{"id":15285,"date":"2024-04-13T23:45:23","date_gmt":"2024-04-13T20:15:23","guid":{"rendered":"https:\/\/www.itpiran.net\/blog\/?p=15285"},"modified":"2024-04-13T23:45:23","modified_gmt":"2024-04-13T20:15:23","slug":"using-terraform-to-configure-automated-guardduty","status":"publish","type":"post","link":"https:\/\/www.itpiran.net\/blog\/en\/amazon\/using-terraform-to-configure-automated-guardduty\/","title":{"rendered":"How to configure automated incident response for Amazon GuardDuty findings with Terraform"},"content":{"rendered":"<h2 id=\"%d9%85%d9%82%d8%af%d9%85%d9%87\">\u0645\u0642\u062f\u0645\u0647<\/h2>\n<p>\u062f\u0631 \u0627\u06cc\u0646 \u0622\u0645\u0648\u0632\u0634\u060c \u0646\u062d\u0648\u0647 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u0631\u0627\u0647 \u062d\u0644 \u0627\u0645\u0646\u06cc\u062a\u06cc AWS \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 Terraform \u0631\u0627 \u062e\u0648\u0627\u0647\u06cc\u062f \u0622\u0645\u0648\u062e\u062a. \u0634\u0645\u0627 \u0627\u0632 \u062e\u062f\u0645\u0627\u062a Amazon GuardDuty\u060c Amazon SNS\u060c AWS Lambda \u0648 Amazon EvenBridge \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u062e\u0648\u0627\u0647\u06cc\u062f \u06a9\u0631\u062f.<\/p>\n<p>\u062a\u0634\u062e\u06cc\u0635 \u062a\u0647\u062f\u06cc\u062f \u0648 \u067e\u0627\u0633\u062e \u0628\u0647 \u062d\u0627\u062f\u062b\u0647 (TDIR) \u0645\u06cc \u062a\u0648\u0627\u0646\u062f \u0628\u0631\u0627\u06cc \u0628\u0633\u06cc\u0627\u0631\u06cc \u0627\u0632 \u0633\u0627\u0632\u0645\u0627\u0646 \u0647\u0627 \u0641\u0631\u0622\u06cc\u0646\u062f\u06cc \u0632\u0645\u0627\u0646 \u0628\u0631 \u0648 \u062f\u0633\u062a\u06cc \u0628\u0627\u0634\u062f. \u0627\u06cc\u0646 \u0645\u0646\u062c\u0631 \u0628\u0647 \u0641\u0631\u0622\u06cc\u0646\u062f\u0647\u0627\u06cc \u067e\u0627\u0633\u062e \u0646\u0627\u0633\u0627\u0632\u06af\u0627\u0631\u060c \u0646\u062a\u0627\u06cc\u062c \u0627\u0645\u0646\u06cc\u062a\u06cc \u0646\u0627\u0633\u0627\u0632\u06af\u0627\u0631 \u0648 \u0627\u0641\u0632\u0627\u06cc\u0634 \u0631\u06cc\u0633\u06a9 \u0645\u06cc \u0634\u0648\u062f. \u062f\u0631 \u0627\u06cc\u0646 \u0622\u0645\u0648\u0632\u0634\u060c \u06cc\u0627\u062f \u062e\u0648\u0627\u0647\u06cc\u062f \u06af\u0631\u0641\u062a \u06a9\u0647 \u0686\u06af\u0648\u0646\u0647 \u06cc\u0627\u0641\u062a\u0647 \u0647\u0627\u06cc \u062a\u0634\u062e\u06cc\u0635 \u062a\u0647\u062f\u06cc\u062f \u0631\u0627 \u062e\u0648\u062f\u06a9\u0627\u0631 \u06a9\u0646\u06cc\u062f \u0648 \u0641\u0631\u0622\u06cc\u0646\u062f \u067e\u0627\u0633\u062e \u0628\u0647 \u062d\u0627\u062f\u062b\u0647 \u062e\u0648\u062f \u0631\u0627 \u062e\u0648\u062f\u06a9\u0627\u0631 \u06a9\u0646\u06cc\u062f \u0648 \u0632\u0645\u0627\u0646 \u067e\u0627\u0633\u062e\u06af\u0648\u06cc\u06cc \u0628\u0647 \u062a\u0647\u062f\u06cc\u062f\u0627\u062a \u0631\u0627 \u06a9\u0627\u0647\u0634 \u062f\u0647\u06cc\u062f. \u0627\u0632 \u0622\u0646\u062c\u0627\u06cc\u06cc \u06a9\u0647 \u0628\u0633\u06cc\u0627\u0631\u06cc \u0627\u0632 \u0633\u0627\u0632\u0645\u0627\u0646\u200c\u0647\u0627 \u062a\u0631\u062c\u06cc\u062d \u0645\u06cc\u200c\u062f\u0647\u0646\u062f \u0627\u0632 \u0627\u0628\u0632\u0627\u0631 \u0627\u0633\u062a\u0627\u0646\u062f\u0627\u0631\u062f \u0632\u06cc\u0631\u0633\u0627\u062e\u062a \u0628\u0647\u200c\u0639\u0646\u0648\u0627\u0646 \u06a9\u062f (IaC) \u0628\u0631\u0627\u06cc \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc\u200c\u0647\u0627\u06cc \u062b\u0627\u0628\u062a \u062f\u0631 \u0645\u06cc\u0627\u0646 \u0641\u0631\u0648\u0634\u0646\u062f\u06af\u0627\u0646 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u0646\u062f\u060c \u0627\u06cc\u0646 \u0622\u0645\u0648\u0632\u0634 \u0646\u062d\u0648\u0647 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u0627\u06cc\u0646 \u0631\u0627\u0647\u200c\u062d\u0644 \u0631\u0627 \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 Terraform \u0646\u0634\u0627\u0646 \u0645\u06cc\u200c\u062f\u0647\u062f.<\/p>\n<h5 id=\"%d9%be%db%8c%d8%b4-%d9%86%db%8c%d8%a7%d8%b2%d9%87%d8%a7\">\u067e\u06cc\u0634 \u0646\u06cc\u0627\u0632\u0647\u0627<\/h5>\n<ul>\n<li>\u062d\u0633\u0627\u0628 AWS<\/li>\n<\/ul>\n<h2 id=\"%d8%af%d8%b1%d8%a8%d8%a7%d8%b1%d9%87-amazon-guardduty\">\u062f\u0631\u0628\u0627\u0631\u0647 Amazon GuardDuty<\/h2>\n<p>\u0642\u0628\u0644 \u0627\u0632 \u0627\u06cc\u0646\u06a9\u0647 \u0648\u0627\u0631\u062f \u0622\u0645\u0648\u0632\u0634 \u0634\u0648\u06cc\u0645\u060c \u062f\u0631\u06a9 \u0639\u0645\u0644\u06a9\u0631\u062f \u0627\u0633\u0627\u0633\u06cc \u0628\u0631\u062e\u06cc \u0627\u0632 \u0627\u0628\u0632\u0627\u0631\u0647\u0627\u06cc\u06cc \u06a9\u0647 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u062e\u0648\u0627\u0647\u06cc\u0645 \u06a9\u0631\u062f \u0645\u0641\u06cc\u062f \u0627\u0633\u062a. Amazon GuardDuty \u062a\u0634\u062e\u06cc\u0635 \u062a\u0647\u062f\u06cc\u062f \u0631\u0627 \u0627\u0631\u0627\u0626\u0647 \u0645\u06cc \u062f\u0647\u062f \u06a9\u0647 \u0628\u0647 \u0634\u0645\u0627 \u0627\u0645\u06a9\u0627\u0646 \u0645\u06cc \u062f\u0647\u062f \u0628\u0647 \u0637\u0648\u0631 \u0645\u062f\u0627\u0648\u0645 \u062d\u0633\u0627\u0628 \u0647\u0627\u06cc AWS\u060c \u0628\u0627\u0631\u0647\u0627\u06cc \u06a9\u0627\u0631\u06cc \u0648 \u062f\u0627\u062f\u0647 \u0647\u0627\u06cc \u0630\u062e\u06cc\u0631\u0647 \u0634\u062f\u0647 \u062f\u0631 \u0633\u0631\u0648\u06cc\u0633 \u0630\u062e\u06cc\u0631\u0647 \u0633\u0627\u0632\u06cc \u0633\u0627\u062f\u0647 \u0622\u0645\u0627\u0632\u0648\u0646 (S3) \u0631\u0627 \u0646\u0638\u0627\u0631\u062a \u0648 \u0645\u062d\u0627\u0641\u0638\u062a \u06a9\u0646\u06cc\u062f. GuardDuty \u062c\u0631\u06cc\u0627\u0646\u200c\u0647\u0627\u06cc \u0645\u062a\u0627\u062f\u06cc\u062a\u0627\u06cc \u067e\u06cc\u0648\u0633\u062a\u0647 \u062a\u0648\u0644\u06cc\u062f \u0634\u062f\u0647 \u0627\u0632 \u062d\u0633\u0627\u0628 \u0648 \u0641\u0639\u0627\u0644\u06cc\u062a \u0634\u0628\u06a9\u0647 \u0634\u0645\u0627 \u0631\u0627 \u06a9\u0647 \u062f\u0631 \u0631\u0648\u06cc\u062f\u0627\u062f\u0647\u0627\u06cc AWS CloudTrail\u060c \u06af\u0632\u0627\u0631\u0634\u200c\u0647\u0627\u06cc \u062c\u0631\u06cc\u0627\u0646 \u0627\u0628\u0631 \u062e\u0635\u0648\u0635\u06cc \u0645\u062c\u0627\u0632\u06cc \u0622\u0645\u0627\u0632\u0648\u0646 (VPC) \u0648 \u06af\u0632\u0627\u0631\u0634\u200c\u0647\u0627\u06cc \u0633\u06cc\u0633\u062a\u0645 \u0646\u0627\u0645 \u062f\u0627\u0645\u0646\u0647 (DNS) \u06cc\u0627\u0641\u062a \u0645\u06cc\u200c\u0634\u0648\u062f\u060c \u062a\u062c\u0632\u06cc\u0647 \u0648 \u062a\u062d\u0644\u06cc\u0644 \u0645\u06cc\u200c\u06a9\u0646\u062f. GuardDuty \u0647\u0645\u0686\u0646\u06cc\u0646 \u0627\u0632 \u0647\u0648\u0634 \u062a\u0647\u062f\u06cc\u062f \u06cc\u06a9\u067e\u0627\u0631\u0686\u0647 \u0645\u0627\u0646\u0646\u062f \u0622\u062f\u0631\u0633 \u0647\u0627\u06cc IP \u0645\u062e\u0631\u0628 \u0634\u0646\u0627\u062e\u062a\u0647 \u0634\u062f\u0647\u060c \u062a\u0634\u062e\u06cc\u0635 \u0646\u0627\u0647\u0646\u062c\u0627\u0631\u06cc \u0648 \u06cc\u0627\u062f\u06af\u06cc\u0631\u06cc \u0645\u0627\u0634\u06cc\u0646 (ML) \u0628\u0631\u0627\u06cc \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u062f\u0642\u06cc\u0642 \u062a\u0631 \u062a\u0647\u062f\u06cc\u062f\u0647\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc \u06a9\u0646\u062f.<\/p>\n<p>GuardDuty \u06a9\u0627\u0645\u0644\u0627\u064b \u0645\u0633\u062a\u0642\u0644 \u0627\u0632 \u0645\u0646\u0627\u0628\u0639 \u0634\u0645\u0627 \u0639\u0645\u0644 \u0645\u06cc \u06a9\u0646\u062f\u060c \u0628\u0646\u0627\u0628\u0631\u0627\u06cc\u0646 \u0647\u06cc\u0686 \u062e\u0637\u0631\u06cc \u0628\u0631\u0627\u06cc \u062a\u0623\u062b\u06cc\u0631 \u0639\u0645\u0644\u06a9\u0631\u062f \u06cc\u0627 \u062f\u0631 \u062f\u0633\u062a\u0631\u0633 \u0628\u0648\u062f\u0646 \u0628\u0631 \u062d\u062c\u0645 \u06a9\u0627\u0631\u06cc \u0634\u0645\u0627 \u0648\u062c\u0648\u062f \u0646\u062f\u0627\u0631\u062f. \u0627\u06cc\u0646 \u0633\u0631\u0648\u06cc\u0633 \u0628\u0647 \u0637\u0648\u0631 \u06a9\u0627\u0645\u0644 \u0628\u0627 \u0627\u0637\u0644\u0627\u0639\u0627\u062a \u06cc\u06a9\u067e\u0627\u0631\u0686\u0647 \u062a\u0647\u062f\u06cc\u062f\u060c \u062a\u0634\u062e\u06cc\u0635 \u0646\u0627\u0647\u0646\u062c\u0627\u0631\u06cc \u0648 ML \u0645\u062f\u06cc\u0631\u06cc\u062a \u0645\u06cc \u0634\u0648\u062f. Amazon GuardDuty \u0647\u0634\u062f\u0627\u0631\u0647\u0627\u06cc \u062f\u0642\u06cc\u0642 \u0648 \u06a9\u0627\u0631\u0628\u0631\u062f\u06cc \u0631\u0627 \u0627\u0631\u0627\u0626\u0647 \u0645\u06cc \u062f\u0647\u062f \u06a9\u0647 \u0628\u0647 \u0631\u0627\u062d\u062a\u06cc \u0628\u0627 \u0633\u06cc\u0633\u062a\u0645 \u0647\u0627\u06cc \u0645\u062f\u06cc\u0631\u06cc\u062a \u0631\u0648\u06cc\u062f\u0627\u062f \u0648 \u06af\u0631\u062f\u0634 \u06a9\u0627\u0631 \u0645\u0648\u062c\u0648\u062f \u0627\u062f\u063a\u0627\u0645 \u0645\u06cc \u0634\u0648\u0646\u062f. \u0647\u06cc\u0686 \u0647\u0632\u06cc\u0646\u0647 \u0627\u0648\u0644\u06cc\u0647 \u0627\u06cc \u0648\u062c\u0648\u062f \u0646\u062f\u0627\u0631\u062f \u0648 \u0634\u0645\u0627 \u0641\u0642\u0637 \u0628\u0631\u0627\u06cc \u0631\u0648\u06cc\u062f\u0627\u062f\u0647\u0627\u06cc \u062a\u062c\u0632\u06cc\u0647 \u0648 \u062a\u062d\u0644\u06cc\u0644 \u0634\u062f\u0647 \u067e\u0631\u062f\u0627\u062e\u062a \u0645\u06cc \u06a9\u0646\u06cc\u062f\u060c \u0628\u062f\u0648\u0646 \u0646\u06cc\u0627\u0632 \u0628\u0647 \u0646\u0631\u0645 \u0627\u0641\u0632\u0627\u0631 \u0627\u0636\u0627\u0641\u06cc \u0628\u0631\u0627\u06cc \u0627\u0633\u062a\u0642\u0631\u0627\u0631 \u06cc\u0627 \u0627\u0634\u062a\u0631\u0627\u06a9 \u0641\u06cc\u062f \u0627\u0637\u0644\u0627\u0639\u0627\u062a\u06cc \u062a\u0647\u062f\u06cc\u062f.<\/p>\n<h2 id=\"%d8%af%d8%b1%d8%a8%d8%a7%d8%b1%d9%87-terraform-%d9%88-cloud9\">\u062f\u0631\u0628\u0627\u0631\u0647 Terraform \u0648 Cloud9<\/h2>\n<p>Terraform \u06cc\u06a9 \u0627\u0628\u0632\u0627\u0631 Infrastructure-as-Code (IaC) \u0627\u0633\u062a \u06a9\u0647 \u062a\u0648\u0633\u0637 Hashicorp \u0627\u06cc\u062c\u0627\u062f \u0634\u062f\u0647 \u0627\u0633\u062a \u06a9\u0647 \u0628\u0647 \u0634\u0645\u0627 \u0627\u0645\u06a9\u0627\u0646 \u0645\u06cc \u062f\u0647\u062f \u0632\u06cc\u0631\u0633\u0627\u062e\u062a \u0631\u0627 \u0628\u0627 \u0641\u0627\u06cc\u0644 \u0647\u0627\u06cc \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u0628\u0647 \u062c\u0627\u06cc \u0631\u0627\u0628\u0637 \u06a9\u0627\u0631\u0628\u0631\u06cc \u0645\u062f\u06cc\u0631\u06cc\u062a \u06a9\u0646\u06cc\u062f. \u0628\u0627 Terraform \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u06cc\u062f \u0632\u06cc\u0631\u0633\u0627\u062e\u062a\u200c\u0647\u0627\u06cc \u062e\u0648\u062f \u0631\u0627 \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0641\u0627\u06cc\u0644\u200c\u0647\u0627\u06cc \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u062e\u0648\u0627\u0646\u0627 \u0648 \u0627\u0639\u0644\u0627\u0645\u06cc \u0628\u0633\u0627\u0632\u06cc\u062f\u060c \u062a\u063a\u06cc\u06cc\u0631 \u062f\u0647\u06cc\u062f \u0648 \u0646\u0627\u0628\u0648\u062f \u06a9\u0646\u06cc\u062f. \u0628\u0644\u0647\u060c \u0634\u0645\u0627 \u0647\u0645\u0686\u0646\u06cc\u0646 \u0645\u06cc \u062a\u0648\u0627\u0646\u06cc\u062f \u0632\u06cc\u0631\u0633\u0627\u062e\u062a AWS \u0631\u0627 \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 Terraform \u0628\u0633\u0627\u0632\u06cc\u062f\u060c \u062a\u063a\u06cc\u06cc\u0631 \u062f\u0647\u06cc\u062f \u0648 \u0627\u0632 \u0628\u06cc\u0646 \u0628\u0628\u0631\u06cc\u062f &#8211; \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u06cc\u06a9 \u067e\u0644\u0627\u06af\u06cc\u0646 Terraform \u0628\u0647 \u0646\u0627\u0645 Provider. \u0627\u0631\u0627\u0626\u0647 \u062f\u0647\u0646\u062f\u0647 AWS \u0628\u0647 Terraform \u0627\u062c\u0627\u0632\u0647 \u0645\u06cc \u062f\u0647\u062f \u062a\u0627 \u0628\u0627 \u0631\u0627\u0628\u0637 \u0628\u0631\u0646\u0627\u0645\u0647 \u0646\u0648\u06cc\u0633\u06cc \u0628\u0631\u0646\u0627\u0645\u0647 AWS (API) \u062a\u0639\u0627\u0645\u0644 \u062f\u0627\u0634\u062a\u0647 \u0628\u0627\u0634\u062f.