Amazon Machine Images (AMIs) introduce cloud attack surface risks through three main vectors: misconfigured private golden images, sensitive data leakage in publicly shared AMIs, and malicious or untrusted public/community AMIs. Private AMIs can accumulate version drift and inherit vulnerabilities from base images; public AMIs may contain hardcoded secrets or embedded malware like crypto miners. A name confusion attack technique is highlighted where attackers publish AMIs with names matching common search patterns to trick automation into deploying malicious images. Best practices include using CIS benchmarks for secure defaults, maintaining AMI inventories, enforcing allowlists, restricting searches by publisher, deleting shell history before sharing, and using AWS Allowed AMIs controls. Datadog's whoAMI-scanner and Security Graph are presented as tools to detect and visualize these risks.

7m read timeFrom datadoghq.com
Post cover image
Table of contents
Reduce insecure configurations, vulnerabilities, and version drift in private AMIsPrevent sensitive data leakage when sharing Amazon EC2 AMIsDetect and block untrusted or malicious public AMIsHow Datadog can help reduce your cloud attack surfaceMinimize risks in Amazon EC2 AMI usageAcknowledgements
332 Impressions