Episode

AWS Security Incident Response: Tracking Attackers Through Audit Logs

Podcast
The Business Compass LLC Podcasts
Published
Jul 23, 2026
Duration seconds
1224
Processing state
not_requested
Canonical source
https://podcast.businesscompassllc.com/e/aws-security-incident-response-tracking-attackers-through-audit-logs/
Audio
https://mcdn.podbean.com/mf/web/n54qr9mzavthw9zn/b908865b-8bbf-49ed-a3f0-5c973f009595.mp3
JSON
/v1/public/podcasts/the-business-compass-llc-podcasts-7078188/episodes/aws-security-incident-response-tracking-attackers-through-audit-logs
Markdown
/podcast/the-business-compass-llc-podcasts-7078188/aws-security-incident-response-tracking-attackers-through-audit-logs.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/the-business-compass-llc-podcasts-7078188/episodes/aws-security-incident-response-tracking-attackers-through-audit-logs/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/the-business-compass-llc-podcasts-7078188/aws-security-incident-response-tracking-attackers-through-audit-logs.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

A suspicious API call fires at 2 AM. An IAM role you don’t recognize starts spinning up EC2 instances. Your S3 bucket permissions changed — and nobody on your team did it.