#aws-network-firewall
New on @hackingthe.cloud! A great post by Federico Lucini on bypassing AWS Network Firewall egress filtering!

hackingthe.cloud/aws/post_exp...
AWS Network Firewall Egress Filtering Bypass - Hacking The Cloud
Bypass AWS Network Firewall Egress Filtering using SNI spoofing and Host Header manipulation.
hackingthe.cloud
September 29, 2025 at 2:30 PM
AWS announces DNS analytics and insights for Route 53 Global Resolver and DNS Firewall through CloudWatch integration, enabling network administrators to monitor DNS patterns and detect anomalies.
Announcing DNS analytics and insights for Route 53 Global Resolver and DNS Firewall
AWS announces DNS analytics and insights for Route 53 Global Resolver and DNS Firewall through CloudWatch integration, enabling network administrators to monitor DNS patterns and detect anomalies.
aws-news.com
October 1, 2026 at 6:56 PM
Today I heard a network engineer ask an AWS SA if the AWS Network Firewall can block host file tampering, and it took every fiber to not laugh and then asphyxiate
March 13, 2025 at 3:24 AM
Wrapping up our final network design for integrating AWS Network Firewall. It’s been a journey, and we learned a few things along the way (thanks to an AWS expert for confirming that Host --> NFW --> NGW --> IGW is the recommended architecture).

The design is quirky - good luck cloud network folks!
January 30, 2025 at 3:00 PM
Announcing DNS analytics and insights for Route 53 Global Resolver and DNS Firewall

Route 53 Global Resolver and DNS Firewall now provide DNS analytics and insights through native Amazon CloudWatch integration. These new capabilities enable network administ...

#AWS #AmazonRoute53 #AmazonCloudwatch
Announcing DNS analytics and insights for Route 53 Global Resolver and DNS Firewall
Route 53 Global Resolver and DNS Firewall now provide DNS analytics and insights through native Amazon CloudWatch integration. These new capabilities enable network administrators and security teams to gain full observability into DNS query patterns, monitor DNS Firewall rule effectiveness, detect anomalous activity, and optimize DNS infrastructure performance. DNS analytics and insights is available in all AWS Regions where Amazon CloudWatch, Route 53 Global Resolver, and DNS Firewall are available. With CloudWatch Metrics and Contributor Insights, customers can search and analyze DNS query logs, create metric filters for specific patterns such as blocked queries and DNS response codes, and set automated alarms. A new Analytics tab in both the Global Resolver and DNS Firewall consoles provides streamlined access to all analytics in one place. For example, customers can create a metric filter for blocked DNS queries by VPC and set an alarm to trigger when more than 10 queries are blocked within an hour, enabling rapid response to potential security threats. Standard https://aws.amazon.com/cloudwatch/pricing/ applies to the metrics that customers opt in to. To learn more, visit the https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/Welcome.html.
aws.amazon.com
October 1, 2026 at 7:05 PM
Oh fuck...
October 20, 2025 at 2:14 PM
🆕 AWS Route 53 Global Resolver and DNS Firewall now integrate with Amazon CloudWatch for DNS analytics, enhancing observability, anomaly detection, and performance optimization, with metrics and automated alarms available in all supporting regions.

#AWS #AmazonRoute53 #AmazonCloudwatch
Announcing DNS analytics and insights for Route 53 Global Resolver and DNS Firewall
Route 53 Global Resolver and DNS Firewall now provide DNS analytics and insights through native Amazon CloudWatch integration. These new capabilities enable network administrators and security teams to gain full observability into DNS query patterns, monitor DNS Firewall rule effectiveness, detect anomalous activity, and optimize DNS infrastructure performance. DNS analytics and insights is available in all AWS Regions where Amazon CloudWatch, Route 53 Global Resolver, and DNS Firewall are available. With CloudWatch Metrics and Contributor Insights, customers can search and analyze DNS query logs, create metric filters for specific patterns such as blocked queries and DNS response codes, and set automated alarms. A new Analytics tab in both the Global Resolver and DNS Firewall consoles provides streamlined access to all analytics in one place. For example, customers can create a metric filter for blocked DNS queries by VPC and set an alarm to trigger when more than 10 queries are blocked within an hour, enabling rapid response to potential security threats. Standard Amazon CloudWatch pricing applies to the metrics that customers opt in to. To learn more, visit the Route 53 documentation.
aws.amazon.com
October 1, 2026 at 7:11 PM
Ubicloud : une alternative Open Source à AWS … une plateforme cloud offrant des services tels que l'Elastic compute, block storage, firewall et load balancer.