<\/p>\n<p>\u0627\u06cc\u0646 \u0622\u0645\u0648\u0632\u0634 \u0627\u0632 AWS Cloud9 \u0628\u0631\u0627\u06cc \u0627\u0646\u062c\u0627\u0645 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc Terraform \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc \u06a9\u0646\u062f. AWS Cloud9 \u06cc\u06a9 \u0645\u062d\u06cc\u0637 \u062a\u0648\u0633\u0639\u0647 \u06cc\u06a9\u067e\u0627\u0631\u0686\u0647 \u0645\u0628\u062a\u0646\u06cc \u0628\u0631 \u0627\u0628\u0631 (IDE) \u0627\u0633\u062a \u06a9\u0647 \u0628\u0647 \u0634\u0645\u0627 \u0627\u0645\u06a9\u0627\u0646 \u0645\u06cc \u062f\u0647\u062f \u06a9\u062f \u062e\u0648\u062f \u0631\u0627 \u0641\u0642\u0637 \u0628\u0627 \u06cc\u06a9 \u0645\u0631\u0648\u0631\u06af\u0631 \u0628\u0646\u0648\u06cc\u0633\u06cc\u062f\u060c \u0627\u062c\u0631\u0627 \u06a9\u0646\u06cc\u062f \u0648 \u0627\u0634\u06a9\u0627\u0644 \u0632\u062f\u0627\u06cc\u06cc \u06a9\u0646\u06cc\u062f. \u0627\u06cc\u0646 \u0634\u0627\u0645\u0644 \u06cc\u06a9 \u0648\u06cc\u0631\u0627\u06cc\u0634\u06af\u0631 \u06a9\u062f\u060c \u062f\u06cc\u0628\u0627\u06af\u0631 \u0648 \u062a\u0631\u0645\u06cc\u0646\u0627\u0644 \u0627\u0633\u062a. Cloud9 \u0628\u0627 \u0627\u0628\u0632\u0627\u0631\u0647\u0627\u06cc \u0636\u0631\u0648\u0631\u06cc \u0628\u0631\u0627\u06cc \u0632\u0628\u0627\u0646 \u0647\u0627\u06cc \u0628\u0631\u0646\u0627\u0645\u0647 \u0646\u0648\u06cc\u0633\u06cc \u0645\u062d\u0628\u0648\u0628 \u0627\u0632 \u062c\u0645\u0644\u0647 \u062c\u0627\u0648\u0627 \u0627\u0633\u06a9\u0631\u06cc\u067e\u062a\u060c \u067e\u0627\u06cc\u062a\u0648\u0646\u060c PHP \u0648 Terraform \u0627\u0632 \u067e\u06cc\u0634 \u0628\u0633\u062a\u0647 \u0628\u0646\u062f\u06cc \u0634\u062f\u0647 \u0627\u0633\u062a\u060c \u0628\u0646\u0627\u0628\u0631\u0627\u06cc\u0646 \u0628\u0631\u0627\u06cc \u0631\u0627\u0647 \u0627\u0646\u062f\u0627\u0632\u06cc \u0627\u06cc\u0646 \u06a9\u0627\u0631\u06af\u0627\u0647 \u0646\u06cc\u0627\u0632\u06cc \u0628\u0647 \u0646\u0635\u0628 \u0641\u0627\u06cc\u0644 \u0647\u0627 \u06cc\u0627 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u062f\u0633\u062a\u06af\u0627\u0647 \u062a\u0648\u0633\u0639\u0647 \u062e\u0648\u062f \u0646\u062f\u0627\u0631\u06cc\u062f. Cloud9 \u0628\u0631 \u0631\u0648\u06cc \u06cc\u06a9 \u0646\u0645\u0648\u0646\u0647 EC2 \u0627\u062c\u0631\u0627 \u0645\u06cc \u0634\u0648\u062f \u06a9\u0647 \u0647\u0646\u06af\u0627\u0645 \u0634\u0631\u0648\u0639 \u0627\u06cc\u0646 \u06a9\u0627\u0631\u06af\u0627\u0647 \u0628\u0631\u0627\u06cc \u0634\u0645\u0627 \u0627\u06cc\u062c\u0627\u062f \u0634\u062f\u0647 \u0627\u0633\u062a.<\/p>\n<h2 id=\"%d8%a2%d9%86%da%86%d9%87-%d8%b4%d9%85%d8%a7-%d8%a7%d9%86%d8%ac%d8%a7%d9%85-%d8%ae%d9%88%d8%a7%d9%87%db%8c%d8%af-%d8%af%d8%a7%d8%af\">\u0622\u0646\u0686\u0647 \u0634\u0645\u0627 \u0627\u0646\u062c\u0627\u0645 \u062e\u0648\u0627\u0647\u06cc\u062f \u062f\u0627\u062f<\/h2>\n<ol>\n<li>\u06cc\u06a9 \u0645\u06cc\u0632\u0628\u0627\u0646 &#8220;\u0645\u062e\u0627\u0637\u0628&#8221; \u0628\u0627 \u06cc\u06a9 \u0645\u06cc\u0632\u0628\u0627\u0646 &#8220;\u062f\u0631 \u062e\u0637\u0631&#8221; \u062a\u0639\u0627\u0645\u0644 \u0645\u06cc \u06a9\u0646\u062f \u0648 \u0628\u0627\u0639\u062b \u0645\u06cc \u0634\u0648\u062f GuardDuty \u06cc\u06a9 \u06cc\u0627\u0641\u062a\u0647 \u0631\u0627 \u06af\u0632\u0627\u0631\u0634 \u06a9\u0646\u062f.<\/li>\n<li>\u0627\u06cc\u0646 \u06cc\u0627\u0641\u062a\u0647 \u062f\u0631 \u06cc\u06a9 \u0642\u0627\u0646\u0648\u0646 EventBridge \u06a9\u0647 \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 Terraform \u0627\u06cc\u062c\u0627\u062f \u062e\u0648\u0627\u0647\u06cc\u062f \u06a9\u0631\u062f\u060c \u0645\u0637\u0627\u0628\u0642\u062a \u062f\u0627\u062f\u0647 \u0645\u06cc \u0634\u0648\u062f. \u0642\u0627\u0646\u0648\u0646 EventBridge \u062f\u0648 \u06a9\u0627\u0631 \u0632\u06cc\u0631 \u0631\u0627 \u0627\u0646\u062c\u0627\u0645 \u0645\u06cc \u062f\u0647\u062f:<\/li>\n<li>\u06cc\u06a9 \u0642\u0627\u0646\u0648\u0646 SNS \u0631\u0627 \u0627\u06cc\u062c\u0627\u062f \u0645\u06cc \u06a9\u0646\u062f \u06a9\u0647 \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 Terraform \u0627\u06cc\u062c\u0627\u062f \u062e\u0648\u0627\u0647\u06cc\u062f \u06a9\u0631\u062f. \u0627\u06cc\u0646 \u0642\u0627\u0646\u0648\u0646 SNS \u06cc\u06a9 \u0627\u06cc\u0645\u06cc\u0644 \u0628\u0647 \u06cc\u06a9 \u0645\u062f\u06cc\u0631 \u062a\u0639\u0631\u06cc\u0641 \u0634\u062f\u0647 \u0628\u0627 \u0645\u062a\u0646\u06cc \u062e\u0648\u0627\u0646\u0627 \u0627\u0631\u0633\u0627\u0644 \u0645\u06cc \u06a9\u0646\u062f \u06a9\u0647 \u06cc\u0627\u0641\u062a\u0647 \u0647\u0627 \u0631\u0627 \u062a\u0648\u0636\u06cc\u062d \u0645\u06cc \u062f\u0647\u062f.<\/li>\n<li>\u06cc\u06a9 \u062a\u0627\u0628\u0639 Lambda \u0631\u0627 \u0641\u0639\u0627\u0644 \u0645\u06cc \u06a9\u0646\u062f \u06a9\u0647 \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 Terraform \u0627\u06cc\u062c\u0627\u062f \u062e\u0648\u0627\u0647\u06cc\u062f \u06a9\u0631\u062f. \u062a\u0627\u0628\u0639 Lambda \u0645\u06cc\u0632\u0628\u0627\u0646 \u062f\u0631 \u0645\u0639\u0631\u0636 \u062e\u0637\u0631 \u0631\u0627 \u0628\u0647 \u06cc\u06a9 \u06af\u0631\u0648\u0647 \u0627\u0645\u0646\u06cc\u062a\u06cc \u067e\u0632\u0634\u06a9\u06cc \u0642\u0627\u0646\u0648\u0646\u06cc \u0645\u0646\u062a\u0642\u0644 \u0645\u06cc \u06a9\u0646\u062f \u06a9\u0647 \u062f\u0631 \u0622\u0646\u062c\u0627 \u0628\u0631\u0627\u06cc \u0628\u0631\u0631\u0633\u06cc \u0628\u06cc\u0634\u062a\u0631 \u062c\u062f\u0627 \u0645\u06cc \u0634\u0648\u062f.<\/li>\n<\/ol>\n<h2 id=\"%d9%85%d8%b1%d8%ad%d9%84%d9%87-1-%d8%aa%d9%86%d8%b8%db%8c%d9%85%d8%a7%d8%aa-%d8%a7%d9%88%d9%84%db%8c%d9%87-%d8%b1%d8%a7-%d8%a8%d8%a7%d8%b1%da%af%db%8c%d8%b1%db%8c-%da%a9%d9%86%db%8c%d8%af\">\u0645\u0631\u062d\u0644\u0647 1. \u062a\u0646\u0638\u06cc\u0645\u0627\u062a \u0627\u0648\u0644\u06cc\u0647 \u0631\u0627 \u0628\u0627\u0631\u06af\u06cc\u0631\u06cc \u06a9\u0646\u06cc\u062f<\/h2>\n<p>\u0627\u06cc\u0646 \u0622\u0645\u0648\u0632\u0634 \u0627\u0632 \u06cc\u06a9 \u0627\u0644\u06af\u0648\u06cc AWS CloudFormation \u0628\u0631\u0627\u06cc \u062a\u0647\u06cc\u0647 \u0645\u0646\u0627\u0628\u0639 \u0627\u0648\u0644\u06cc\u0647 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc \u06a9\u0646\u062f. \u0627\u06cc\u0646 \u06a9\u0627\u0631 \u0628\u0647 \u0627\u06cc\u0646 \u062f\u0644\u06cc\u0644 \u0627\u0646\u062c\u0627\u0645 \u0645\u06cc \u0634\u0648\u062f \u06a9\u0647 \u0628\u062a\u0648\u0627\u0646\u06cc\u062f \u0641\u0642\u0637 \u0628\u0631 \u0631\u0648\u06cc \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u0632\u0645\u06cc\u0646\u06cc \u0631\u0627\u0647 \u062d\u0644 \u0627\u0645\u0646\u06cc\u062a\u06cc \u062e\u0648\u062f \u062a\u0645\u0631\u06a9\u0632 \u06a9\u0646\u06cc\u062f. \u0627\u0644\u06af\u0648\u06cc CloudFormation \u06cc\u06a9 \u067e\u0634\u062a\u0647 \u0627\u06cc\u062c\u0627\u062f \u0645\u06cc \u06a9\u0646\u062f. \u067e\u0634\u062a\u0647 \u0627\u0632 \u06cc\u06a9 \u0646\u0645\u0648\u0646\u0647 AWS Cloud9 IDE \u062a\u0634\u06a9\u06cc\u0644 \u0634\u062f\u0647 \u0627\u0633\u062a. \u0645\u0627 \u0627\u0632 \u0627\u06cc\u0646 \u0646\u0645\u0648\u0646\u0647 Cloud9 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc \u06a9\u0646\u06cc\u0645 \u062a\u0627 \u0647\u0645\u0647 \u06a9\u0633\u0627\u0646\u06cc \u06a9\u0647 \u0627\u06cc\u0646 \u0622\u0645\u0648\u0632\u0634 \u0631\u0627 \u0627\u062c\u0631\u0627 \u0645\u06cc \u06a9\u0646\u0646\u062f \u062a\u062c\u0631\u0628\u0647 \u0648\u06cc\u0631\u0627\u06cc\u0634 \u0648 \u067e\u06cc\u0627\u062f\u0647 \u0633\u0627\u0632\u06cc \u06cc\u06a9\u0633\u0627\u0646\u06cc \u062f\u0627\u0634\u062a\u0647 \u0628\u0627\u0634\u0646\u062f. \u0639\u0644\u0627\u0648\u0647 \u0628\u0631 \u0627\u06cc\u0646\u060c \u0647\u0646\u06af\u0627\u0645\u06cc \u06a9\u0647 \u067e\u0634\u062a\u0647 \u0631\u0627 \u062f\u0631 US-WEST-2 \u067e\u06cc\u0627\u062f\u0647 \u0633\u0627\u0632\u06cc \u0645\u06cc \u06a9\u0646\u06cc\u062f\u060c \u0645\u0637\u0645\u0626\u0646 \u0645\u06cc \u0634\u0648\u06cc\u062f \u06a9\u0647 \u06cc\u06a9 \u0646\u0645\u0648\u0646\u0647 t3.small \u0648\u062c\u0648\u062f \u062f\u0627\u0631\u062f. \u0627\u06af\u0631 \u0627\u0644\u06af\u0648 \u062f\u0631 \u0645\u0646\u0627\u0637\u0642 \u062f\u06cc\u06af\u0631 \u0645\u0633\u062a\u0642\u0631 \u0627\u0633\u062a\u060c \u0645\u0645\u06a9\u0646 \u0627\u0633\u062a \u0644\u0627\u0632\u0645 \u0628\u0627\u0634\u062f \u0627\u0644\u06af\u0648 \u0631\u0627 \u062a\u063a\u06cc\u06cc\u0631 \u062f\u0647\u06cc\u062f \u062a\u0627 \u0627\u0632 \u0646\u0648\u0639 \u0646\u0645\u0648\u0646\u0647 \u062f\u06cc\u06af\u0631\u06cc \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u062f \u0627\u06af\u0631 t3.small \u062f\u0631 \u062f\u0633\u062a\u0631\u0633 \u0646\u06cc\u0633\u062a.<\/p>\n<h5 id=\"1-1-%d8%a8%d9%87-aws-cloudformation-%d8%af%d8%b1-%da%a9%d9%86%d8%b3%d9%88%d9%84-%d9%85%d8%af%db%8c%d8%b1%db%8c%d8%aa-aws-%d8%a8%d8%b1%d9%88%db%8c%d8%af-%d9%88-%d8%a8%d8%a7-%da%a9%d9%84%db%8c%da%a9\">1.1. \u0628\u0647 AWS CloudFormation \u062f\u0631 \u06a9\u0646\u0633\u0648\u0644 \u0645\u062f\u06cc\u0631\u06cc\u062a AWS \u0628\u0631\u0648\u06cc\u062f \u0648 \u0628\u0627 \u06a9\u0644\u06cc\u06a9 \u0628\u0631 \u0631\u0648\u06cc \u062f\u06a9\u0645\u0647 \u0627\u06cc\u062c\u0627\u062f \u067e\u0634\u062a\u0647 \u06cc\u06a9 \u067e\u0634\u062a\u0647 \u0627\u06cc\u062c\u0627\u062f \u06a9\u0646\u06cc\u062f.<\/h5>\n<h5 id=\"1-2-%d8%a2%d9%be%d9%84%d9%88%d8%af-%d9%81%d8%a7%db%8c%d9%84-%d8%a7%d9%84%da%af%d9%88-%d8%b1%d8%a7-%d8%a7%d9%86%d8%aa%d8%ae%d8%a7%d8%a8-%da%a9%d9%86%db%8c%d8%af-%d9%88-%d9%81%d8%a7%db%8c%d9%84-gd-iac\"><img  loading=\"lazy\"  decoding=\"async\"  src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABAQMAAAAl21bKAAAAA1BMVEUAAP+KeNJXAAAAAXRSTlMAQObYZgAAAAlwSFlzAAAOxAAADsQBlSsOGwAAAApJREFUCNdjYAAAAAIAAeIhvDMAAAAASUVORK5CYII=\"  alt=\"\"  width=\"750\"  height=\"400\"  class=\"aligncenter wp-image-15286 size-full pk-lazyload\"  data-pk-sizes=\"auto\"  data-ls-sizes=\"auto, (max-width: 750px) 100vw, 750px\"  data-pk-src=\"https:\/\/cdn.itpiran.net\/2024\/04\/13200753\/1-2.webp\"  data-pk-srcset=\"https:\/\/cdn.itpiran.net\/2024\/04\/13200753\/1-2.webp 750w, https:\/\/cdn.itpiran.net\/2024\/04\/13200753\/1-2-300x160.webp 300w, https:\/\/cdn.itpiran.net\/2024\/04\/13200753\/1-2-110x59.webp 110w, https:\/\/cdn.itpiran.net\/2024\/04\/13200753\/1-2-200x107.webp 200w, https:\/\/cdn.itpiran.net\/2024\/04\/13200753\/1-2-380x203.webp 380w, https:\/\/cdn.itpiran.net\/2024\/04\/13200753\/1-2-255x136.webp 255w, https:\/\/cdn.itpiran.net\/2024\/04\/13200753\/1-2-550x293.webp 550w\" ><br \/>\n1.2. \u0622\u067e\u0644\u0648\u062f \u0641\u0627\u06cc\u0644 \u0627\u0644\u06af\u0648 \u0631\u0627 \u0627\u0646\u062a\u062e\u0627\u0628 \u06a9\u0646\u06cc\u062f \u0648 \u0641\u0627\u06cc\u0644 gd-iac-initial.yml \u0631\u0627 \u0627\u0632 \u0645\u062e\u0632\u0646 \u06a9\u062f \u0646\u0645\u0648\u0646\u0647 \u0627\u0631\u0627\u0626\u0647 \u0634\u062f\u0647 \u062f\u0631 \u0628\u0627\u0644\u0627 \u0622\u067e\u0644\u0648\u062f \u06a9\u0646\u06cc\u062f. \u0633\u067e\u0633 \u0631\u0648\u06cc Next \u06a9\u0644\u06cc\u06a9 \u06a9\u0646\u06cc\u062f.