Threat Hunting AWS CloudTrail Logs using KQL: EC2 SSRF Attack Demo
2025-05-12 , Grand Ballroom B

In today’s cloud-centric world, securing cloud infrastructures is crucial. This session provides a live demo of threat hunting in AWS CloudTrail logs. Attendees will see an attacker exploit a vulnerable web app to perform an SSRF attack and learn effective techniques for hunting through AWS CloudTrail logs using Kusto Query Language (KQL).


Difficulty Level of Presentation:

Intermediate/Some Knowledge Advised

Arijit Paul is a seasoned cybersecurity professional with extensive experience in cloud security, threat hunting and incident response. With a background in both offensive and defensive security, Arijit specializes in leveraging advanced tools and techniques to protect cloud environments. Currently, Arijit is focused on threat detection, automation and response, helping organizations secure their cloud infrastructures.