技能 编程开发 云工作负载防护

云工作负载防护

v20260317
implementing-cloud-workload-protection
利用 boto3 与 Google Cloud API,在 EC2/GCE 运行时监控进程、网络、文件完整性和资源异常,发现挖矿、反向 shell 与未授权二进制程序。
获取技能
278 次下载
概览

Implementing Cloud Workload Protection

Instructions

Monitor cloud workloads for runtime threats by checking process lists, network connections, file integrity, and resource utilization anomalies.

import boto3

ssm = boto3.client("ssm")
# Run command on EC2 instances to check for suspicious processes
response = ssm.send_command(
    InstanceIds=["i-1234567890abcdef0"],
    DocumentName="AWS-RunShellScript",
    Parameters={"commands": ["ps aux | grep -E 'xmrig|minerd|cryptonight'"]},
)

Key protection areas:

  1. Process monitoring for cryptominers and reverse shells
  2. File integrity monitoring on critical system files
  3. Network connection auditing for C2 callbacks
  4. Resource utilization anomaly detection (CPU spikes)
  5. Unauthorized binary detection via hash comparison

Examples

# Check for unauthorized outbound connections
ssm.send_command(
    InstanceIds=instances,
    DocumentName="AWS-RunShellScript",
    Parameters={"commands": ["ss -tlnp | grep ESTABLISHED"]},
)
信息
Category 编程开发
Name implementing-cloud-workload-protection
版本 v20260317
大小 8.25KB
更新时间 2026-03-18
语言