<\/h5>\n<h5 id=\"1-3-%db%8c%da%a9-%d9%86%d8%a7%d9%85-%d9%be%d8%b4%d8%aa%d9%87-%d9%88%d8%a7%d8%b1%d8%af-%da%a9%d9%86%db%8c%d8%af-%d9%88-%d8%b1%d9%88%db%8c-next-%da%a9%d9%84%db%8c%da%a9-%da%a9%d9%86%db%8c%d8%af\"><img  loading=\"lazy\"  decoding=\"async\"  src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABAQMAAAAl21bKAAAAA1BMVEUAAP+KeNJXAAAAAXRSTlMAQObYZgAAAAlwSFlzAAAOxAAADsQBlSsOGwAAAApJREFUCNdjYAAAAAIAAeIhvDMAAAAASUVORK5CYII=\"  alt=\"\"  width=\"750\"  height=\"400\"  class=\"aligncenter wp-image-15287 size-full pk-lazyload\"  data-pk-sizes=\"auto\"  data-ls-sizes=\"auto, (max-width: 750px) 100vw, 750px\"  data-pk-src=\"https:\/\/cdn.itpiran.net\/2024\/04\/13201015\/2-3.webp\"  data-pk-srcset=\"https:\/\/cdn.itpiran.net\/2024\/04\/13201015\/2-3.webp 750w, https:\/\/cdn.itpiran.net\/2024\/04\/13201015\/2-3-300x160.webp 300w, https:\/\/cdn.itpiran.net\/2024\/04\/13201015\/2-3-110x59.webp 110w, https:\/\/cdn.itpiran.net\/2024\/04\/13201015\/2-3-200x107.webp 200w, https:\/\/cdn.itpiran.net\/2024\/04\/13201015\/2-3-380x203.webp 380w, https:\/\/cdn.itpiran.net\/2024\/04\/13201015\/2-3-255x136.webp 255w, https:\/\/cdn.itpiran.net\/2024\/04\/13201015\/2-3-550x293.webp 550w\" ><br \/>\n1.3. \u06cc\u06a9 \u0646\u0627\u0645 \u067e\u0634\u062a\u0647 \u0648\u0627\u0631\u062f \u06a9\u0646\u06cc\u062f \u0648 \u0631\u0648\u06cc Next \u06a9\u0644\u06cc\u06a9 \u06a9\u0646\u06cc\u062f.<\/h5>\n<h5 id=\"1-4-%d8%af%d8%b1-%d8%b5%d9%81%d8%ad%d9%87-configure-stack-options-%d8%b1%d9%88%db%8c-next-%da%a9%d9%84%db%8c%da%a9-%da%a9%d9%86%db%8c%d8%af\"><img  loading=\"lazy\"  decoding=\"async\"  src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABAQMAAAAl21bKAAAAA1BMVEUAAP+KeNJXAAAAAXRSTlMAQObYZgAAAAlwSFlzAAAOxAAADsQBlSsOGwAAAApJREFUCNdjYAAAAAIAAeIhvDMAAAAASUVORK5CYII=\"  alt=\"\"  width=\"750\"  height=\"401\"  class=\"aligncenter wp-image-15288 size-full pk-lazyload\"  data-pk-sizes=\"auto\"  data-ls-sizes=\"auto, (max-width: 750px) 100vw, 750px\"  data-pk-src=\"https:\/\/cdn.itpiran.net\/2024\/04\/13205757\/3-3.webp\"  data-pk-srcset=\"https:\/\/cdn.itpiran.net\/2024\/04\/13205757\/3-3.webp 750w, https:\/\/cdn.itpiran.net\/2024\/04\/13205757\/3-3-300x160.webp 300w, https:\/\/cdn.itpiran.net\/2024\/04\/13205757\/3-3-110x59.webp 110w, https:\/\/cdn.itpiran.net\/2024\/04\/13205757\/3-3-200x107.webp 200w, https:\/\/cdn.itpiran.net\/2024\/04\/13205757\/3-3-380x203.webp 380w, https:\/\/cdn.itpiran.net\/2024\/04\/13205757\/3-3-255x136.webp 255w, https:\/\/cdn.itpiran.net\/2024\/04\/13205757\/3-3-550x294.webp 550w\" ><br \/>\n1.4. \u062f\u0631 \u0635\u0641\u062d\u0647 Configure stack options \u0631\u0648\u06cc Next \u06a9\u0644\u06cc\u06a9 \u06a9\u0646\u06cc\u062f.<\/h5>\n<h5 id=\"1-5-%d8%af%d8%b1-%d8%b5%d9%81%d8%ad%d9%87-%d8%a8%d8%b1%d8%b1%d8%b3%db%8c%d8%8c-%d8%a8%d9%87-%d9%be%d8%a7%db%8c%db%8c%d9%86-%d8%a8%d8%b1%d9%88%db%8c%d8%af-%d9%88-%d8%b1%d9%88%db%8c-%da%a9%d8%a7%d8%af\"><img  loading=\"lazy\"  decoding=\"async\"  src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABAQMAAAAl21bKAAAAA1BMVEUAAP+KeNJXAAAAAXRSTlMAQObYZgAAAAlwSFlzAAAOxAAADsQBlSsOGwAAAApJREFUCNdjYAAAAAIAAeIhvDMAAAAASUVORK5CYII=\"  alt=\"\"  width=\"750\"  height=\"401\"  class=\"aligncenter wp-image-15289 size-full pk-lazyload\"  data-pk-sizes=\"auto\"  data-ls-sizes=\"auto, (max-width: 750px) 100vw, 750px\"  data-pk-src=\"https:\/\/cdn.itpiran.net\/2024\/04\/13205845\/4-3.webp\"  data-pk-srcset=\"https:\/\/cdn.itpiran.net\/2024\/04\/13205845\/4-3.webp 750w, https:\/\/cdn.itpiran.net\/2024\/04\/13205845\/4-3-300x160.webp 300w, https:\/\/cdn.itpiran.net\/2024\/04\/13205845\/4-3-110x59.webp 110w, https:\/\/cdn.itpiran.net\/2024\/04\/13205845\/4-3-200x107.webp 200w, https:\/\/cdn.itpiran.net\/2024\/04\/13205845\/4-3-380x203.webp 380w, https:\/\/cdn.itpiran.net\/2024\/04\/13205845\/4-3-255x136.webp 255w, https:\/\/cdn.itpiran.net\/2024\/04\/13205845\/4-3-550x294.webp 550w\" ><br \/>\n1.5. \u062f\u0631 \u0635\u0641\u062d\u0647 \u0628\u0631\u0631\u0633\u06cc\u060c \u0628\u0647 \u067e\u0627\u06cc\u06cc\u0646 \u0628\u0631\u0648\u06cc\u062f \u0648 \u0631\u0648\u06cc \u06a9\u0627\u062f\u0631 \u062a\u0623\u06cc\u06cc\u062f \u06a9\u0644\u06cc\u06a9 \u06a9\u0646\u06cc\u062f \u062a\u0627 \u062a\u0623\u06cc\u06cc\u062f \u06a9\u0646\u06cc\u062f \u06a9\u0647 AWS CloudFormation \u0645\u0645\u06a9\u0646 \u0627\u0633\u062a \u0645\u0646\u0627\u0628\u0639 IAM \u0627\u06cc\u062c\u0627\u062f \u06a9\u0646\u062f\u060c \u0633\u067e\u0633 \u0631\u0648\u06cc Next \u06a9\u0644\u06cc\u06a9 \u06a9\u0646\u06cc\u062f.<\/h5>\n<h5 id=\"1-6-%d9%85%d8%b1%d8%a7%d9%82%d8%a8-%d8%a8%d8%a7%d8%b4%db%8c%d8%af-%da%a9%d9%87-%d9%be%d8%b4%d8%aa%d9%87-%d8%af%d8%b1-%d8%ad%d8%a7%d9%84%d8%aa-%d8%a7%db%8c%d8%ac%d8%a7%d8%af-%da%a9%d8%a7%d9%85%d9%84\"><img  loading=\"lazy\"  decoding=\"async\"  src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABAQMAAAAl21bKAAAAA1BMVEUAAP+KeNJXAAAAAXRSTlMAQObYZgAAAAlwSFlzAAAOxAAADsQBlSsOGwAAAApJREFUCNdjYAAAAAIAAeIhvDMAAAAASUVORK5CYII=\"  alt=\"\"  width=\"750\"  height=\"401\"  class=\"aligncenter wp-image-15290 size-full pk-lazyload\"  data-pk-sizes=\"auto\"  data-ls-sizes=\"auto, (max-width: 750px) 100vw, 750px\"  data-pk-src=\"https:\/\/cdn.itpiran.net\/2024\/04\/13205932\/5-3.webp\"  data-pk-srcset=\"https:\/\/cdn.itpiran.net\/2024\/04\/13205932\/5-3.webp 750w, https:\/\/cdn.itpiran.net\/2024\/04\/13205932\/5-3-300x160.webp 300w, https:\/\/cdn.itpiran.net\/2024\/04\/13205932\/5-3-110x59.webp 110w, https:\/\/cdn.itpiran.net\/2024\/04\/13205932\/5-3-200x107.webp 200w, https:\/\/cdn.itpiran.net\/2024\/04\/13205932\/5-3-380x203.webp 380w, https:\/\/cdn.itpiran.net\/2024\/04\/13205932\/5-3-255x136.webp 255w, https:\/\/cdn.itpiran.net\/2024\/04\/13205932\/5-3-550x294.webp 550w\" ><br \/>\n1.6. \u0645\u0631\u0627\u0642\u0628 \u0628\u0627\u0634\u06cc\u062f \u06a9\u0647 \u067e\u0634\u062a\u0647 \u062f\u0631 \u062d\u0627\u0644\u062a \u0627\u06cc\u062c\u0627\u062f \u06a9\u0627\u0645\u0644 \u0628\u0627\u0634\u062f.<\/h5>\n<p><img  loading=\"lazy\"  decoding=\"async\"  src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABAQMAAAAl21bKAAAAA1BMVEUAAP+KeNJXAAAAAXRSTlMAQObYZgAAAAlwSFlzAAAOxAAADsQBlSsOGwAAAApJREFUCNdjYAAAAAIAAeIhvDMAAAAASUVORK5CYII=\"  alt=\"\"  width=\"750\"  height=\"401\"  class=\"aligncenter wp-image-15291 size-full pk-lazyload\"  data-pk-sizes=\"auto\"  data-ls-sizes=\"auto, (max-width: 750px) 100vw, 750px\"  data-pk-src=\"https:\/\/cdn.itpiran.net\/2024\/04\/13210016\/6-3.webp\"  data-pk-srcset=\"https:\/\/cdn.itpiran.net\/2024\/04\/13210016\/6-3.webp 750w, https:\/\/cdn.itpiran.net\/2024\/04\/13210016\/6-3-300x160.webp 300w, https:\/\/cdn.itpiran.net\/2024\/04\/13210016\/6-3-110x59.webp 110w, https:\/\/cdn.itpiran.net\/2024\/04\/13210016\/6-3-200x107.webp 200w, https:\/\/cdn.itpiran.net\/2024\/04\/13210016\/6-3-380x203.webp 380w, https:\/\/cdn.itpiran.net\/2024\/04\/13210016\/6-3-255x136.webp 255w, https:\/\/cdn.itpiran.net\/2024\/04\/13210016\/6-3-550x294.webp 550w\" ><br \/>\n\u062f\u0631 \u0627\u06cc\u0646 \u0645\u0631\u062d\u0644\u0647 \u0634\u0645\u0627 \u0645\u0646\u0627\u0628\u0639 \u0627\u0648\u0644\u06cc\u0647 \u0627\u06cc \u0631\u0627 \u06a9\u0647 \u0628\u0631\u0627\u06cc \u062f\u0646\u0628\u0627\u0644 \u06a9\u0631\u062f\u0646 \u0627\u06cc\u0646 \u0622\u0645\u0648\u0632\u0634 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u062e\u0648\u0627\u0647\u06cc\u062f \u06a9\u0631\u062f \u0628\u0647 \u062a\u0646\u0647\u0627\u06cc\u06cc \u0645\u0633\u062a\u0642\u0631 \u06a9\u0631\u062f\u0647 \u0627\u06cc\u062f. \u062f\u0631 \u0645\u0631\u062d\u0644\u0647 \u0628\u0639\u062f \u0628\u0647 \u0646\u0645\u0648\u0646\u0647 Cloud9 \u06a9\u0647 \u067e\u0634\u062a\u0647 \u0627\u06cc\u062c\u0627\u062f \u06a9\u0631\u062f\u0647 \u062f\u0633\u062a\u0631\u0633\u06cc \u062e\u0648\u0627\u0647\u06cc\u062f \u062f\u0627\u0634\u062a \u0648 Terraform \u0631\u0627 \u0645\u0642\u062f\u0627\u0631\u062f\u0647\u06cc \u0627\u0648\u0644\u06cc\u0647 \u0645\u06cc \u06a9\u0646\u06cc\u062f.<\/p>\n<h2 id=\"%d9%85%d8%b1%d8%ad%d9%84%d9%87-2-%d8%a8%d9%87-cloud9-%d8%af%d8%b3%d8%aa%d8%b1%d8%b3%db%8c-%d9%be%db%8c%d8%af%d8%a7-%da%a9%d8%b1%d8%af%d9%87-%d9%88-terraform-%d8%b1%d8%a7-%d8%b1%d8%a7%d9%87-%d8%a7\">\u0645\u0631\u062d\u0644\u0647 2. \u0628\u0647 Cloud9 \u062f\u0633\u062a\u0631\u0633\u06cc \u067e\u06cc\u062f\u0627 \u06a9\u0631\u062f\u0647 \u0648 Terraform \u0631\u0627 \u0631\u0627\u0647 \u0627\u0646\u062f\u0627\u0632\u06cc \u06a9\u0646\u06cc\u062f<\/h2>\n<h5 id=\"2-1-aws-cloud9-%d8%b1%d8%a7-%d8%af%d8%b1-%da%a9%d9%86%d8%b3%d9%88%d9%84-%d9%85%d8%af%db%8c%d8%b1%db%8c%d8%aa-aws-%d8%a8%d8%a7%d8%b2-%da%a9%d9%86%db%8c%d8%af-%d9%88-%d9%85%d8%ad%db%8c%d8%b7-%d8%b1\">2.1. AWS Cloud9 \u0631\u0627 \u062f\u0631 \u06a9\u0646\u0633\u0648\u0644 \u0645\u062f\u06cc\u0631\u06cc\u062a AWS \u0628\u0627\u0632 \u06a9\u0646\u06cc\u062f \u0648 \u0645\u062d\u06cc\u0637 \u0631\u0627 \u062f\u0631 Cloud9 IDE \u0628\u0627\u0632 \u06a9\u0646\u06cc\u062f.<\/h5>\n<h5 id=\"2-2-%d8%af%d8%b1-%d8%a7%d9%88%d9%84%d9%88%db%8c%d8%aa%d9%87%d8%a7%db%8c-cloud9%d8%8c-%d8%a7%d8%b3%d8%aa%d9%81%d8%a7%d8%af%d9%87-%d8%a7%d8%b2-%d8%a7%d8%b9%d8%aa%d8%a8%d8%a7%d8%b1%d9%86%d8%a7\"><img  decoding=\"async\"  src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABAQMAAAAl21bKAAAAA1BMVEUAAP+KeNJXAAAAAXRSTlMAQObYZgAAAAlwSFlzAAAOxAAADsQBlSsOGwAAAApJREFUCNdjYAAAAAIAAeIhvDMAAAAASUVORK5CYII=\"  alt=\"https:\/\/community.aws\/_next\/image?url=https%3A%2F%2Fcommunity.aws%2Fraw-post-images%2Ftutorials%2Fusing-terraform-to-configure-automated-guardduty-findings%2Fimages%2F0007.png&amp;w=750&amp;q=75\"  class=\" pk-lazyload\"  data-pk-sizes=\"auto\"  data-pk-src=\"https:\/\/community.aws\/_next\/image?url=https%3A%2F%2Fcommunity.aws%2Fraw-post-images%2Ftutorials%2Fusing-terraform-to-configure-automated-guardduty-findings%2Fimages%2F0007.png&amp;w=750&amp;q=75\" ><br \/>\n2.2. \u062f\u0631 \u0627\u0648\u0644\u0648\u06cc\u062a\u200c\u0647\u0627\u06cc Cloud9\u060c \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0627\u0639\u062a\u0628\u0627\u0631\u0646\u0627\u0645\u0647\u200c\u0647\u0627\u06cc \u0645\u0648\u0642\u062a \u0645\u062f\u06cc\u0631\u06cc\u062a\u200c\u0634\u062f\u0647 AWS \u0631\u0627 \u063a\u06cc\u0631\u0641\u0639\u0627\u0644 \u06a9\u0646\u06cc\u062f.<\/h5>\n<h5 id=\"2-3-%d8%a7%d8%b2-%d8%aa%d8%b1%d9%85%db%8c%d9%86%d8%a7%d9%84-%d9%85%d9%88%d8%ac%d9%88%d8%af-%d8%af%d8%b1-%d9%86%d9%85%d9%88%d9%86%d9%87-cloud9%d8%8c-%d9%85%d8%ae%d8%b2%d9%86-%da%a9%d8%af-%d8%a7%d9%88\"><img  loading=\"lazy\"  decoding=\"async\"  src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABAQMAAAAl21bKAAAAA1BMVEUAAP+KeNJXAAAAAXRSTlMAQObYZgAAAAlwSFlzAAAOxAAADsQBlSsOGwAAAApJREFUCNdjYAAAAAIAAeIhvDMAAAAASUVORK5CYII=\"  alt=\"\"  width=\"750\"  height=\"359\"  class=\"aligncenter wp-image-15292 size-full pk-lazyload\"  data-pk-sizes=\"auto\"  data-ls-sizes=\"auto, (max-width: 750px) 100vw, 750px\"  data-pk-src=\"https:\/\/cdn.itpiran.net\/2024\/04\/13210300\/8-2.webp\"  data-pk-srcset=\"https:\/\/cdn.itpiran.net\/2024\/04\/13210300\/8-2.webp 750w, https:\/\/cdn.itpiran.net\/2024\/04\/13210300\/8-2-300x144.webp 300w, https:\/\/cdn.itpiran.net\/2024\/04\/13210300\/8-2-110x53.webp 110w, https:\/\/cdn.itpiran.net\/2024\/04\/13210300\/8-2-200x96.webp 200w, https:\/\/cdn.itpiran.net\/2024\/04\/13210300\/8-2-380x182.webp 380w, https:\/\/cdn.itpiran.net\/2024\/04\/13210300\/8-2-255x122.webp 255w, https:\/\/cdn.itpiran.net\/2024\/04\/13210300\/8-2-550x263.webp 550w\" ><br \/>\n2.3. \u0627\u0632 \u062a\u0631\u0645\u06cc\u0646\u0627\u0644 \u0645\u0648\u062c\u0648\u062f \u062f\u0631 \u0646\u0645\u0648\u0646\u0647 Cloud9\u060c \u0645\u062e\u0632\u0646 \u06a9\u062f \u0627\u0648\u0644\u06cc\u0647 \u0631\u0627 \u0634\u0628\u06cc\u0647 \u0633\u0627\u0632\u06cc \u06a9\u0646\u06cc\u062f.