Python (Boto3) for AWS
"AWSome scripts, Pythonic way" - a hands-on session on automating AWS security tasks with Python3 and Boto3, requiring only minimal AWS/Python knowledge to start.
Key Takeaways
- Assumed baseline: AWS console access, IAM basics, EC2 operations, S3 buckets, ELB awareness, and prior security group use - plus minimal Python (data types, control statements, functions, lists/tuples/dicts,
pipinstalls). - Hands-on scripts built in the session: AWS resource inventory, listing public S3 buckets, listing IAM details, finding security groups exposed to the internet, getting ELB public IPs for follow-up scanning, and finding orphaned security groups.
- Broader AWS practice exercises referenced: creating IAM users/groups/roles via CLI, spinning up EC2 instances with different security groups, making one S3 bucket public and one private (then correctly encrypting/securing them), building separate security groups per service (web/mysql/mongo/ssh), attaching instances to load balancers, checking AWS Config for non-compliant resources, and reviewing CloudTrail/CloudWatch output.
- Core message: security automation in Python/Boto3 turns manual security reviews (checking IAM policies, hunting public buckets, auditing security groups) into repeatable scripts you can run on a schedule or in CI/CD.
Go Deeper
- Python for AWS - the full written guide with code examples on this site
- Python Track Introduction
- IAM Security, S3 Security
- python-for-cybersecurity repo for more code-along scripts