👉 En savoir plus : www.ubicloud.com/
👉 Le projet : github.com/ubicloud/...
January 13, 2025 at 2:54 PM
AWS Network Firewall now supports IPv6 Service Endpoints

AWS Network Firewall introduces dual stack support for Network Firewall management API, enabling you to connect using Internet Protocol Version 6 (IPv6), Internet Protocol Version 4 (IP...

#AWS #AmazonVpc #AwsNetworkFirewall #AwsGovcloudUs
AWS Network Firewall now supports IPv6 Service Endpoints
AWS Network Firewall introduces dual stack support for Network Firewall management API, enabling you to connect using Internet Protocol Version 6 (IPv6), Internet Protocol Version 4 (IPv4), or dual stack clients. Dual stack support is also available when the AWS Network Firewall management API endpoint is privately accessed from your Amazon Virtual Private Cloud (VPC) using AWS https://aws.amazon.com/about-aws/whats-new/2022/12/amazon-eks-supports-aws-privatelink/. Dual stack endpoints are made available on a new AWS DNS domain name. The existing AWS Network Firewall management API endpoints are maintained for backwards compatibility reasons. AWS Network Firewall is a managed firewall service that is easy to deploy. The service automatically scales with network traffic volume to provide high-availability protections without the need to set up and maintain the underlying infrastructure. With simultaneous support for both IPv4 and IPv6 clients on AWS Network Firewall endpoints, you are able to gradually transition from IPv4 to IPv6 based systems and applications, without needing to switch all over at once. There is no additional charge when you connect to AWS Network Firewall endpoints using Internet Protocol Version 6 (IPv6) clients. To see which regions AWS Network Firewall is available in, visit the https://aws.amazon.com/about-aws/global-infrastructure/regional-product-services/. For more information, please see the AWS Network Firewall https://aws.amazon.com/network-firewall/ and the service https://docs.aws.amazon.com/network-firewall/latest/developerguide/.  
aws.amazon.com
January 19, 2025 at 11:05 PM
AWS Network Firewall introduces Geographic IP Filtering, enabling customers to control network traffic based on geographic location, enhancing security and meeting compliance requirements for internet-facing applications.
AWS Network Firewall Geographic IP Filtering launch
AWS Network Firewall introduces Geographic IP Filtering, enabling customers to control network traffic based on geographic location, enhancing security and meeting compliance requirements for internet-facing applications.
aws-news.com
December 6, 2024 at 9:26 PM
Active threat defense now enabled by default in AWS Network Firewall

Starting today, AWS Network Firewall enables active threat defense by default in alert mode when you create new firewall policies in the AWS Management Console. Active threat defense p...

#AWS #AwsGovcloudUs #AwsNetworkFirewall
Active threat defense now enabled by default in AWS Network Firewall
Starting today, AWS Network Firewall enables active threat defense by default in alert mode when you create new firewall policies in the AWS Management Console. Active threat defense provides automated, intelligence-driven protection against dynamic, ongoing threat activities observed across AWS infrastructure. With this default setting you get visibility into threat activity and indicator groups, types, and threat names you are protected against. You can switch to block mode to automatically prevent suspicious traffic, such as command-and-control (C2) communication, embedded URLs, and malicious domains, or disable the feature entirely. AWS verifies threat indicators to ensure high accuracy and minimize false positives. Active threat defense is available in all regions where AWS Network Firewall is available, including AWS GovCloud (US) and China Regions. To learn more about active threat defense and pricing, see the AWS Network Firewall https://aws.amazon.com/network-firewall/ and https://docs.aws.amazon.com/network-firewall/latest/developerguide/aws-managed-rule-groups-atd.html.
aws.amazon.com
November 18, 2025 at 7:05 PM
~Trendmicro~
Trend Micro now offers one-click managed IPS rule groups natively within AWS Network Firewall.
-
IOCs: (None identified)
-
#AWS #CloudSecurity #IPS #ThreatIntel
Trend & AWS Partner on Cloud IPS
www.trendmicro.com
November 20, 2025 at 4:03 AM
🆕 AWS Network Firewall boosts console, monitoring, and security with enhanced insights, advanced TLS Inspection, and session holding for stronger outbound traffic protection, available in all regions.

