│
▼
CloudTrail
│
▼
SOC / SIEM
This is the kind of architecture you should learn to read and investigate, not just memorize. - AWS + SOC Analyst
For your SOC career, focus on this path:
Level 1 — AWS Fundamentals
Learn:
Cloud Computing
↓
AWS Regions / AZ
↓
EC2
↓
S3
↓
IAM
↓
VPC
Level 2 — AWS Security
Then learn:
IAM
Security Groups
NACL
CloudTrail
CloudWatch
AWS KMS
GuardDuty
Security Hub
AWS Config
Level 3 — SOC Investigation
Finally:
AWS Event
↓
Log
↓
SIEM
↓
Alert
↓
Investigation
↓
Threat Hunting
↓
Incident Response
This fits very well with the SOC workflow you've already been practicing:
Alert → Investigation → Threat Hunting → Detection → Incident Response. - AWS Attack Scenario — SOC Perspective
Imagine an attacker obtains an AWS access key.
They use it to:
Attacker
↓
Compromised Access Key
↓
AWS API
↓
List S3 Buckets
↓
Access Sensitive Data
↓
Download Data
A SOC analyst might investigate:
Who performed the action?
→ IAM identity
What action was performed?
→ AWS API event
When?
→ Timestamp
From where?
→ Source IP
What resource was accessed?
→ S3 bucket / EC2 / IAM etc.
Was the behavior legitimate?
→ Compare with normal activity
What should happen next?
→ Containment → Credential rotation → Investigation → Recovery - AWS Services You Should Remember
Service
Simple meaning
SOC importance
EC2
Virtual server
⭐⭐⭐⭐⭐
S3
Cloud storage
⭐⭐⭐⭐⭐
IAM
Identity & permissions
⭐⭐⭐⭐⭐
VPC
Cloud network
⭐⭐⭐⭐⭐
CloudTrail
AWS activity/API logging
⭐⭐⭐⭐⭐
CloudWatch
Monitoring/logs
⭐⭐⭐⭐
GuardDuty
Threat detection
⭐⭐⭐⭐⭐
Security Hub
Security findings
⭐⭐⭐⭐⭐
KMS
Encryption/key management
⭐⭐⭐
RDS
Managed database
⭐⭐⭐
Lambda
Serverless compute
⭐⭐⭐
Enjoyed reading this content? Let the author know!
Your likes, comments, shares, and saves help creators reach more builders.
Loading recommendations
Loading article