SOC Update (21-25 October 2019)

Progress / Completed Projects & Tasks


Plan / Work in progress


Roadblocks / Problems


Notable Incidents
SOC-10
Summary
EC2 instance Abusive Brute Force Activity from Instance ID i-059a85c5c601dcf27 [52.221.215.54] towards Sony Interactive Entertainment. Instance belongs to tvlk-cri-dev aws account.

RCA: unrestricted security groups policy applied/ User operator error.
Status: Resolved
JIRA incident ticket: AWS Ticket 18118678292
Impact: Internal: minimal. External: Blacklisting of tvlk-cri-dev IP Addresses on Sony network.

Details at: https://29022131.atlassian.net/browse/SOC-10