BSIDES BELGRADE 2026
AGENDA 2026
Defending Against AWS Data Exfiltration Paths
SPEAKERS: Nicolás Villalobos Ramírez
About the Workshop/Talk
Operating in the cloud can be daunting at first. With hundreds of services at your disposal, each with its own quirks, the probability of misconfiguration is high. Cloud infrastructure operates in a whole different world compared to traditional on-prem environments. In this context, data exfiltration is one of the most impactful outcomes of a cloud compromise. Surprisingly, most cloud breaches are not caused by sophisticated attacks but by misconfigurations, oversights, or unanticipated service behaviors. Understanding these risks is critical to protecting sensitive data. This talk examines AWS exfiltration paths, including S3 access and replication misuse, EBS snapshot and AMI sharing, cross-account role assumption, SQS and SNS messages, among others. Attendees will learn how to use AWS native controls such as CloudTrail, IAM Access Analyzer, EventBridge, and service control policies to detect and prevent exfiltration. We will also cover preventative guardrails, identity restrictions, and automation techniques that reduce blast radius without disrupting legitimate workloads, giving participants a practical framework to secure their AWS environments.