<\/h5>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-bash\" data-lang=\"Bash\"><code>git clone https:\/\/github.com\/build-on-aws\/automating-amazon-guardduty-with-iac.git\r\n<\/code><\/pre>\n<\/div>\n<h5 id=\"2-4-%d8%a8%d9%87-%d8%af%d8%a7%db%8c%d8%b1%da%a9%d8%aa%d9%88%d8%b1%db%8c-automating-amazon-guardduty-with-iac-%d8%aa%d8%ba%db%8c%db%8c%d8%b1-%d8%af%d9%87%db%8c%d8%af-%d9%88-%db%8c%da%a9-terraform-init\">2.4. \u0628\u0647 \u062f\u0627\u06cc\u0631\u06a9\u062a\u0648\u0631\u06cc automating-amazon-guardduty-with-iac \u062a\u063a\u06cc\u06cc\u0631 \u062f\u0647\u06cc\u062f \u0648 \u06cc\u06a9 terraform init\u060c terraform plan \u0648 terraform \u0627\u0639\u0645\u0627\u0644 \u06a9\u0646\u06cc\u062f.<\/h5>\n<p><img  loading=\"lazy\"  decoding=\"async\"  src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABAQMAAAAl21bKAAAAA1BMVEUAAP+KeNJXAAAAAXRSTlMAQObYZgAAAAlwSFlzAAAOxAAADsQBlSsOGwAAAApJREFUCNdjYAAAAAIAAeIhvDMAAAAASUVORK5CYII=\"  alt=\"\"  width=\"750\"  height=\"401\"  class=\"aligncenter wp-image-15293 size-full pk-lazyload\"  data-pk-sizes=\"auto\"  data-ls-sizes=\"auto, (max-width: 750px) 100vw, 750px\"  data-pk-src=\"https:\/\/cdn.itpiran.net\/2024\/04\/13214747\/10-1.webp\"  data-pk-srcset=\"https:\/\/cdn.itpiran.net\/2024\/04\/13214747\/10-1.webp 750w, https:\/\/cdn.itpiran.net\/2024\/04\/13214747\/10-1-300x160.webp 300w, https:\/\/cdn.itpiran.net\/2024\/04\/13214747\/10-1-110x59.webp 110w, https:\/\/cdn.itpiran.net\/2024\/04\/13214747\/10-1-200x107.webp 200w, https:\/\/cdn.itpiran.net\/2024\/04\/13214747\/10-1-380x203.webp 380w, https:\/\/cdn.itpiran.net\/2024\/04\/13214747\/10-1-255x136.webp 255w, https:\/\/cdn.itpiran.net\/2024\/04\/13214747\/10-1-550x294.webp 550w\" ><br \/>\n\u06cc\u06a9 \u062f\u0631\u062e\u0648\u0627\u0633\u062a \u0645\u0648\u0641\u0642 \u0634\u0628\u06cc\u0647 \u0645\u0648\u0627\u0631\u062f \u0632\u06cc\u0631 \u062e\u0648\u0627\u0647\u062f \u0628\u0648\u062f:<\/p>\n<h5 id=\"2-5-%d8%a8%d8%b1%d8%b1%d8%b3%db%8c-%da%a9%d9%86%db%8c%d8%af-%da%a9%d9%87-%d8%af%d9%88-%d9%86%d9%85%d9%88%d9%86%d9%87-%d8%ac%d8%af%db%8c%d8%af-ec2-%d9%88%d8%ac%d9%88%d8%af-%d8%af%d8%a7%d8%b1%d8%af\"><img  loading=\"lazy\"  decoding=\"async\"  src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABAQMAAAAl21bKAAAAA1BMVEUAAP+KeNJXAAAAAXRSTlMAQObYZgAAAAlwSFlzAAAOxAAADsQBlSsOGwAAAApJREFUCNdjYAAAAAIAAeIhvDMAAAAASUVORK5CYII=\"  alt=\"\"  width=\"750\"  height=\"96\"  class=\"aligncenter wp-image-15294 size-full pk-lazyload\"  data-pk-sizes=\"auto\"  data-ls-sizes=\"auto, (max-width: 750px) 100vw, 750px\"  data-pk-src=\"https:\/\/cdn.itpiran.net\/2024\/04\/13214833\/11-1.webp\"  data-pk-srcset=\"https:\/\/cdn.itpiran.net\/2024\/04\/13214833\/11-1.webp 750w, https:\/\/cdn.itpiran.net\/2024\/04\/13214833\/11-1-300x38.webp 300w, https:\/\/cdn.itpiran.net\/2024\/04\/13214833\/11-1-110x14.webp 110w, https:\/\/cdn.itpiran.net\/2024\/04\/13214833\/11-1-200x26.webp 200w, https:\/\/cdn.itpiran.net\/2024\/04\/13214833\/11-1-380x49.webp 380w, https:\/\/cdn.itpiran.net\/2024\/04\/13214833\/11-1-255x33.webp 255w, https:\/\/cdn.itpiran.net\/2024\/04\/13214833\/11-1-550x70.webp 550w\" ><br \/>\n2.5. \u0628\u0631\u0631\u0633\u06cc \u06a9\u0646\u06cc\u062f \u06a9\u0647 \u062f\u0648 \u0646\u0645\u0648\u0646\u0647 \u062c\u062f\u06cc\u062f EC2 \u0648\u062c\u0648\u062f \u062f\u0627\u0631\u062f\u060c \u06cc\u06a9\u06cc \u0628\u0627 \u0646\u0627\u0645 IAC Tutorial: Compromised Instance \u0648 \u062f\u06cc\u06af\u0631\u06cc \u0628\u0627 \u0646\u0627\u0645 IAC Tutorial: Malicious Instance.<\/h5>\n<p><img  loading=\"lazy\"  decoding=\"async\"  src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABAQMAAAAl21bKAAAAA1BMVEUAAP+KeNJXAAAAAXRSTlMAQObYZgAAAAlwSFlzAAAOxAAADsQBlSsOGwAAAApJREFUCNdjYAAAAAIAAeIhvDMAAAAASUVORK5CYII=\"  alt=\"\"  width=\"750\"  height=\"323\"  class=\"aligncenter wp-image-15295 size-full pk-lazyload\"  data-pk-sizes=\"auto\"  data-ls-sizes=\"auto, (max-width: 750px) 100vw, 750px\"  data-pk-src=\"https:\/\/cdn.itpiran.net\/2024\/04\/13215727\/12.webp\"  data-pk-srcset=\"https:\/\/cdn.itpiran.net\/2024\/04\/13215727\/12.webp 750w, https:\/\/cdn.itpiran.net\/2024\/04\/13215727\/12-300x129.webp 300w, https:\/\/cdn.itpiran.net\/2024\/04\/13215727\/12-110x47.webp 110w, https:\/\/cdn.itpiran.net\/2024\/04\/13215727\/12-200x86.webp 200w, https:\/\/cdn.itpiran.net\/2024\/04\/13215727\/12-380x164.webp 380w, https:\/\/cdn.itpiran.net\/2024\/04\/13215727\/12-255x110.webp 255w, https:\/\/cdn.itpiran.net\/2024\/04\/13215727\/12-550x237.webp 550w\" ><br \/>\n\u062f\u0631 \u0627\u06cc\u0646 \u0645\u0631\u062d\u0644\u0647\u060c \u0634\u0645\u0627 \u06cc\u06a9 VPC \u0648 \u062f\u0648 \u0646\u0645\u0648\u0646\u0647 EC2 \u0631\u0627 \u0645\u0633\u062a\u0642\u0631 \u06a9\u0631\u062f\u0647 \u0627\u06cc\u062f. \u062f\u0648 \u0646\u0645\u0648\u0646\u0647 EC2 \u0628\u0627 \u06cc\u06a9\u062f\u06cc\u06af\u0631 \u0635\u062d\u0628\u062a \u0645\u06cc\u200c\u06a9\u0646\u0646\u062f \u0648 \u0628\u0639\u062f\u0627\u064b \u0648\u0642\u062a\u06cc \u06cc\u06a9\u06cc \u0627\u0632 \u0646\u0645\u0648\u0646\u0647\u200c\u0647\u0627\u06cc EC2 Elastic \u0622\u062f\u0631\u0633 IP \u0631\u0627 \u0628\u0647 \u0644\u06cc\u0633\u062a \u062a\u0647\u062f\u06cc\u062f \u0627\u0636\u0627\u0641\u0647 \u0645\u06cc\u200c\u06a9\u0646\u06cc\u062f\u060c \u0628\u0627\u0639\u062b \u0645\u06cc\u200c\u0634\u0648\u062f GuardDuty \u06cc\u06a9 \u06cc\u0627\u0641\u062a\u0647 \u0631\u0627 \u0627\u06cc\u062c\u0627\u062f \u06a9\u0646\u062f. \u0627\u0632 \u0627\u06cc\u0646 \u0645\u0631\u062d\u0644\u0647 \u0628\u0647 \u0628\u0639\u062f\u060c \u0634\u0645\u0627 \u0647\u0631 \u06cc\u06a9 \u0627\u0632 \u0645\u0646\u0627\u0628\u0639\u06cc \u0631\u0627 \u06a9\u0647 \u0628\u062e\u0634\u06cc \u0627\u0632 \u0631\u0627\u0647 \u062d\u0644 \u0627\u0645\u0646\u06cc\u062a\u06cc \u0648\u0627\u0642\u0639\u06cc \u0647\u0633\u062a\u0646\u062f \u0627\u06cc\u062c\u0627\u062f \u062e\u0648\u0627\u0647\u06cc\u062f \u06a9\u0631\u062f.<\/p>\n<h2 id=\"%d9%85%d8%b1%d8%ad%d9%84%d9%87-3-%db%8c%da%a9-%d8%b3%d8%b7%d9%84-s3-%d8%a8%d8%b1%d8%a7%db%8c-%d8%b0%d8%ae%db%8c%d8%b1%d9%87-%d9%84%db%8c%d8%b3%d8%aa-%d8%aa%d9%87%d8%af%db%8c%d8%af-%d8%a7%db%8c%d8%ac\">\u0645\u0631\u062d\u0644\u0647 3: \u06cc\u06a9 \u0633\u0637\u0644 S3 \u0628\u0631\u0627\u06cc \u0630\u062e\u06cc\u0631\u0647 \u0644\u06cc\u0633\u062a \u062a\u0647\u062f\u06cc\u062f \u0627\u06cc\u062c\u0627\u062f \u06a9\u0646\u06cc\u062f<\/h2>\n<p>GuardDuty \u0645\u06cc \u062a\u0648\u0627\u0646\u062f \u0628\u0647 \u062f\u0648 \u0646\u0648\u0639 \u0644\u06cc\u0633\u062a \u0627\u0634\u0627\u0631\u0647 \u06a9\u0646\u062f: \u06cc\u06a9 \u0644\u06cc\u0633\u062a IP \u0645\u0648\u0631\u062f \u0627\u0639\u062a\u0645\u0627\u062f \u0648 \u06cc\u06a9 \u0644\u06cc\u0633\u062a IP \u062a\u0647\u062f\u06cc\u062f. GuardDuty \u06cc\u0627\u0641\u062a\u0647 \u0647\u0627\u06cc\u06cc \u0631\u0627 \u0628\u0631\u0627\u06cc \u0622\u062f\u0631\u0633 \u0647\u0627\u06cc IP \u06a9\u0647 \u062f\u0631 \u0644\u06cc\u0633\u062a \u0647\u0627\u06cc IP \u0642\u0627\u0628\u0644 \u0627\u0639\u062a\u0645\u0627\u062f \u06af\u0646\u062c\u0627\u0646\u062f\u0647 \u0634\u062f\u0647 \u0627\u0646\u062f \u0627\u06cc\u062c\u0627\u062f \u0646\u0645\u06cc \u06a9\u0646\u062f\u060c \u0627\u0645\u0627 \u06cc\u0627\u0641\u062a\u0647 \u0647\u0627\u06cc\u06cc \u0631\u0627 \u0628\u0631\u0627\u06cc \u0622\u062f\u0631\u0633 \u0647\u0627\u06cc IP \u0627\u06cc\u062c\u0627\u062f \u0645\u06cc \u06a9\u0646\u062f \u06a9\u0647 \u062f\u0631 \u0644\u06cc\u0633\u062a \u0647\u0627\u06cc IP \u062a\u0647\u062f\u06cc\u062f \u06af\u0646\u062c\u0627\u0646\u062f\u0647 \u0634\u062f\u0647 \u0627\u0646\u062f. \u0627\u0632 \u0622\u0646\u062c\u0627\u06cc\u06cc \u06a9\u0647 \u0645\u06cc \u062e\u0648\u0627\u0647\u06cc\u0645 \u062f\u0631 \u0627\u06cc\u0646 \u0622\u0645\u0648\u0632\u0634 \u0628\u0647 \u0627\u062c\u0628\u0627\u0631 \u06cc\u06a9 \u06cc\u0627\u0641\u062a\u0647 \u0631\u0627 \u0627\u0646\u062c\u0627\u0645 \u062f\u0647\u06cc\u0645\u060c \u0627\u0632 \u06cc\u06a9 \u0644\u06cc\u0633\u062a IP \u062a\u0647\u062f\u06cc\u062f \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc \u06a9\u0646\u06cc\u0645.<\/p>\n<h5 id=\"3-1-%d8%a8%d8%a7-%d8%a7%db%8c%d8%ac%d8%a7%d8%af-%db%8c%da%a9-%d9%85%d8%aa%d8%ba%db%8c%d8%b1-%d8%af%d8%b1-modules-s3-variables-tf-%d8%a8%d8%b1%d8%a7%db%8c-vpc_id-%d8%b4%d8%b1%d9%88%d8%b9-%da%a9%d9%86\">3.1. \u0628\u0627 \u0627\u06cc\u062c\u0627\u062f \u06cc\u06a9 \u0645\u062a\u063a\u06cc\u0631 \u062f\u0631 modules\/s3\/variables.tf \u0628\u0631\u0627\u06cc vpc_id \u0634\u0631\u0648\u0639 \u06a9\u0646\u06cc\u062f.<\/h5>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\"><code>variable \"vpc_id\" {\r\n}\r\n<\/code><\/pre>\n<\/div>\n<h5 id=\"3-2-%d8%a8%d8%b9%d8%af%d8%8c-%d8%af%d8%b1-%d9%81%d8%a7%db%8c%d9%84-modules-s3-main-tf%d8%8c-%d8%b4%d9%85%d8%a7%d8%b1%d9%87-%d8%ad%d8%b3%d8%a7%d8%a8-%da%a9%d8%a7%d8%b1%d8%a8%d8%b1%db%8c-%d9%81%d8%b9\">3.2. \u0628\u0639\u062f\u060c \u062f\u0631 \u0641\u0627\u06cc\u0644 modules\/s3\/main.tf\u060c \u0634\u0645\u0627\u0631\u0647 \u062d\u0633\u0627\u0628 \u06a9\u0627\u0631\u0628\u0631\u06cc \u0641\u0639\u0644\u06cc AWS \u0631\u0627 \u062f\u0631\u06cc\u0627\u0641\u062a \u06a9\u0631\u062f\u0647 \u0648 \u06cc\u06a9 \u0645\u0646\u0628\u0639 \u0633\u0637\u0644 S3 \u0627\u06cc\u062c\u0627\u062f \u06a9\u0646\u06cc\u062f.<\/h5>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\"><code># GET CURRENT AWS ACCOUNT NUMBER\r\ndata \"aws_caller_identity\" \"current\" {}\r\n# CREATE TWO S3 BUCKETS\r\nresource \"aws_s3_bucket\" \"bucket\" {\r\nbucket = \"guardduty-example-${data.aws_caller_identity.current.account_id}-us-east-1\"\r\nforce_destroy = true\r\n}\r\nresource \"aws_s3_bucket\" \"flow-log-bucket\" {\r\nbucket = \"vpc-flow-logs-${data.aws_caller_identity.current.account_id}-us-east-1\"\r\nforce_destroy = true\r\n}\r\n<\/code><\/pre>\n<\/div>\n<blockquote><\/blockquote>\n<h5 id=\"3-3-%d8%b3%d9%be%d8%b3-vpc-flow-log-%d9%87%d8%a7-%d8%b1%d8%a7-%d8%af%d8%b1-%d8%b3%d8%b7%d9%84-s3-%d9%81%d8%b9%d8%a7%d9%84-%da%a9%d9%86%db%8c%d8%af-%d8%a7%db%8c%d9%86-%d9%85%d9%88%d8%b1%d8%af-%d9%86\">3.3. \u0633\u067e\u0633 VPC Flow log \u0647\u0627 \u0631\u0627 \u062f\u0631 \u0633\u0637\u0644 S3 \u0641\u0639\u0627\u0644 \u06a9\u0646\u06cc\u062f. \u0627\u06cc\u0646 \u0645\u0648\u0631\u062f \u0646\u06cc\u0627\u0632 \u0646\u06cc\u0633\u062a\u060c \u0627\u0645\u0627 \u0628\u0647 \u0645\u0627 \u0627\u0645\u06a9\u0627\u0646 \u0645\u06cc \u062f\u0647\u062f \u06af\u0632\u0627\u0631\u0634 \u0647\u0627\u06cc\u06cc \u0631\u0627 \u06a9\u0647 GuardDuty \u0645\u06cc \u0628\u06cc\u0646\u062f\u060c \u0645\u0634\u0627\u0647\u062f\u0647 \u06a9\u0646\u06cc\u0645.<\/h5>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\"><code># VPC FLOW LOGS\r\nresource \"aws_flow_log\" \"flow_log_example\" {\r\nlog_destination = aws_s3_bucket.flow-log-bucket.arn\r\nlog_destination_type = \"s3\"\r\ntraffic_type = \"ALL\"\r\nvpc_id = var.vpc_id\r\n}\r\n<\/code><\/pre>\n<\/div>\n<h5 id=\"3-4-%d8%af%d8%b1-%d9%86%d9%87%d8%a7%db%8c%d8%aa%d8%8c-%d9%85%d9%82%d8%a7%d8%af%db%8c%d8%b1-bucket_id-%d9%88-bucket_arn-%d8%b1%d8%a7-%d8%af%d8%b1-%d9%81%d8%a7%db%8c%d9%84-modules-s3-outputs-tf-%d8%ae\">3.4. \u062f\u0631 \u0646\u0647\u0627\u06cc\u062a\u060c \u0645\u0642\u0627\u062f\u06cc\u0631 bucket_id \u0648 bucket_arn \u0631\u0627 \u062f\u0631 \u0641\u0627\u06cc\u0644 modules\/s3\/outputs.tf \u062e\u0627\u0631\u062c \u06a9\u0646\u06cc\u062f.<\/h5>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\"><code># S3 Bucket id\r\noutput \"bucket_id\" {\r\nvalue = aws_s3_bucket.bucket.id\r\ndescription = \"Output of s3 bucket id.\"\r\n}\r\n# S3 Bucket arn\r\noutput \"bucket_arn\" {\r\nvalue = aws_s3_bucket.bucket.arn\r\ndescription = \"Output of s3 bucket arn.