#AWS #AwsNetworkFirewall
AWS Network Firewall enhances console, monitoring, and security features
AWS Network Firewall now offers enhancements to its console, monitoring dashboard, and security controls. These improvements include expanded monitoring insights and advanced TLS Inspection features. These updates provide customers with enhanced visibility into their firewall's performance and stronger security measures for outbound connections. The monitoring dashboard now provides deeper insights into traffic going to AWS services such as Amazon S3, Amazon DynamoDB, and AWS Backup, which can be sent over PrivateLink endpoints. The dashboard also gives visibility into top source and destination IP addresses based on packets and bytes processed. Customers can filter the dashboard based on IP addresses and protocol, enabling more targeted analysis of network traffic patterns. To further strengthen security, AWS Network Firewall has introduced session holding for TLS Inspection. This feature prevents any TCP and TLS establishment packets from reaching destination servers until TLS protocol rules matching on Server Name Indication (SNI) have been evaluated. This enhancement provides stronger security controls for outbound traffic and helps protect against connections to potentially malicious targets. These new features are available in all AWS Regions where AWS Network Firewall is offered. To learn more about these new features and other AWS Network Firewall capabilities, visit the AWS Network Firewall product page and the service documentation.
aws.amazon.com
September 17, 2025 at 9:41 PM
🆕 AWS Network Security Manager is now available in US East (N. Virginia) to simplify security policy deployment and enforce firewall, WAF, and DDoS protections across AWS resources, reducing manual management overhead.

#AWS #AwsFirewallManager #AwsWaf #AwsShield #NewService
AWS Network Security Manager is now generally available in US East (N. Virginia) Region
Today, AWS announces the general availability of AWS Network Security Manager, a comprehensive network security management solution designed to simplify security policy deployment and enforcement at scale. Network Security Manager supports AWS WAF and AWS Shield Advanced, with support for AWS Network Firewall soon to follow. AWS Network Security Manager enables security teams to consistently enforce firewall and DDoS protection configurations across their entire AWS organization. Network Security Manager features always-on security deployment automation that applies AWS WAD and AWS Sheild Advanced security protection to Internet facing assets like AWS Application Load Balancer and Amazon CloudFront. This automated approach helps security teams deploy and manage WAF rules and Shield Advanced protections efficiently, ensuring consistent security posture across targeted accounts and resources. Teams can centrally manage security policies, automatically detect configuration drift, and apply remediation reducing the operational overhead of manual security management while maintaining comprehensive protection. AWS Network Security Manager is generally available in US East (N. Virginia). For pricing information, visit the AWS Network Security Manager Pricing page.
aws.amazon.com
September 24, 2026 at 9:10 PM
AWS Network Security Manager is now generally available in US East (N. Virginia) Region
Today, AWS announces the general availability of AWS Network Security Manager, a comprehensive network security management solution designed to simplify security policy deployment and enforcement at scale. Network Security Manager supports AWS WAF and AWS Shield Advanced, with support for AWS Network Firewall soon to follow. AWS Network Security Manager enables security teams to consistently enforce firewall and DDoS protection configurations across their entire AWS organization. Network Security Manager features always-on security deployment automation that applies AWS WAD and AWS Sheild Advanced security protection to Internet facing assets like AWS Application Load Balancer and Amazon CloudFront. This automated approach helps security teams deploy and manage WAF rules and Shield Advanced protections efficiently, ensuring consistent security posture across targeted accounts and resources. Teams can centrally manage security policies, automatically detect configuration drift, and apply remediation reducing the operational overhead of manual security management while maintaining comprehensive protection. AWS Network Security Manager is generally available in US East (N. Virginia). For pricing information, visit the AWS Network Security Manager Pricing page.
dlvr.it
September 24, 2026 at 9:04 PM
Why is AWS Network Firewall so expensive? #aws #cloud #firewall
November 19, 2024 at 8:55 AM
AWS Network Firewall enhances application layer traffic controls - AWS aws.amazon.com/about-aws/wh...
AWS Network Firewall enhances application layer traffic controls - AWS
Discover more about what's new at AWS with AWS Network Firewall enhances application layer traffic controls
aws.amazon.com
September 26, 2025 at 7:48 AM
AWS Network Firewall enhances application layer traffic controls - AWS aws.amazon.com/about-aws/wh...
AWS Network Firewall enhances application layer traffic controls - AWS
Discover more about what's new at AWS with AWS Network Firewall enhances application layer traffic controls
aws.amazon.com
September 26, 2025 at 7:59 AM
AWS Network Security Manager is now generally available in US East (N. Virginia) Region

