Hero guide: Security
This guide highlights sessions at re:Invent 2024 that will help you learn about advanced threat detection, secure your AI environments, stay updated on compliance rules, and protect your web applications and your network.

Sena Yakut
AWS Security Hero
Security isn’t just a priority; it’s the foundation of any resilient cloud environment. In the dynamic world of AWS, staying ahead of potential threats and ensuring compliance is critical for anyone involved in building and maintaining cloud infrastructures. Whether you're a security professional, DevOps engineer, compliance officer, cloud administrator, IT manager, or developer, understanding how to integrate and elevate security within your AWS workloads is paramount.
I've prepared this guide based on your requirements—I've seen and been there before. With the belief that security is not just a priority but the foundation of everything, this guide helps you navigate the most impactful security sessions at re: Invent 2024 with a focus on practical, cloud-native security solutions as well as the insights and tools needed to stay ahead in an ever-evolving security landscape. Prepare to expand your knowledge, challenge your current strategies, and discover new ways to secure your AWS workloads.
Breakout session
CDN303 | I didn’t know AWS WAF did this
Securing web applications in today’s ever-evolving threat landscape is crucial. As threats evolve, so must security controls and countermeasures. In this chalk talk, dive into how AWS WAF seamlessly integrates with other AWS services, making it possible for you to construct a resilient, multi-layered defense strategy. Learn about uncommon use cases and how to address even the most unconventional threats.
SVS324 | Implementing security best practices for serverless applications
Building with serverless enables organizations to build and deploy applications without managing underlying infrastructure. Serverless strengthens your overall security posture by reducing attack surface and shifting security operations to AWS. In this session, explore how to implement security best practices across the software delivery lifecycle and into production deployment. Hear lessons learned from working with numerous enterprise customers that can help your builders be productive and innovative within security guardrails.
Builders' session
SVS301-R | Architecting for data protection and compliance with Amazon ECS [REPEAT]
Many organizations running containerized workloads need to ensure that they are meeting stringent data protection and compliance requirements, including those pertaining to the HIPAA Privacy and Security Rules for securing protected health information (PHI). This builders’ session focuses on how you can use Amazon ECS and other AWS services to run container applications containing PHI. Learn best practices with Amazon ECS, Amazon ECR, AWS Fargate, Amazon GuardDuty, and more. You must bring your laptop to participate.
Chalk talk
IOT301-R | Preparing for the US Cyber Trust Mark: A guide for AWS IoT developers [REPEAT]
The US Cyber Trust Mark program is set to roll out in late 2024, providing a new benchmark for IoT device security. In this chalk talk, get a guide for AWS IoT developers on how to prepare for the program. Explore the program’s criteria, which include asset identification, data protection, and software updates, among others. Also learn how AWS IoT services can be used to meet these criteria and help you achieve US Cyber Trust Mark certification.
Code talk
SEC401 | Inspect and secure your application with generative AI
Explore how to use generative AI to improve the security of your applications. Learn how AI-powered tools can help rapidly identify and then recommend remediations for security threats. Learn about how Amazon Inspector detects software and code vulnerabilities in your applications, and discover how to scan for issues and remediate them using generative AI in your IDE.
Workshop
SEC301-R | Threat detection and response using AWS security services [REPEAT]
Join AWS security experts for an immersive threat detection and response workshop using native security services to detect threats across different workloads. Learn about common threat types, how to detect them, and how to prioritize a response. This workshop simulates several security events across different resources and behaviors. Get hands-on in a provided sandbox environment to review and respond to findings from the simulated events. You must bring your laptop to participate.
SEC304 | Mitigate zero-day events and ransomware risks with VPC egress controls
In this network security workshop, learn how to implement AWS best practices for egress controls to mitigate risks from software supply chain dependencies, zero-day events, cryptocurrency mining, and ransomware. Also, explore a new security use case enabled by TLS decryption of outbound network flows. You must bring your laptop to participate.
SEC305 | Generative AI–based code remediations and patch management at scale
In this workshop, get hands-on experience with multiple vulnerability solutions to provide automated generative AI–based code remediation for AWS Lambda functions, manage software vulnerabilities in container images, and approach patch management for Amazon EC2 instances at scale. Learn how to use AWS security tools to detect vulnerabilities in different workloads, implement a patching policy for software packages, and use generative AI to recommend code changes. You must bring your laptop to participate.
SEC306 | Securing your generative AI applications on AWS
In this workshop, discover how to secure generative AI applications using AWS services and features. Explore how to deploy a vulnerable sample generative AI application and then layer security controls to protect, detect, and respond to security issues. Learn how to apply similar controls to the generative AI applications in your organization. You must bring your laptop to participate.
CDN301-R | Get hands-on with fraud prevention using AWS WAF [REPEAT]
Traffic from malicious bots can lead to negative user experiences, financial losses, and operational bottlenecks ranging from add-to-cart attacks that disrupt your web applications to distributed denial of service (DDoS) attacks that increase your infrastructure costs. In this workshop, explore how AWS uses a combination of techniques to identify and mitigate different types of bots and fraudulent activities. Gain valuable insights into how AWS WAF and Amazon CloudFront work together to safeguard and deliver your applications. You must bring your laptop to participate.
SUP302-R | Detect, investigate & respond to security scenarios with generative AI [REPEAT]
In this workshop, participate in an interactive tabletop exercise covering threat vectors like exposed AWS access keys, insecure security group ports, and unauthorized resource launches. Through engaging role-play, take on an incident response persona, strategizing and working together to defend an organization from security threats and dilemmas. Learn how to correlate data from sources including AWS CloudTrail, IAM Access Analyzer, AWS Config, and AWS Trusted Advisor using Amazon Q. Discover how to respond to incidents using AWS Systems Manager, AWS Lambda, and Amazon CloudWatch Events. Learn how AWS programs can help you prepare for the unexpected. You must bring your laptop to participate.
SUP402-R | Intelligently automating cloud operations [REPEAT]
Join this workshop to learn how to use AWS Health, AWS Trusted Advisor, and AWS generative AI and machine learning services to intelligently automate cloud operations. Also learn how to use Amazon EventBridge and AWS Lambda to create automations that organizations can use to optimize their cloud infrastructure, improve efficiency, and reduce operational costs. This workshop is designed for cloud administrators, DevOps engineers, site reliability engineers, and IT professionals who are responsible for managing and optimizing cloud operations. You must bring your laptop to participate.
Closing comments
To get the most out of re:Invent 2024, I highly recommend coming prepared with specific goals and questions related to your organization's needs. Take advantage of the hands-on workshops and interactive sessions to deepen your understanding of AWS services, security, and their practical applications. Networking with peers and AWS experts can provide invaluable insights and potential collaborations.
Finally, make sure to explore the new and emerging technologies showcased at the event, as these offer innovative solutions to your current and future challenges. With careful planning and active participation, re: Invent 2024 can be a transformative experience for both your personal development and your organization's success.