\"\r\n}\r\n<\/code><\/pre>\n<\/div>\n<h5 id=\"3-5-%d8%ad%d8%a7%d9%84%d8%a7-%d8%a8%d9%87-%d9%81%d8%a7%db%8c%d9%84-root-main-tf-%d8%a8%d8%b1%da%af%d8%b1%d8%af%db%8c%d8%af-%d9%88-%d8%b3%d8%b7%d9%84-s3-%d8%b1%d8%a7-%d8%a7%d8%b6%d8%a7%d9%81%d9%87\">3.5. \u062d\u0627\u0644\u0627 \u0628\u0647 \u0641\u0627\u06cc\u0644 root\/main.tf \u0628\u0631\u06af\u0631\u062f\u06cc\u062f \u0648 \u0633\u0637\u0644 S3 \u0631\u0627 \u0627\u0636\u0627\u0641\u0647 \u06a9\u0646\u06cc\u062f.<\/h5>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\"><code># CREATES S3 BUCKET\r\nmodule \"s3_bucket\" {\r\nsource = \".\/modules\/s3\"\r\nvpc_id = module.iac_vpc.vpc_attributes.id\r\n}\r\n<\/code><\/pre>\n<\/div>\n<p>\u062f\u0631 \u0627\u06cc\u0646 \u0645\u0631\u062d\u0644\u0647 \u0634\u0645\u0627 \u062f\u0648 \u0633\u0637\u0644 S3 \u0627\u06cc\u062c\u0627\u062f \u06a9\u0631\u062f\u0647 \u0627\u06cc\u062f. \u0627\u06af\u0631 \u0645\u06cc\u200c\u062e\u0648\u0627\u0647\u06cc\u062f \u062e\u0648\u062f\u062a\u0627\u0646 \u0622\u0646\u0647\u0627 \u0631\u0627 \u0628\u0631\u0631\u0633\u06cc \u06a9\u0646\u06cc\u062f\u060c \u06cc\u06a9 \u0633\u0637\u0644 \u0628\u0631\u0627\u06cc \u06af\u0632\u0627\u0631\u0634\u200c\u0647\u0627\u06cc \u062c\u0631\u06cc\u0627\u0646 VPC \u0627\u0633\u062a. \u0633\u0637\u0644 \u062f\u06cc\u06af\u0631 \u062d\u0627\u0648\u06cc \u0644\u06cc\u0633\u062a \u062a\u0647\u062f\u06cc\u062f\u0627\u062a\u06cc \u0627\u0633\u062a \u06a9\u0647 \u062f\u0631 \u0645\u0631\u062d\u0644\u0647 \u0628\u0639\u062f \u0627\u06cc\u062c\u0627\u062f \u062e\u0648\u0627\u0647\u06cc\u062f \u06a9\u0631\u062f.<\/p>\n<h2 id=\"%d9%85%d8%b1%d8%ad%d9%84%d9%87-4-%d9%85%d8%a7%da%98%d9%88%d9%84-%d9%87%d8%a7%db%8c-guardduty-terraform-%d8%b1%d8%a7-%d8%a7%db%8c%d8%ac%d8%a7%d8%af-%da%a9%d9%86%db%8c%d8%af\">\u0645\u0631\u062d\u0644\u0647 4: \u0645\u0627\u0698\u0648\u0644 \u0647\u0627\u06cc GuardDuty Terraform \u0631\u0627 \u0627\u06cc\u062c\u0627\u062f \u06a9\u0646\u06cc\u062f<\/h2>\n<h5 id=\"4-1-%d9%81%d8%a7%db%8c%d9%84-%d9%87%d8%a7%db%8c-guardduty-module-%d8%a8%d8%b1%d8%a7%db%8c-%d8%b4%d9%85%d8%a7-%d8%b3%d8%a7%d8%ae%d8%aa%d9%87-%d8%b4%d8%af%d9%87-%d8%a7%d9%86%d8%af%d8%8c-%d8%a7%d9%85\">4.1. \u0641\u0627\u06cc\u0644 \u0647\u0627\u06cc GuardDuty Module \u0628\u0631\u0627\u06cc \u0634\u0645\u0627 \u0633\u0627\u062e\u062a\u0647 \u0634\u062f\u0647 \u0627\u0646\u062f\u060c \u0627\u0645\u0627 \u0645\u0627\u0646\u0646\u062f \u0641\u0627\u06cc\u0644 \u0647\u0627\u06cc S3 \u062e\u0627\u0644\u06cc \u0647\u0633\u062a\u0646\u062f. \u0628\u0627 \u0641\u0627\u06cc\u0644 modules\/guardduty\/variables.tf \u0634\u0631\u0648\u0639 \u06a9\u0646\u06cc\u062f. \u062f\u0631 \u0627\u06cc\u0646\u062c\u0627 \u0628\u0627\u06cc\u062f \u062f\u0648 \u0645\u062a\u063a\u06cc\u0631 \u0627\u06cc\u062c\u0627\u062f \u06a9\u0646\u06cc\u062f. \u0627\u0648\u0644\u06cc \u0645\u062a\u063a\u06cc\u0631\u06cc \u0628\u0647 \u0646\u0627\u0645 bucket \u0627\u0633\u062a \u06a9\u0647 \u0627\u0632 \u0622\u0646 \u0628\u0631\u0627\u06cc \u062a\u0639\u0631\u06cc\u0641 \u062c\u0632\u0626\u06cc\u0627\u062a \u0644\u06cc\u0633\u062a \u062a\u0647\u062f\u06cc\u062f \u0633\u0637\u0644 S3 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc \u06a9\u0646\u06cc\u0645. \u062f\u0648\u0645\u06cc \u0645\u0631\u0628\u0648\u0637 \u0628\u0647 IP \u0645\u062e\u0631\u0628\u06cc \u0627\u0633\u062a \u06a9\u0647 \u0628\u0647 \u0633\u0637\u0644 \u0627\u0636\u0627\u0641\u0647 \u06a9\u0631\u062f\u0647 \u0627\u06cc\u0645.<\/h5>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\"><code>variable \"bucket\" {\r\n}\r\nvariable \"malicious_ip\" {\r\n}\r\n<\/code><\/pre>\n<\/div>\n<h5 id=\"4-2-%d8%b3%d9%be%d8%b3-%d8%a8%d9%87-%d9%81%d8%a7%db%8c%d9%84-modules-guardduty-main-tf-%d8%a8%d8%b1%d9%88%db%8c%d8%af\">4.2. \u0633\u067e\u0633 \u0628\u0647 \u0641\u0627\u06cc\u0644 modules\/guardduty\/main.tf \u0628\u0631\u0648\u06cc\u062f.<\/h5>\n<p>\u062f\u0631 \u0627\u06cc\u0646 \u0641\u0627\u06cc\u0644 \u0634\u0645\u0627 \u0633\u0647 \u0645\u0646\u0628\u0639 \u0631\u0627 \u0627\u0636\u0627\u0641\u0647 \u062e\u0648\u0627\u0647\u06cc\u062f \u06a9\u0631\u062f. \u0627\u0648\u0644\u06cc\u0646 \u0645\u0646\u0628\u0639 \u0622\u0634\u06a9\u0627\u0631\u0633\u0627\u0632 GuardDuty \u0627\u0633\u062a. \u0634\u0645\u0627 \u062f\u0631 \u0627\u0633\u0646\u0627\u062f \u0627\u0631\u0627\u0626\u0647 \u062f\u0647\u0646\u062f\u0647 \u06cc\u0627\u062f\u062f\u0627\u0634\u062a \u062e\u0648\u0627\u0647\u06cc\u062f \u06a9\u0631\u062f \u06a9\u0647 \u06af\u0632\u06cc\u0646\u0647 \u0647\u0627 \u0647\u0645\u0647 \u0627\u062e\u062a\u06cc\u0627\u0631\u06cc \u0647\u0633\u062a\u0646\u062f &#8211; \u0647\u06cc\u0686 \u0686\u06cc\u0632 \u062f\u06cc\u06af\u0631\u06cc \u062c\u0632 \u0627\u0639\u0644\u0627\u0645 \u0645\u0646\u0628\u0639 \u0645\u0648\u0631\u062f \u0646\u06cc\u0627\u0632 \u0646\u06cc\u0633\u062a. \u0628\u0627 \u0627\u06cc\u0646 \u062d\u0627\u0644\u060c \u0645\u0642\u062f\u0627\u0631 \u0641\u0639\u0627\u0644 \u0634\u062f\u0647 \u0631\u0627 \u062f\u0631 \u0645\u062b\u0627\u0644 \u062e\u0648\u062f \u0631\u0648\u06cc true \u0642\u0631\u0627\u0631 \u0645\u06cc \u062f\u0647\u06cc\u0645 \u0648 \u0647\u0645\u0686\u0646\u06cc\u0646 finding_publishing_frequency \u0631\u0627 \u0628\u0647 15 \u062f\u0642\u06cc\u0642\u0647 \u062a\u063a\u06cc\u06cc\u0631 \u0645\u06cc \u062f\u0647\u06cc\u0645. \u067e\u06cc\u0634 \u0641\u0631\u0636 \u06cc\u06a9 \u0633\u0627\u0639\u062a \u0627\u0633\u062a.<\/p>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\"><code># ENABLE THE DETECTOR\r\nresource \"aws_guardduty_detector\" \"gd-tutorial\" {\r\nenable = true\r\nfinding_publishing_frequency = \"FIFTEEN_MINUTES\"\r\n}\r\n<\/code><\/pre>\n<\/div>\n<h5 id=\"4-3-%d8%af%d8%b1-%d9%85%d8%b1%d8%ad%d9%84%d9%87-%d8%a8%d8%b9%d8%af-%d9%81%d8%a7%db%8c%d9%84%db%8c-%d8%b1%d8%a7-%d8%af%d8%b1-%d8%b3%d8%b7%d9%84-s3-%da%a9%d9%87-%d8%af%d8%b1-%d9%85%d8%b1%d8%ad%d9%84\">4.3. \u062f\u0631 \u0645\u0631\u062d\u0644\u0647 \u0628\u0639\u062f \u0641\u0627\u06cc\u0644\u06cc \u0631\u0627 \u062f\u0631 \u0633\u0637\u0644 S3 \u06a9\u0647 \u062f\u0631 \u0645\u0631\u062d\u0644\u0647 \u0642\u0628\u0644 \u0627\u06cc\u062c\u0627\u062f \u06a9\u0631\u062f\u06cc\u0645 \u0622\u067e\u0644\u0648\u062f \u0645\u06cc \u06a9\u0646\u06cc\u0645. \u0627\u06cc\u0646 \u0645\u0648\u0631\u062f \u0646\u06cc\u0627\u0632 \u0646\u06cc\u0633\u062a\u060c \u0627\u0645\u0627 \u0628\u0631\u0627\u06cc \u0627\u0647\u062f\u0627\u0641 \u0646\u0645\u0627\u06cc\u0634\u06cc \u0645\u06cc\u200c\u062e\u0648\u0627\u0647\u06cc\u0645 \u0627\u0632 \u0622\u062f\u0631\u0633 IP \u06cc\u06a9\u06cc \u0627\u0632 \u0646\u0645\u0648\u0646\u0647\u200c\u0647\u0627\u06cc EC2 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u0645 \u062a\u0627 \u0627\u0637\u0645\u06cc\u0646\u0627\u0646 \u062d\u0627\u0635\u0644 \u06a9\u0646\u06cc\u0645 \u06a9\u0647 \u06cc\u0627\u0641\u062a\u0647\u200c\u0647\u0627 \u062f\u0631 \u0627\u06cc\u0646 \u0622\u0645\u0648\u0632\u0634 \u0627\u06cc\u062c\u0627\u062f \u0645\u06cc\u200c\u0634\u0648\u0646\u062f. \u062f\u0631 \u06a9\u062f \u0632\u06cc\u0631 \u0645\u0627 \u06cc\u06a9 \u0641\u0627\u06cc\u0644 \u0645\u062a\u0646\u06cc \u0631\u0627 \u062f\u0631 \u0633\u0637\u0644 S3 \u062e\u0648\u062f \u0622\u067e\u0644\u0648\u062f \u0645\u06cc \u06a9\u0646\u06cc\u0645 \u06a9\u0647 \u0622\u0646 \u0631\u0627 MyThreatIntelSet \u0645\u06cc \u0646\u0627\u0645\u06cc\u0645 \u0648 \u0645\u062d\u062a\u0648\u0627\u06cc \u0641\u0627\u06cc\u0644 \u0622\u062f\u0631\u0633 IP \u0645\u0648\u062c\u0648\u062f \u062f\u0631 \u0645\u062a\u063a\u06cc\u0631 var.malicious_ip \u062e\u0648\u0627\u0647\u062f \u0628\u0648\u062f.<\/h5>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\"><code># ADD THE EIP\/MALICIOUS IP TO THE BUCKET AS A TEXT FILE.\r\nresource \"aws_s3_object\" \"MyThreatIntelSet\" {\r\ncontent = var.malicious_ip\r\nbucket = var.bucket\r\nkey = \"MyThreatIntelSet\"\r\n}\r\n<\/code><\/pre>\n<\/div>\n<h5 id=\"4-4-%d8%af%d8%b1-%d9%86%d9%87%d8%a7%db%8c%d8%aa-%d9%85%d8%a7-%db%8c%da%a9-%d9%85%d9%86%d8%a8%d8%b9-%d8%a8%d9%87-%d9%86%d8%a7%d9%85-aws_guardduty_threatintelset-%d8%a7%db%8c%d8%ac%d8%a7%d8%af-%d8%ae\">4.4. \u062f\u0631 \u0646\u0647\u0627\u06cc\u062a \u0645\u0627 \u06cc\u06a9 \u0645\u0646\u0628\u0639 \u0628\u0647 \u0646\u0627\u0645 aws_guardduty_threatintelset \u0627\u06cc\u062c\u0627\u062f \u062e\u0648\u0627\u0647\u06cc\u0645 \u06a9\u0631\u062f \u06a9\u0647 \u0628\u0647 GuardDuty \u0645\u06cc \u06af\u0648\u06cc\u062f \u06a9\u0647 \u0628\u0627\u06cc\u062f \u0627\u0632 \u0641\u0627\u06cc\u0644\u06cc \u06a9\u0647 \u062f\u0631 \u0645\u06a9\u0627\u0646 \u062a\u0639\u0631\u06cc\u0641 \u0634\u062f\u0647 \u0642\u0631\u0627\u0631 \u062f\u0627\u0631\u062f \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u062f (\u0627\u06cc\u0646 \u0647\u0645\u0627\u0646 \u0686\u06cc\u0632\u06cc \u0627\u0633\u062a \u06a9\u0647 activate = true \u0627\u0646\u062c\u0627\u0645 \u0645\u06cc \u062f\u0647\u062f).<\/h5>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\"><code># HAVE GUARDDUTY LOOK AT THE TEXT FILE IN S3\r\nresource \"aws_guardduty_threatintelset\" \"Example-Threat-List\" {\r\nactivate = true\r\ndetector_id = aws_guardduty_detector.gd-tutorial.id\r\nformat = \"TXT\"\r\nlocation = \"https:\/\/s3.amazonaws.com\/${aws_s3_object.MyThreatIntelSet.bucket}\/${aws_s3_object.MyThreatIntelSet.key}\"\r\nname = \"MyThreatIntelSet\"\r\n}\r\n<\/code><\/pre>\n<\/div>\n<h5 id=\"4-5-%d8%b3%d9%be%d8%b3-%d8%a8%d9%87-%d9%81%d8%a7%db%8c%d9%84-root-main-tf-%d8%a8%d8%b1%d9%88%db%8c%d8%af-%d9%88-%d9%85%d8%a7%da%98%d9%88%d9%84-guardduty-%d8%b1%d8%a7-%d9%81%d8%b1%d8%a7%d8%ae%d9%88\">4.5. \u0633\u067e\u0633 \u0628\u0647 \u0641\u0627\u06cc\u0644 root\/main.tf \u0628\u0631\u0648\u06cc\u062f \u0648 \u0645\u0627\u0698\u0648\u0644 GuardDuty \u0631\u0627 \u0641\u0631\u0627\u062e\u0648\u0627\u0646\u06cc \u06a9\u0646\u06cc\u062f. \u0628\u0627\u06cc\u062f \u0634\u0646\u0627\u0633\u0647 \u0633\u0637\u0644 \u0648 IP \u0645\u062e\u0631\u0628 \u0631\u0627 \u0627\u0631\u0627\u0626\u0647 \u06a9\u0646\u06cc\u0645. \u0645\u06cc \u0628\u06cc\u0646\u06cc\u062f \u06a9\u0647 \u0627\u06cc\u0646\u0647\u0627 \u0627\u0632 \u0645\u0627\u0698\u0648\u0644 S3 \u0648 \u0645\u0627\u0698\u0648\u0644 \u0645\u062d\u0627\u0633\u0628\u0627\u062a\u06cc \u0645\u06cc \u0622\u06cc\u0646\u062f.<\/h5>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\"><code># Enable GuardDuty\r\nmodule \"guardduty\" {\r\nsource = \".\/modules\/guardduty\"\r\nbucket = module.s3_bucket.bucket_id\r\nmalicious_ip = module.compute.malicious_ip\r\n}\r\n<\/code><\/pre>\n<\/div>\n<p>\u062f\u0631 \u0627\u06cc\u0646 \u0628\u062e\u0634\u060c GuardDuty \u0631\u0627 \u0641\u0639\u0627\u0644 \u06a9\u0631\u062f\u06cc\u062f\u060c \u0644\u06cc\u0633\u062a \u062a\u0647\u062f\u06cc\u062f \u0631\u0627 \u0627\u06cc\u062c\u0627\u062f \u06a9\u0631\u062f\u06cc\u062f \u0648 \u0622\u062f\u0631\u0633 IP Elastic \u0646\u0645\u0648\u0646\u0647 \u0645\u062e\u0631\u0628 EC2 \u0631\u0627 \u0628\u0647 \u0622\u0646 \u0644\u06cc\u0633\u062a \u0627\u0636\u0627\u0641\u0647 \u06a9\u0631\u062f\u06cc\u062f. \u062f\u0631 \u0645\u0631\u062d\u0644\u0647 \u0628\u0639\u062f\u060c \u0645\u0627 \u06cc\u06a9 \u0642\u0627\u0646\u0648\u0646 SNS \u0627\u06cc\u062c\u0627\u062f \u0645\u06cc \u06a9\u0646\u06cc\u0645.