Today, AWS announces the general availability of AWS Network Security Manager, a comprehensive network security management solution designed to simplif...

#AWS #AwsFirewallManager #AwsWaf #AwsShield #NewService
AWS Network Security Manager is now generally available in US East (N. Virginia) Region
Today, AWS announces the general availability of AWS Network Security Manager, a comprehensive network security management solution designed to simplify security policy deployment and enforcement at scale. Network Security Manager supports AWS WAF and AWS Shield Advanced, with support for AWS Network Firewall soon to follow. AWS Network Security Manager enables security teams to consistently enforce firewall and DDoS protection configurations across their entire AWS organization. Network Security Manager features always-on security deployment automation that applies AWS WAD and AWS Sheild Advanced security protection to Internet facing assets like AWS Application Load Balancer and Amazon CloudFront. This automated approach helps security teams deploy and manage WAF rules and Shield Advanced protections efficiently, ensuring consistent security posture across targeted accounts and resources. Teams can centrally manage security policies, automatically detect configuration drift, and apply remediation reducing the operational overhead of manual security management while maintaining comprehensive protection. AWS Network Security Manager is generally available in US East (N. Virginia). For pricing information, visit the https://aws.amazon.com/network-security-manager/pricing/.
aws.amazon.com
September 24, 2026 at 9:05 PM
Why you need strict outbound network rules. Restrict to trusted domains with AWS DNS security controls. Block DGAs, unnecessary protocols and more with AWS Firewall.

AWS re:Invent - Reduce your risk exposure with least privilege egress controls (SEC322)

m.youtube.com/watch?v=Mjko...
December 18, 2024 at 2:54 PM
📰 New article by Diego Dalmolin, Veeramani A

Dive Deep into the AWS Transform Network Migration Agent: Hub and Spoke Network Setup

#AWS #Migrations #Modernization
Dive Deep into the AWS Transform Network Migration Agent: Hub and Spoke Network Setup
Introduction Network design takes real effort in any migration. You need to map source network segments to VPCs, plan subnets across Availability Zones, translate firewall rules into security groups, and configure route tables that keep traffic flowing, a challenge the AWS Transform – Migrations network migration agent solves for you. You upload exports from well-known [...]
aws.amazon.com
September 4, 2026 at 3:11 PM
Infoblox、AWSと連携し革新的な脅威防御ソリューションを発表#東京都#港区#AWS#サイバーセキュリティ#Infoblox

InfobloxがAWS Network Firewall向けに予測型DNSベース脅威防御ソリューションを発表。手動ルール管理を削減し、迅速なセキュリティを実現します。
Infoblox、AWSと連携し革新的な脅威防御ソリューションを発表
InfobloxがAWS Network Firewall向けに予測型DNSベース脅威防御ソリューションを発表。手動ルール管理を削減し、迅速なセキュリティを実現します。
news.3rd-in.co.jp
November 20, 2025 at 3:44 AM