<\/p>\n<h2 id=\"%d9%85%d8%b1%d8%ad%d9%84%d9%87-5-%d9%85%d8%a7%da%98%d9%88%d9%84-sns-terraform-%d8%b1%d8%a7-%d8%a7%db%8c%d8%ac%d8%a7%d8%af-%da%a9%d9%86%db%8c%d8%af\">\u0645\u0631\u062d\u0644\u0647 5: \u0645\u0627\u0698\u0648\u0644 SNS Terraform \u0631\u0627 \u0627\u06cc\u062c\u0627\u062f \u06a9\u0646\u06cc\u062f<\/h2>\n<p>\u062f\u0631 \u0627\u06cc\u0646 \u0628\u062e\u0634 \u0627\u0632 Terraform \u0628\u0631\u0627\u06cc \u0627\u06cc\u062c\u0627\u062f \u06cc\u06a9 \u0642\u0627\u0646\u0648\u0646 SNS \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc \u06a9\u0646\u06cc\u0645. SNS \u0633\u0631\u0648\u06cc\u0633 \u0627\u0639\u0644\u0627\u0646 \u0633\u0627\u062f\u0647 \u0627\u0633\u062a \u0648 \u0628\u0647 \u0634\u0645\u0627 \u0627\u0645\u06a9\u0627\u0646 \u0645\u06cc \u062f\u0647\u062f \u062f\u0631 \u0635\u0648\u0631\u062a \u0631\u0639\u0627\u06cc\u062a \u0645\u0639\u06cc\u0627\u0631\u0647\u0627\u06cc \u062e\u0627\u0635\u060c \u0627\u0639\u0644\u0627\u0646 \u0627\u0631\u0633\u0627\u0644 \u06a9\u0646\u06cc\u062f. \u062e\u0648\u062f SNS \u0628\u0627 \u0627\u0642\u062f\u0627\u0645\u06cc \u0628\u0631\u0627\u06cc \u0627\u0631\u0633\u0627\u0644 \u067e\u06cc\u0627\u0645 \u0645\u0637\u0627\u0628\u0642\u062a \u0646\u062f\u0627\u0631\u062f. \u0645\u0627 \u0627\u0632 EventBridge \u0628\u0631\u0627\u06cc \u0622\u0646 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u062e\u0648\u0627\u0647\u06cc\u0645 \u06a9\u0631\u062f. \u0628\u0627 \u0627\u06cc\u0646 \u062d\u0627\u0644\u060c \u0627\u0632 \u0622\u0646\u062c\u0627\u06cc\u06cc \u06a9\u0647 EventBridge \u0628\u0631\u0627\u06cc \u0627\u0631\u0633\u0627\u0644 \u0627\u0639\u0644\u0627\u0646\u200c\u0647\u0627 \u0628\u0647 \u06cc\u06a9 \u0642\u0627\u0646\u0648\u0646 \u0646\u06cc\u0627\u0632 \u062f\u0627\u0631\u062f\u060c \u0627\u0628\u062a\u062f\u0627 \u0628\u0627\u06cc\u062f \u0642\u0627\u0646\u0648\u0646 SNS \u0631\u0627 \u0627\u06cc\u062c\u0627\u062f \u06a9\u0646\u06cc\u0645.<\/p>\n<h5 id=\"5-1-%d8%af%d8%b1-%d8%a7%d8%a8%d8%aa%d8%af%d8%a7-%d8%af%d8%b1-%d9%81%d8%a7%db%8c%d9%84-modules-sns-variables-tf%d8%8c-%d8%a8%d8%a7%db%8c%d8%af-%d8%af%d9%88-%d9%85%d8%aa%d8%ba%db%8c%d8%b1-%d8%a7%db%8c\">5.1. \u062f\u0631 \u0627\u0628\u062a\u062f\u0627 \u062f\u0631 \u0641\u0627\u06cc\u0644 modules\/sns\/variables.tf\u060c \u0628\u0627\u06cc\u062f \u062f\u0648 \u0645\u062a\u063a\u06cc\u0631 \u0627\u06cc\u062c\u0627\u062f \u06a9\u0646\u06cc\u062f:<\/h5>\n<ol>\n<li>sns_name \u0628\u0631\u0627\u06cc \u0646\u0627\u0645\u06af\u0630\u0627\u0631\u06cc \u0645\u0648\u0636\u0648\u0639 SNS \u06a9\u0647 \u0627\u06cc\u062c\u0627\u062f \u062e\u0648\u0627\u0647\u06cc\u0645 \u06a9\u0631\u062f.<\/li>\n<li>\u0627\u06cc\u0645\u06cc\u0644 \u0628\u0631\u0627\u06cc \u0646\u06af\u0647 \u062f\u0627\u0634\u062a\u0646 \u0622\u062f\u0631\u0633 \u0627\u06cc\u0645\u06cc\u0644\u06cc \u06a9\u0647 \u0628\u0631\u0627\u06cc \u0627\u0634\u062a\u0631\u0627\u06a9 \u062f\u0631 \u0627\u0639\u0644\u0627\u0646 \u0647\u0627\u06cc \u062e\u0648\u062f \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc \u06a9\u0646\u06cc\u0645.<\/li>\n<\/ol>\n<p>\u062f\u0631 \u0632\u06cc\u0631 \u0646\u0645\u0648\u0646\u0647 \u0627\u06cc \u0627\u0632 \u0645\u062a\u063a\u06cc\u0631\u0647\u0627\u06cc \u0645\u0627 \u0628\u0631\u0627\u06cc SNS \u0622\u0648\u0631\u062f\u0647 \u0634\u062f\u0647 \u0627\u0633\u062a.<\/p>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\"><code>variable \"sns_name\" {\r\ndescription = \"Name of the SNS Topic to be created\"\r\ndefault = \"GuardDuty-Example\"\r\n}\r\nvariable \"email\" {\r\ndescription = \"Email address for SNS\"\r\n}\r\n<\/code><\/pre>\n<\/div>\n<h5 id=\"5-2-%d8%b3%d9%be%d8%b3-%d9%85%d9%88%d8%b6%d9%88%d8%b9-sns-%d9%88-%d8%a7%d8%b4%d8%aa%d8%b1%d8%a7%da%a9-%d8%b1%d8%a7-%d8%af%d8%b1-%d9%81%d8%a7%db%8c%d9%84-modules-sns-main-tf-%d8%a7%db%8c%d8%ac%d8%a7\">5.2. \u0633\u067e\u0633 \u0645\u0648\u0636\u0648\u0639 SNS \u0648 \u0627\u0634\u062a\u0631\u0627\u06a9 \u0631\u0627 \u062f\u0631 \u0641\u0627\u06cc\u0644 modules\/sns\/main.tf \u0627\u06cc\u062c\u0627\u062f \u0645\u06cc \u06a9\u0646\u06cc\u0645.<\/h5>\n<p>\u0628\u0627 \u0627\u06cc\u062c\u0627\u062f \u06cc\u06a9 \u0645\u0646\u0628\u0639 \u0645\u0648\u0636\u0648\u0639 \u0634\u0631\u0648\u0639 \u06a9\u0646\u06cc\u062f.<\/p>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\"><code># Create the SNS topic\r\nresource \"aws_sns_topic\" \"gd_sns_topic\" {\r\nname = var.sns_name\r\n}\r\n<\/code><\/pre>\n<\/div>\n<p>\u062f\u0631 \u06a9\u062f \u0628\u0627\u0644\u0627 \u0634\u0645\u0627 \u062f\u0631 \u062d\u0627\u0644 \u0627\u06cc\u062c\u0627\u062f \u0645\u0646\u0628\u0639\u06cc \u0647\u0633\u062a\u06cc\u062f \u06a9\u0647 \u062a\u0648\u0633\u0637 Terraform gd_sns_topic \u0646\u0627\u0645\u06cc\u062f\u0647 \u0645\u06cc \u0634\u0648\u062f. \u062f\u0631 \u06a9\u0646\u0633\u0648\u0644 AWS\u060c &#8220;GuardDuty-Example&#8221; \u0646\u0627\u0645\u06cc\u062f\u0647 \u0645\u06cc \u0634\u0648\u062f. \u0627\u06cc\u0646 \u0628\u0647 \u0627\u06cc\u0646 \u062f\u0644\u06cc\u0644 \u0627\u0633\u062a \u06a9\u0647 \u0645\u0627 \u0645\u062a\u063a\u06cc\u0631 var.sns_name \u0631\u0627 \u0641\u0631\u0627\u062e\u0648\u0627\u0646\u06cc \u0645\u06cc \u06a9\u0646\u06cc\u0645 \u0648 \u06cc\u06a9 \u062a\u0646\u0638\u06cc\u0645 \u067e\u06cc\u0634 \u0641\u0631\u0636 \u0631\u0648\u06cc &#8220;GuardDuty-Example&#8221; \u062f\u0627\u0631\u062f.<\/p>\n<h5 id=\"5-3-%d8%b3%d9%be%d8%b3-%db%8c%da%a9-%d9%85%d9%86%d8%a8%d8%b9-%d8%b3%db%8c%d8%a7%d8%b3%d8%aa-sns-%d8%a7%db%8c%d8%ac%d8%a7%d8%af-%da%a9%d9%86%db%8c%d8%af-arn-%d9%88-policy-%d9%85%d9%82%d8%a7%d8%af\">5.3. \u0633\u067e\u0633 \u06cc\u06a9 \u0645\u0646\u0628\u0639 \u0633\u06cc\u0627\u0633\u062a SNS \u0627\u06cc\u062c\u0627\u062f \u06a9\u0646\u06cc\u062f. arn \u0648 Policy \u0645\u0642\u0627\u062f\u06cc\u0631 \u0645\u0648\u0631\u062f \u0646\u06cc\u0627\u0632 \u0647\u0633\u062a\u0646\u062f. \u062e\u0637 \u0645\u0634\u06cc \u0627\u06cc\u062c\u0627\u062f \u0634\u062f\u0647 \u062f\u0631 \u0627\u06cc\u0646\u062c\u0627 \u06cc\u06a9 \u0633\u0646\u062f \u062e\u0637 \u0645\u0634\u06cc AWS IAM \u0627\u0633\u062a. \u0627\u06cc\u0646 \u0633\u0646\u062f \u062e\u0637 \u0645\u0634\u06cc \u0628\u0647 \u0633\u0631\u0648\u06cc\u0633 principal events.amazonaws.com \u0627\u062c\u0627\u0632\u0647 \u0645\u06cc \u062f\u0647\u062f \u062a\u0627 \u062f\u0631 \u0645\u0648\u0636\u0648\u0639 \u0645\u0648\u0631\u062f \u0646\u0638\u0631 \u0645\u0646\u062a\u0634\u0631 \u06a9\u0646\u062f.<\/h5>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\"><code>resource \"aws_sns_topic_policy\" \"gd_sns_topic_policy\" {\r\narn = aws_sns_topic.gd_sns_topic.arn\r\npolicy = jsonencode(\r\n{\r\nId = \"ID-GD-Topic-Policy\"\r\nStatement = [\r\n{\r\nAction = \"sns:Publish\"\r\nEffect = \"Allow\"\r\nPrincipal = {\r\nService = \"events.amazonaws.com\"\r\n}\r\nResource = aws_sns_topic.gd_sns_topic.arn\r\nSid = \"SID-GD-Example\"\r\n},\r\n]\r\nVersion = \"2012-10-17\"\r\n}\r\n)\r\n}\r\n<\/code><\/pre>\n<\/div>\n<h5 id=\"5-4-%d8%af%d8%b1-%d9%85%d8%b1%d8%ad%d9%84%d9%87-%d8%a8%d8%b9%d8%af-%d8%a7%d8%b4%d8%aa%d8%b1%d8%a7%da%a9-%d9%85%d9%88%d8%b6%d9%88%d8%b9-%d8%b1%d8%a7-%d8%a7%db%8c%d8%ac%d8%a7%d8%af-%d9%85%db%8c-%da%a9\">5.4. \u062f\u0631 \u0645\u0631\u062d\u0644\u0647 \u0628\u0639\u062f \u0627\u0634\u062a\u0631\u0627\u06a9 \u0645\u0648\u0636\u0648\u0639 \u0631\u0627 \u0627\u06cc\u062c\u0627\u062f \u0645\u06cc \u06a9\u0646\u06cc\u062f. \u0627\u0634\u062a\u0631\u0627\u06a9 \u0645\u0648\u0636\u0648\u0639 ARN \u0631\u0627 \u0641\u0631\u0627\u062e\u0648\u0627\u0646\u06cc \u0645\u06cc \u06a9\u0646\u062f\u060c \u067e\u0631\u0648\u062a\u06a9\u0644 \u0645\u0648\u0631\u062f \u0627\u0633\u062a\u0641\u0627\u062f\u0647 &#8211; \u062f\u0631 \u0627\u06cc\u0646 \u0645\u0648\u0631\u062f \u0627\u06cc\u0645\u06cc\u0644 &#8211; \u0648 \u0622\u062f\u0631\u0633 \u0627\u06cc\u0645\u06cc\u0644\u06cc \u06a9\u0647 \u0627\u0639\u0644\u0627\u0646 \u0628\u0647 \u0622\u0646 \u0627\u0631\u0633\u0627\u0644 \u0645\u06cc \u0634\u0648\u062f \u0631\u0627 \u062a\u0646\u0638\u06cc\u0645 \u0645\u06cc \u06a9\u0646\u062f. \u0622\u062f\u0631\u0633 \u0627\u06cc\u0645\u06cc\u0644 \u062f\u0631 \u0627\u06cc\u0646 \u0645\u0648\u0631\u062f \u0633\u062e\u062a \u06a9\u062f\u06af\u0630\u0627\u0631\u06cc \u0645\u06cc \u0634\u0648\u062f\u060c \u0627\u0645\u0627 \u0645\u06cc \u062a\u0648\u0627\u0646\u06cc\u062f \u0622\u0646 \u0631\u0627 \u0637\u0648\u0631\u06cc \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u06a9\u0646\u06cc\u062f \u06a9\u0647 \u0647\u0646\u06af\u0627\u0645 \u0627\u0639\u0645\u0627\u0644 Terraform\u060c \u0622\u062f\u0631\u0633 \u0627\u06cc\u0645\u06cc\u0644 \u0631\u0627 \u062f\u0631\u062e\u0648\u0627\u0633\u062a \u06a9\u0646\u062f. \u0647\u0645\u0686\u0646\u06cc\u0646\u060c \u062a\u0646\u0638\u06cc\u0645 endpoint_auto_confirm \u0631\u0648\u06cc false \u0628\u0647 \u0627\u06cc\u0646 \u0645\u0639\u0646\u06cc \u0627\u0633\u062a \u06a9\u0647 \u0635\u0627\u062d\u0628 \u0627\u06cc\u0645\u06cc\u0644 \u0627\u06cc\u0645\u06cc\u0644\u06cc \u0628\u0627 \u067e\u06cc\u0648\u0646\u062f\u06cc \u062f\u0631\u06cc\u0627\u0641\u062a \u0645\u06cc\u200c\u06a9\u0646\u062f \u06a9\u0647 \u0628\u0627\u06cc\u062f \u0628\u0631\u0627\u06cc \u0627\u0634\u062a\u0631\u0627\u06a9 \u062f\u0631 \u0627\u0639\u0644\u0627\u0646\u200c\u0647\u0627 \u0631\u0648\u06cc \u0622\u0646 \u06a9\u0644\u06cc\u06a9 \u06a9\u0646\u062f.<\/h5>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\"><code># Create the topic subscription \r\nresource \"aws_sns_topic_subscription\" \"user_updates_sqs_target\" {\r\ntopic_arn = aws_sns_topic.gd_sns_topic.arn\r\nprotocol = \"email\"\r\nendpoint = var.email\r\nendpoint_auto_confirms = false\r\n}\r\n<\/code><\/pre>\n<\/div>\n<h5 id=\"5-5-%d8%a8%d8%b9%d8%af%d8%8c-%d8%af%d8%b1-%d9%81%d8%a7%db%8c%d9%84-modules-sns-outputs-tf%d8%8c-%d9%85%db%8c%d8%ae%d9%88%d8%a7%d9%87%db%8c%d9%85-arn-%d9%85%d9%88%d8%b6%d9%88%d8%b9-%d8%b1\">5.5. \u0628\u0639\u062f\u060c \u062f\u0631 \u0641\u0627\u06cc\u0644 modules\/sns\/outputs.tf\u060c \u0645\u06cc\u200c\u062e\u0648\u0627\u0647\u06cc\u0645 ARN \u0645\u0648\u0636\u0648\u0639 \u0631\u0627 \u062e\u0631\u0648\u062c\u06cc \u0628\u06af\u06cc\u0631\u06cc\u0645 \u062a\u0627 \u0628\u062a\u0648\u0627\u0646\u06cc\u0645 \u0627\u0634\u0627\u0631\u0647 \u06a9\u0646\u06cc\u0645 \u06a9\u0647 \u062f\u0631 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc EventBridge \u0628\u0639\u062f\u0627\u064b \u0627\u0646\u062c\u0627\u0645 \u062e\u0648\u0627\u0647\u06cc\u0645 \u062f\u0627\u062f.<\/h5>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\"><code>output \"sns_topic_arn\" {\r\nvalue = aws_sns_topic.gd_sns_topic.arn\r\ndescription = \"Output of ARN to call in the eventbridge rule.\"\r\n}\r\n<\/code><\/pre>\n<\/div>\n<h5 id=\"5-6-%d8%af%d8%b1-%d9%86%d9%87%d8%a7%db%8c%d8%aa-%d8%a8%d9%87-%d9%81%d8%a7%db%8c%d9%84-root-main-tf-%d8%a8%d8%b1%da%af%d8%b1%d8%af%db%8c%d8%af-%d9%88-%d9%85%d9%88%d8%b6%d9%88%d8%b9-sns-%d8%b1%d8%a7\">5.6. \u062f\u0631 \u0646\u0647\u0627\u06cc\u062a \u0628\u0647 \u0641\u0627\u06cc\u0644 root\/main.tf \u0628\u0631\u06af\u0631\u062f\u06cc\u062f \u0648 \u0645\u0648\u0636\u0648\u0639 SNS \u0631\u0627 \u0627\u0636\u0627\u0641\u0647 \u06a9\u0646\u06cc\u062f. \u0627\u06cc\u0646 \u062c\u0627\u06cc\u06cc \u0627\u0633\u062a \u06a9\u0647 \u0634\u0645\u0627 \u0622\u062f\u0631\u0633 \u0627\u06cc\u0645\u06cc\u0644\u06cc \u0631\u0627 \u0628\u0631\u0627\u06cc \u0627\u0634\u062a\u0631\u0627\u06a9 \u062a\u0639\u06cc\u06cc\u0646 \u0645\u06cc \u06a9\u0646\u06cc\u062f.<\/h5>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\"><code># Creates an SNS Topic\r\nmodule \"guardduty_sns_topic\" {\r\nsource = \".\/modules\/sns\"\r\nemail = \"youremailaddress@domain.com\"\r\n}\r\n<\/code><\/pre>\n<\/div>\n<p>\u062f\u0631 \u0627\u06cc\u0646 \u0628\u062e\u0634 \u0634\u0645\u0627 \u0645\u0648\u0636\u0648\u0639\u0627\u062a SNS \u0631\u0627 \u0627\u06cc\u062c\u0627\u062f \u06a9\u0631\u062f\u06cc\u062f \u062a\u0627 \u062f\u0631 \u0635\u0648\u0631\u062a \u062a\u0648\u0644\u06cc\u062f \u06cc\u06a9 \u06cc\u0627\u0641\u062a\u0647 \u062e\u0627\u0635\u060c \u0627\u06cc\u0645\u06cc\u0644\u06cc \u0628\u0631\u0627\u06cc \u0634\u0645\u0627 \u0627\u0631\u0633\u0627\u0644 \u0634\u0648\u062f.<\/p>\n<h2 id=\"%d9%85%d8%b1%d8%ad%d9%84%d9%87-6-%d9%85%d8%a7%da%98%d9%88%d9%84-eventbridge-terraform-%d8%b1%d8%a7-%d8%a7%db%8c%d8%ac%d8%a7%d8%af-%da%a9%d9%86%db%8c%d8%af\">\u0645\u0631\u062d\u0644\u0647 6: \u0645\u0627\u0698\u0648\u0644 EventBridge Terraform \u0631\u0627 \u0627\u06cc\u062c\u0627\u062f \u06a9\u0646\u06cc\u062f<\/h2>\n<p>\u062f\u0631 \u0627\u06cc\u0646 \u0628\u062e\u0634 \u0627\u0632 Terraform \u0628\u0631\u0627\u06cc \u0627\u06cc\u062c\u0627\u062f \u06cc\u06a9 \u0642\u0627\u0646\u0648\u0646 EventBridge \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u062e\u0648\u0627\u0647\u06cc\u062f \u06a9\u0631\u062f. \u0642\u0627\u0646\u0648\u0646 EventBridge \u062f\u0648 \u0639\u0646\u0635\u0631 \u0627\u06cc\u0646 \u0631\u0627\u0647 \u062d\u0644 \u0631\u0627 \u0628\u0647 \u0647\u0645 \u06af\u0631\u0647 \u0645\u06cc \u0632\u0646\u062f.<\/p>\n<p>EventBridge \u0686\u06af\u0648\u0646\u0647 \u06a9\u0627\u0631 \u0645\u06cc \u06a9\u0646\u062f\u061f \u0627\u0633\u0627\u0633\u0627\u060c EventBridge \u06cc\u06a9 \u0631\u0648\u06cc\u062f\u0627\u062f &#8211; \u0646\u0634\u0627\u0646\u06af\u0631 \u062a\u063a\u06cc\u06cc\u0631 \u062f\u0631 \u0645\u062d\u06cc\u0637 &#8211; \u0631\u0627 \u062f\u0631\u06cc\u0627\u0641\u062a \u0645\u06cc \u06a9\u0646\u062f \u0648 \u06cc\u06a9 \u0642\u0627\u0646\u0648\u0646 \u0631\u0627 \u0628\u0631\u0627\u06cc \u0645\u0633\u06cc\u0631\u06cc\u0627\u0628\u06cc \u0631\u0648\u06cc\u062f\u0627\u062f \u0628\u0647 \u06cc\u06a9 \u0647\u062f\u0641 \u0627\u0639\u0645\u0627\u0644 \u0645\u06cc \u06a9\u0646\u062f. \u0642\u0648\u0627\u0646\u06cc\u0646 \u0628\u0631 \u0627\u0633\u0627\u0633 \u0633\u0627\u062e\u062a\u0627\u0631 \u0631\u0648\u06cc\u062f\u0627\u062f\u060c \u06a9\u0647 \u0627\u0644\u06af\u0648\u06cc \u0631\u0648\u06cc\u062f\u0627\u062f \u0646\u0627\u0645\u06cc\u062f\u0647 \u0645\u06cc \u0634\u0648\u062f\u060c \u06cc\u0627 \u0628\u0631 \u0627\u0633\u0627\u0633 \u06cc\u06a9 \u0628\u0631\u0646\u0627\u0645\u0647\u060c \u0631\u0648\u06cc\u062f\u0627\u062f\u0647\u0627 \u0631\u0627 \u0628\u0627 \u0627\u0647\u062f\u0627\u0641 \u0645\u0637\u0627\u0628\u0642\u062a \u0645\u06cc \u062f\u0647\u0646\u062f. \u062f\u0631 \u0627\u06cc\u0646 \u0645\u0648\u0631\u062f\u060c GuardDuty \u06cc\u06a9 \u0631\u0648\u06cc\u062f\u0627\u062f \u0628\u0631\u0627\u06cc Amazon EventBridge \u0627\u06cc\u062c\u0627\u062f \u0645\u06cc \u06a9\u0646\u062f \u06a9\u0647 \u0647\u0631 \u062a\u063a\u06cc\u06cc\u0631\u06cc \u062f\u0631 \u06cc\u0627\u0641\u062a\u0647 \u0647\u0627 \u0631\u062e \u062f\u0647\u062f. \u0631\u0648\u06cc\u062f\u0627\u062f \u0645\u0637\u0627\u0628\u0642\u062a \u062f\u0627\u0631\u062f \u0648 \u0622\u0645\u0627\u0632\u0648\u0646 EventBridge \u0628\u0647 \u06cc\u06a9 \u0647\u062f\u0641 \u062d\u06a9\u0645 \u0645\u06cc\u200c\u06a9\u0646\u062f. \u062f\u0631 \u0627\u06cc\u0646 \u0645\u0648\u0631\u062f\u060c \u0647\u062f\u0641 \u0642\u0627\u0646\u0648\u0646 anSNS \u0627\u0633\u062a. \u0642\u0627\u0646\u0648\u0646 SNS \u062f\u0627\u062f\u0647 \u0647\u0627\u06cc \u06cc\u0627\u0641\u062a \u0634\u062f\u0647 \u0631\u0627 \u0645\u06cc \u06af\u06cc\u0631\u062f \u0648 \u06cc\u06a9 \u0627\u0639\u0644\u0627\u0646 \u0627\u06cc\u0645\u06cc\u0644 \u0628\u0631\u0627\u06cc \u06a9\u0627\u0631\u0628\u0631 \u0645\u0634\u062a\u0631\u06a9 \u0627\u06cc\u062c\u0627\u062f \u0645\u06cc \u06a9\u0646\u062f.<\/p>\n<h5 id=\"6-1-%d9%82%d8%a7%d9%86%d9%88%d9%86-eventbridge-%d8%a8%d9%87-%d8%a7%d8%b7%d9%84%d8%a7%d8%b9%d8%a7%d8%aa%db%8c-%d8%af%d8%b1-%d9%85%d9%88%d8%b1%d8%af-guardduty-%d9%88-sns-%d9%86%db%8c%d8%a7%d8%b2-%d8%af\">6.1. \u0642\u0627\u0646\u0648\u0646 EventBridge \u0628\u0647 \u0627\u0637\u0644\u0627\u0639\u0627\u062a\u06cc \u062f\u0631 \u0645\u0648\u0631\u062f GuardDuty \u0648 SNS \u0646\u06cc\u0627\u0632 \u062f\u0627\u0631\u062f. \u0628\u0627 \u0627\u06cc\u062c\u0627\u062f \u0645\u062a\u063a\u06cc\u0631\u06cc \u0634\u0631\u0648\u0639 \u06a9\u0646\u06cc\u062f \u06a9\u0647 \u0645\u06cc \u062a\u0648\u0627\u0646\u062f \u0628\u0631\u0627\u06cc \u0645\u0648\u0636\u0648\u0639 SNS ARN \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0634\u0648\u062f. \u0627\u06cc\u0646 \u06a9\u0627\u0631 \u0631\u0627 \u062f\u0631 \u0641\u0627\u06cc\u0644 modules\/eventbridge\/variables.tf \u0627\u0646\u062c\u0627\u0645 \u062f\u0647\u06cc\u062f.<\/h5>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\"><code>variable \"sns_topic_arn\" {\r\n}\r\n<\/code><\/pre>\n<\/div>\n<h5 id=\"6-2-%d8%a8%d8%b9%d8%af%d8%8c-%db%8c%da%a9-%d9%85%d9%86%d8%a8%d8%b9-%d9%82%d8%a7%d9%86%d9%88%d9%86-%d8%b1%d9%88%db%8c%d8%af%d8%a7%d8%af-%d8%af%d8%b1-%d9%81%d8%a7%db%8c%d9%84-modules-eventbridge-main-t\">6.2. \u0628\u0639\u062f\u060c \u06cc\u06a9 \u0645\u0646\u0628\u0639 \u0642\u0627\u0646\u0648\u0646 \u0631\u0648\u06cc\u062f\u0627\u062f \u062f\u0631 \u0641\u0627\u06cc\u0644 modules\/eventbridge\/main.tf \u0627\u06cc\u062c\u0627\u062f \u06a9\u0646\u06cc\u062f. \u0634\u0645\u0627 \u0628\u0627\u06cc\u062f \u0645\u0646\u0628\u0639 \u0648 \u0646\u0648\u0639 \u0631\u0648\u06cc\u062f\u0627\u062f \u0645\u0648\u0631\u062f \u0646\u0638\u0631 \u0645\u0627 \u0631\u0627 \u062a\u0639\u0631\u06cc\u0641 \u06a9\u0646\u06cc\u062f.<\/h5>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\"><code> # EVENT RULE RESOURCE\r\nresource \"aws_cloudwatch_event_rule\" \"GuardDuty-Event-EC2-MaliciousIPCaller\" {\r\nname = \"GuardDuty-Event-EC2-MaliciousIPCaller\"\r\ndescription = \"GuardDuty Event: UnauthorizedAccess:EC2\/MaliciousIPCaller.Custom\"\r\nevent_pattern = &lt;&lt;EOF\r\n{\r\n\"source\": [\"aws.guardduty\"],\r\n\"detail\": {\r\n\"type\": [\"UnauthorizedAccess:EC2\/MaliciousIPCaller.Custom\"]\r\n}\r\n}\r\nEOF\r\n}\r\n<\/code><\/pre>\n<\/div>\n<h5 id=\"6-3-%d8%b3%d9%be%d8%b3-%d9%85%d9%86%d8%a8%d8%b9-%d9%87%d8%af%d9%81-%d8%b1%d9%88%db%8c%d8%af%d8%a7%d8%af-%d8%b1%d8%a7-%d8%aa%d8%b9%d8%b1%db%8c%d9%81-%da%a9%d9%86%db%8c%d8%af-%d9%87%d9%86%da%af%d8%a7\">6.3. \u0633\u067e\u0633 \u0645\u0646\u0628\u0639 \u0647\u062f\u0641 \u0631\u0648\u06cc\u062f\u0627\u062f \u0631\u0627 \u062a\u0639\u0631\u06cc\u0641 \u06a9\u0646\u06cc\u062f. \u0647\u0646\u06af\u0627\u0645 \u0627\u06cc\u062c\u0627\u062f \u0627\u06cc\u0646 \u0645\u0646\u0628\u0639\u060c \u0645\u06cc \u062a\u0648\u0627\u0646\u06cc\u062f \u0628\u0627 \u062a\u0639\u0631\u06cc\u0641 \u06cc\u06a9 \u062a\u0631\u0627\u0646\u0633\u0641\u0648\u0631\u0645\u0627\u062a\u0648\u0631 \u0648\u0631\u0648\u062f\u06cc\u060c \u06a9\u0645\u06cc \u062e\u0648\u0627\u0646\u0627\u06cc\u06cc \u0627\u0636\u0627\u0641\u06cc \u0628\u0647 \u0627\u0639\u0644\u0627\u0646 \u0627\u06cc\u0645\u06cc\u0644 \u0627\u0636\u0627\u0641\u0647 \u06a9\u0646\u06cc\u062f. \u0627\u06cc\u0646 \u0627\u0645\u0631 \u0622\u0646\u0686\u0647 EventBridge \u0628\u0647 \u0647\u062f\u0641 \u0631\u0648\u06cc\u062f\u0627\u062f \u0627\u0631\u0633\u0627\u0644 \u0645\u06cc \u06a9\u0646\u062f \u0633\u0641\u0627\u0631\u0634\u06cc \u0645\u06cc \u06a9\u0646\u062f. \u062f\u0631 \u0632\u06cc\u0631 \u0645\u0627 \u0634\u0646\u0627\u0633\u0647 GuardDuty\u060c \u0645\u0646\u0637\u0642\u0647 \u0648 \u0634\u0646\u0627\u0633\u0647 \u0646\u0645\u0648\u0646\u0647 EC2 \u0631\u0627 \u062f\u0631\u06cc\u0627\u0641\u062a \u0645\u06cc \u06a9\u0646\u06cc\u0645 &#8211; \u0648 \u062f\u0631 \u062d\u0627\u0644 \u0627\u06cc\u062c\u0627\u062f \u06cc\u06a9 \u0627\u0644\u06af\u0648\u06cc \u0648\u0631\u0648\u062f\u06cc \u0647\u0633\u062a\u06cc\u0645 \u06a9\u0647 \u06a9\u0645\u06cc \u062f\u0631 \u0645\u0648\u0631\u062f \u067e\u06cc\u0627\u0645 \u062a\u0648\u0636\u06cc\u062d \u0645\u06cc \u062f\u0647\u062f. \u062f\u0631 \u0632\u06cc\u0631 \u0645\u06cc \u0628\u06cc\u0646\u06cc\u062f \u06a9\u0647 \u0645\u0627 \u06cc\u06a9 \u0627\u0644\u06af\u0648\u06cc \u0648\u0631\u0648\u062f\u06cc \u0627\u06cc\u062c\u0627\u062f \u06a9\u0631\u062f\u0647 \u0627\u06cc\u0645 \u06a9\u0647 \u0627\u0632 \u0627\u0637\u0644\u0627\u0639\u0627\u062a \u062c\u0632\u0626\u06cc\u0627\u062a \u0645\u0648\u062c\u0648\u062f \u062f\u0631 \u06cc\u0627\u0641\u062a\u0647 GuardDuty \u062f\u0631 \u067e\u06cc\u0627\u0645 \u0627\u06cc\u0645\u06cc\u0644 \u0627\u0631\u0633\u0627\u0644 \u0634\u062f\u0647 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc \u06a9\u0646\u062f.<\/h5>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\"><code># EVENT TARGET RESOURCE FOR SNS NOTIFICATIONS\r\nresource \"aws_cloudwatch_event_target\" \"sns\" {\r\nrule = aws_cloudwatch_event_rule.GuardDuty-Event-EC2-MaliciousIPCaller.name\r\ntarget_id = \"GuardDuty-Example\"\r\narn = var.sns_topic_arn\r\ninput_transformer {\r\ninput_paths = {\r\ngdid = \"$.detail.id\",\r\nregion = \"$.detail.region\",\r\ninstanceid = \"$.detail.resource.instanceDetails.instanceId\"\r\n}\r\ninput_template = \"\\\"First GuardDuty Finding for the GuardDuty-IAC tutorial. | ID:&lt;gdid&gt; | The EC2 instance: &lt;instanceid&gt;, may be compromised and should be investigated. Go to https:\/\/console.aws.amazon.com\/guardduty\/home?region=&lt;region&gt;#\/findings?macros=current&amp;fId=&lt;gdid&gt;\\\"\"\r\n}\r\n}<\/code><\/pre>\n<\/div>\n<h5 id=\"6-4-%d8%af%d8%b1-%d8%a7%d9%88%d9%84%db%8c%d9%86-%d9%82%d8%a7%d9%86%d9%88%d9%86-event-%da%a9%d9%87-%d8%a7%db%8c%d8%ac%d8%a7%d8%af-%da%a9%d8%b1%d8%af%db%8c%d9%85%d8%8c-%d8%a8%d9%87-%d8%af%d9%86%d8%a8\">6.4. \u062f\u0631 \u0627\u0648\u0644\u06cc\u0646 \u0642\u0627\u0646\u0648\u0646 Event \u06a9\u0647 \u0627\u06cc\u062c\u0627\u062f \u06a9\u0631\u062f\u06cc\u0645\u060c \u0628\u0647 \u062f\u0646\u0628\u0627\u0644 \u0631\u0648\u06cc\u062f\u0627\u062f GuardDuty-Event-EC2-MaliciousIPCaller \u0647\u0633\u062a\u06cc\u0645. \u06cc\u06a9 \u0642\u0627\u0646\u0648\u0646 \u0631\u0648\u06cc\u062f\u0627\u062f \u062f\u0648\u0645 \u0627\u06cc\u062c\u0627\u062f \u06a9\u0646\u06cc\u062f \u062a\u0627 \u0628\u0647 \u062f\u0646\u0628\u0627\u0644 \u06cc\u0627\u0641\u062a\u0646 GuardDuty-Event-IAMUser-MaliciousIPCaller \u0628\u06af\u0631\u062f\u06cc\u062f \u0648 \u0628\u0631\u0627\u06cc \u0622\u0646 \u0646\u06cc\u0632 \u06cc\u06a9 \u0627\u0639\u0644\u0627\u0646 \u0627\u06cc\u0645\u06cc\u0644 \u0627\u0631\u0633\u0627\u0644 \u06a9\u0646\u06cc\u062f.<\/h5>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\"><code># EVENT RULE RESOURCE\r\nresource \"aws_cloudwatch_event_rule\" \"GuardDuty-Event-IAMUser-MaliciousIPCaller\" {\r\nname = \"GuardDuty-Event-IAMUser-MaliciousIPCaller\"\r\ndescription = \"GuardDuty Event: UnauthorizedAccess:IAMUser\/MaliciousIPCaller.Custom\"\r\nevent_pattern = &lt;&lt;EOF\r\n{\r\n\"source\": [\"aws.guardduty\"],\r\n\"detail\": {\r\n\"type\": [\"UnauthorizedAccess:IAMUser\/MaliciousIPCaller.Custom\", \"Discovery:S3\/MaliciousIPCaller.Custom\"]\r\n}\r\n}\r\nEOF\r\n}\r\n#EVENT TARGET RESOURCE FOR SNS NOTIFICATIONS\r\nresource \"aws_cloudwatch_event_target\" \"iam-sns\" {\r\nrule = aws_cloudwatch_event_rule.GuardDuty-Event-IAMUser-MaliciousIPCaller.name\r\ntarget_id = \"GuardDuty-Example\"\r\narn = var.sns_topic_arn\r\ninput_transformer {\r\ninput_paths = {\r\ngdid = \"$.detail.id\",\r\nregion = \"$.detail.region\",\r\nuserName = \"$.detail.resource.accessKeyDetails.userName\"\r\n} \r\ninput_template = \"\\\"Second GuardDuty Finding for the GuardDuty-IAC tutorial. | ID:&lt;gdid&gt; | AWS Region:&lt;region&gt;. An AWS API operation was invoked (userName: &lt;userName&gt;) from an IP address that is included on your threat list and should be investigated.Go to https:\/\/console.aws.amazon.com\/guardduty\/home?region=&lt;region&gt;#\/findings?macros=current&amp;fId=&lt;gdid&gt;\\\"\"\r\n}\r\n}<\/code><\/pre>\n<\/div>\n<h5 id=\"6-5-%d9%87%d9%86%da%af%d8%a7%d9%85%db%8c-%da%a9%d9%87-%d9%85%d9%86%d8%a7%d8%a8%d8%b9-%d8%a7%db%8c%d8%ac%d8%a7%d8%af-%d8%b4%d8%af%d9%87-%d8%af%d8%b1-%d9%85%d8%a7%da%98%d9%88%d9%84-%d8%b1%d8%a7-%d8%af\">6.5. \u0647\u0646\u06af\u0627\u0645\u06cc \u06a9\u0647 \u0645\u0646\u0627\u0628\u0639 \u0627\u06cc\u062c\u0627\u062f \u0634\u062f\u0647 \u062f\u0631 \u0645\u0627\u0698\u0648\u0644 \u0631\u0627 \u062f\u0627\u0631\u06cc\u062f\u060c \u0628\u0647 \u0641\u0627\u06cc\u0644 root\/main.tf \u0628\u0631\u06af\u0631\u062f\u06cc\u062f \u0648 \u0642\u0627\u0646\u0648\u0646 EventBridge \u0631\u0627 \u0627\u0636\u0627\u0641\u0647 \u06a9\u0646\u06cc\u062f.<\/h5>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\"><code># Create the EventBridge rule\r\nmodule \"guardduty_eventbridge_rule\" {\r\nsource = \".\/modules\/eventbridge\"\r\nsns_topic_arn = module.guardduty_sns_topic.sns_topic_arn\r\n}<\/code><\/pre>\n<\/div>\n<p>\u062f\u0631 \u0627\u06cc\u0646 \u0628\u062e\u0634 \u06cc\u06a9 \u0642\u0627\u0646\u0648\u0646 EventBridge \u0627\u06cc\u062c\u0627\u062f \u06a9\u0631\u062f\u06cc\u062f \u06a9\u0647 \u0627\u0632 \u0645\u0648\u0636\u0648\u0639 SNS \u06a9\u0647 \u0627\u06cc\u062c\u0627\u062f \u06a9\u0631\u062f\u0647\u200c\u0627\u06cc\u062f \u0628\u0631\u0627\u06cc \u0627\u0631\u0633\u0627\u0644 \u0627\u06cc\u0645\u06cc\u0644 \u062f\u0631 \u0635\u0648\u0631\u062a \u062a\u0637\u0628\u06cc\u0642 \u06cc\u0627\u0641\u062a\u0647\u200c\u0647\u0627\u06cc GuardDuty \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc\u200c\u06a9\u0646\u062f. \u062f\u0631 \u0628\u062e\u0634 \u0628\u0639\u062f\u06cc \u0627\u06cc\u0646 \u0639\u0645\u0644\u06a9\u0631\u062f \u0631\u0627 \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 Lambda \u0627\u0641\u0632\u0627\u06cc\u0634 \u062e\u0648\u0627\u0647\u06cc\u062f \u062f\u0627\u062f.<\/p>\n<h2 id=\"%d9%85%d8%b1%d8%ad%d9%84%d9%87-7-%d9%85%d8%a7%da%98%d9%88%d9%84-lambda-terraform-%d8%b1%d8%a7-%d8%a7%db%8c%d8%ac%d8%a7%d8%af-%da%a9%d9%86%db%8c%d8%af\">\u0645\u0631\u062d\u0644\u0647 7: \u0645\u0627\u0698\u0648\u0644 Lambda Terraform \u0631\u0627 \u0627\u06cc\u062c\u0627\u062f \u06a9\u0646\u06cc\u062f<\/h2>\n<p>\u062f\u0631 \u0627\u06cc\u0646 \u0628\u062e\u0634 \u0645\u0627 \u0627\u0632 Terraform \u0628\u0631\u0627\u06cc \u0627\u06cc\u062c\u0627\u062f \u06cc\u06a9 \u062a\u0627\u0628\u0639 Lambda \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc \u06a9\u0646\u06cc\u0645 \u06a9\u0647 \u06cc\u06a9 \u062a\u0627\u0628\u0639 \u0627\u0635\u0644\u0627\u062d \u0631\u0627 \u0628\u0631\u0627\u06cc \u0645\u062d\u06cc\u0637 \u0645\u0627 \u0627\u0646\u062c\u0627\u0645 \u0645\u06cc \u062f\u0647\u062f. \u06a9\u0627\u0631\u06cc \u06a9\u0647 \u0645\u0627 \u0645\u06cc \u062e\u0648\u0627\u0647\u06cc\u0645 \u0628\u0627 \u0627\u06cc\u0646 \u0622\u0645\u0648\u0632\u0634 \u0627\u0646\u062c\u0627\u0645 \u062f\u0647\u06cc\u0645 \u0627\u06cc\u0646 \u0627\u0633\u062a \u06a9\u0647 \u0645\u06cc\u0632\u0628\u0627\u0646 \u062f\u0631 \u0645\u0639\u0631\u0636 \u062e\u0637\u0631 \u0645\u0627 \u0628\u0647 \u06cc\u06a9 \u06af\u0631\u0648\u0647 \u0627\u0645\u0646\u06cc\u062a\u06cc \u062c\u062f\u06cc\u062f \u0645\u0646\u062a\u0642\u0644 \u0634\u0648\u062f. \u0645\u0634\u0627\u0628\u0647 \u0631\u0648\u0634\u06cc \u06a9\u0647 EventBridge \u0627\u0632 SNS \u0628\u0631\u0627\u06cc \u062a\u0648\u0644\u06cc\u062f \u0627\u06cc\u0645\u06cc\u0644 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0631\u062f\u060c EventBridge \u062a\u0627\u0628\u0639 Lambda \u0631\u0627 \u062f\u0631 \u0628\u0631 \u062e\u0648\u0627\u0647\u062f \u06af\u0631\u0641\u062a.<\/p>\n<p>\u0646\u06a9\u062a\u0647 \u0627\u06cc \u06a9\u0647 \u0628\u0627\u06cc\u062f \u062f\u0631 \u0646\u0638\u0631 \u062f\u0627\u0634\u062a \u0627\u06cc\u0646 \u0627\u0633\u062a \u06a9\u0647 \u0628\u0633\u06cc\u0627\u0631\u06cc \u0627\u0632 \u0631\u0648\u06cc\u06a9\u0631\u062f\u0647\u0627\u06cc \u0645\u0645\u06a9\u0646 \u062f\u0631 \u0627\u06cc\u0646\u062c\u0627 \u0648\u062c\u0648\u062f \u062f\u0627\u0631\u062f. \u0628\u0631\u0627\u06cc \u0627\u0637\u0644\u0627\u0639\u0627\u062a \u0628\u06cc\u0634\u062a\u0631\u060c \u0644\u0637\u0641\u0627\u064b \u0628\u0647 \u0645\u0633\u062a\u0646\u062f\u0627\u062a \u0645\u0631\u0628\u0648\u0637 \u0628\u0647 \u0627\u06cc\u062c\u0627\u062f \u067e\u0627\u0633\u062e\u200c\u0647\u0627\u06cc \u0633\u0641\u0627\u0631\u0634\u06cc \u0628\u0647 \u06cc\u0627\u0641\u062a\u0647\u200c\u0647\u0627\u06cc GuardDuty \u0628\u0627 \u0631\u0648\u06cc\u062f\u0627\u062f\u0647\u0627\u06cc Amazon CloudWatch \u0648 \u0645\u0633\u062f\u0648\u062f \u06a9\u0631\u062f\u0646 \u062e\u0648\u062f\u06a9\u0627\u0631 \u062a\u0631\u0627\u0641\u06cc\u06a9 \u0645\u0634\u06a9\u0648\u06a9 \u0628\u0627 \u0641\u0627\u06cc\u0631\u0648\u0627\u0644 \u0634\u0628\u06a9\u0647 AWS \u0648 Amazon GuardDuty \u0645\u0631\u0627\u062c\u0639\u0647 \u06a9\u0646\u06cc\u062f.<\/p>\n<p>\u0642\u0628\u0644 \u0627\u0632 \u0634\u0631\u0648\u0639\u060c \u0628\u06cc\u0627\u06cc\u06cc\u062f \u0628\u0628\u06cc\u0646\u06cc\u0645 \u0686\u0647 \u0627\u062a\u0641\u0627\u0642\u06cc \u0628\u0627\u06cc\u062f \u0628\u06cc\u0641\u062a\u062f \u062a\u0627 \u0627\u06cc\u0646 \u06a9\u0627\u0631 \u0627\u0646\u062c\u0627\u0645 \u0634\u0648\u062f.<\/p>\n<p>\u062f\u0631 \u062d\u0627\u0644 \u062d\u0627\u0636\u0631\u060c \u06cc\u0627\u0641\u062a\u0647\u200c\u0647\u0627\u06cc GuardDuty \u0645\u0627 \u062f\u0631 \u06cc\u06a9 \u0642\u0627\u0646\u0648\u0646 EventBridge \u0628\u0627 \u06cc\u06a9 \u0647\u062f\u0641 \u062a\u0637\u0628\u06cc\u0642 \u062f\u0627\u062f\u0647 \u0634\u062f\u0647 \u0627\u0633\u062a &#8211; \u062f\u0631 \u062d\u0627\u0644 \u062d\u0627\u0636\u0631 \u06cc\u06a9 \u0642\u0627\u0646\u0648\u0646 SNS \u06a9\u0647 \u06cc\u06a9 \u0627\u06cc\u0645\u06cc\u0644 \u0627\u0631\u0633\u0627\u0644 \u0645\u06cc\u200c\u06a9\u0646\u062f. \u0628\u0631\u0627\u06cc \u0627\u0631\u062a\u0642\u0627\u06cc \u0627\u06cc\u0646 \u0642\u0627\u0628\u0644\u06cc\u062a\u060c EventBridge \u0627\u0632 AWS Lambda \u0628\u0647 \u0639\u0646\u0648\u0627\u0646 \u0647\u062f\u0641 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc \u06a9\u0646\u062f.<\/p>\n<p>\u0627\u0632 \u0622\u0646\u062c\u0627\u06cc\u06cc \u06a9\u0647 \u0645\u0627 \u0642\u0635\u062f \u062f\u0627\u0631\u06cc\u0645 \u0627\u0632 \u0637\u0631\u0641 \u062e\u0648\u062f AWS Lambda \u0628\u0647 \u0645\u0646\u0627\u0628\u0639 \u062f\u06cc\u06af\u0631\u06cc \u062f\u0633\u062a\u0631\u0633\u06cc \u062f\u0627\u0634\u062a\u0647 \u0628\u0627\u0634\u06cc\u0645\u060c \u0628\u0627\u06cc\u062f \u06cc\u06a9 \u0646\u0642\u0634 IAM \u0627\u06cc\u062c\u0627\u062f \u06a9\u0646\u06cc\u0645 \u062a\u0627 \u0645\u062c\u0648\u0632\u0647\u0627 \u0631\u0627 \u0628\u0647 \u0633\u0631\u0648\u06cc\u0633 \u0648\u0627\u06af\u0630\u0627\u0631 \u06a9\u0646\u06cc\u0645. \u0627\u06cc\u0646 \u0646\u0642\u0634 \u06cc\u06a9 \u0633\u0631\u0648\u06cc\u0633 \u0646\u0627\u0645\u06cc\u062f\u0647 \u0645\u06cc \u0634\u0648\u062f \u0648 AWS Lambda \u0632\u0645\u0627\u0646\u06cc \u06a9\u0647 \u06af\u0631\u0648\u0647 \u0627\u0645\u0646\u06cc\u062a\u06cc \u0646\u0645\u0648\u0646\u0647 EC2 \u0645\u0627 \u0631\u0627 \u062a\u063a\u06cc\u06cc\u0631 \u0645\u06cc \u062f\u0647\u062f\u060c \u0627\u06cc\u0646 \u0646\u0642\u0634 \u0631\u0627 \u0628\u0631 \u0639\u0647\u062f\u0647 \u0645\u06cc \u06af\u06cc\u0631\u062f.<\/p>\n<p>\u062a\u0635\u0648\u06cc\u0631 \u0632\u06cc\u0631 \u0646\u0634\u0627\u0646 \u0645\u06cc\u200c\u062f\u0647\u062f \u06a9\u0647 \u0686\u06af\u0648\u0646\u0647 \u0633\u0647 \u0628\u0644\u0648\u06a9 \u06a9\u062f \u0627\u0648\u0644 \u0628\u0627 \u0647\u0645 \u0642\u0631\u0627\u0631 \u0645\u06cc\u200c\u06af\u06cc\u0631\u0646\u062f \u062a\u0627 \u0628\u0647 \u0633\u0631\u0648\u06cc\u0633 AWS Lambda \u0627\u062c\u0627\u0632\u0647 \u062f\u0647\u0646\u062f \u0646\u0642\u0634\u06cc \u0631\u0627 \u0628\u0631 \u0639\u0647\u062f\u0647 \u0628\u06af\u06cc\u0631\u0646\u062f \u06a9\u0647 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u062f \u062a\u063a\u06cc\u06cc\u0631\u0627\u062a\u06cc \u062f\u0631 \u06af\u0631\u0648\u0647\u200c\u0647\u0627\u06cc \u0627\u0645\u0646\u06cc\u062a\u06cc \u0627\u062e\u062a\u0635\u0627\u0635 \u062f\u0627\u062f\u0647 \u0634\u062f\u0647 \u0628\u0647 \u0646\u0645\u0648\u0646\u0647\u200c\u0647\u0627\u06cc EC2 \u0627\u06cc\u062c\u0627\u062f \u06a9\u0646\u062f.<\/p>\n<h5 id=\"7-1-%d8%a8%d8%a7-%d8%a7%db%8c%d8%ac%d8%a7%d8%af-%d8%b3%d9%86%d8%af-%d8%b3%db%8c%d8%a7%d8%b3%d8%aa-iam-%d8%af%d8%b1-modules-lambda-main-tf-%d8%b4%d8%b1%d9%88%d8%b9-%da%a9%d9%86%db%8c%d8%af-%d8%a7\"><img  loading=\"lazy\"  decoding=\"async\"  src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABAQMAAAAl21bKAAAAA1BMVEUAAP+KeNJXAAAAAXRSTlMAQObYZgAAAAlwSFlzAAAOxAAADsQBlSsOGwAAAApJREFUCNdjYAAAAAIAAeIhvDMAAAAASUVORK5CYII=\"  alt=\"\"  width=\"750\"  height=\"417\"  class=\"aligncenter wp-image-15296 size-full pk-lazyload\"  data-pk-sizes=\"auto\"  data-ls-sizes=\"auto, (max-width: 750px) 100vw, 750px\"  data-pk-src=\"https:\/\/cdn.itpiran.net\/2024\/04\/13230652\/13.webp\"  data-pk-srcset=\"https:\/\/cdn.itpiran.net\/2024\/04\/13230652\/13.webp 750w, https:\/\/cdn.itpiran.net\/2024\/04\/13230652\/13-300x167.webp 300w, https:\/\/cdn.itpiran.net\/2024\/04\/13230652\/13-110x61.webp 110w, https:\/\/cdn.itpiran.net\/2024\/04\/13230652\/13-200x111.webp 200w, https:\/\/cdn.itpiran.net\/2024\/04\/13230652\/13-380x211.webp 380w, https:\/\/cdn.itpiran.net\/2024\/04\/13230652\/13-255x142.webp 255w, https:\/\/cdn.itpiran.net\/2024\/04\/13230652\/13-550x306.webp 550w\" ><br \/>\n7.1. \u0628\u0627 \u0627\u06cc\u062c\u0627\u062f \u0633\u0646\u062f \u0633\u06cc\u0627\u0633\u062a IAM \u062f\u0631 modules\/lambda\/main.tf \u0634\u0631\u0648\u0639 \u06a9\u0646\u06cc\u062f. \u0627\u06cc\u0646 \u0631\u0627\u0628\u0637\u0647 \u0627\u0639\u062a\u0645\u0627\u062f \u0628\u0631\u0627\u06cc \u0633\u06cc\u0627\u0633\u062a \u0627\u0633\u062a.<\/h5>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\"><code>data \"aws_iam_policy_document\" \"GD-EC2MaliciousIPCaller-policy-document\" {\r\nstatement {\r\neffect = \"Allow\"\r\nactions = [\"sts:AssumeRole\"]\r\nprincipals {\r\ntype = \"Service\"\r\nidentifiers = [\"lambda.amazonaws.com\"]\r\n}\r\n}\r\n}\r\n<\/code><\/pre>\n<\/div>\n<h5 id=\"7-2-%d8%af%d8%b1-%d9%85%d8%b1%d8%ad%d9%84%d9%87-%d8%a8%d8%b9%d8%af%d8%8c-%d8%ae%d8%b7-%d9%85%d8%b4%db%8c-%d8%af%d8%b1%d9%88%d9%86-%d8%ae%d8%b7%db%8c-%d8%b1%d8%a7-%d8%a7%db%8c%d8%ac%d8%a7%d8%af-%da%a9\">7.2. \u062f\u0631 \u0645\u0631\u062d\u0644\u0647 \u0628\u0639\u062f\u060c \u062e\u0637 \u0645\u0634\u06cc \u062f\u0631\u0648\u0646 \u062e\u0637\u06cc \u0631\u0627 \u0627\u06cc\u062c\u0627\u062f \u06a9\u0646\u06cc\u062f \u06a9\u0647 \u0628\u0631\u0627\u06cc \u0646\u0642\u0634\u06cc \u06a9\u0647 AWS Lambda \u0628\u0631 \u0639\u0647\u062f\u0647 \u0645\u06cc \u06af\u06cc\u0631\u062f \u0627\u0639\u0645\u0627\u0644 \u0645\u06cc \u0634\u0648\u062f.<\/h5>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\"><code>resource \"aws_iam_role_policy\" \"GD-EC2MaliciousIPCaller-inline-role-policy\" {\r\nname = \"GD-EC2MaliciousIPCaller-inline-role-policy\"\r\nrole = aws_iam_role.GD-Lambda-EC2MaliciousIPCaller-role.id\r\npolicy = jsonencode({\r\n\"Version\" : \"2012-10-17\",\r\n\"Statement\" : [\r\n{\r\n\"Action\" : [\r\n\"ssm:PutParameter\",\r\n\"ec2:AuthorizeSecurityGroupEgress\",\r\n\"ec2:AuthorizeSecurityGroupIngress\",\r\n\"ec2:CreateSecurityGroup\",\r\n\"ec2:DescribeSecurityGroups\",\r\n\"ec2:RevokeSecurityGroupEgress\",\r\n\"ec2:RevokeSecurityGroupIngress\",\r\n\"ec2:UpdateSecurityGroupRuleDescriptionsEgress\",\r\n\"ec2:UpdateSecurityGroupRuleDescriptionsIngress\",\r\n\"ec2:DescribeInstances\",\r\n\"ec2:UpdateSecurityGroupRuleDescriptionsIngress\",\r\n\"ec2:DescribeVpcs\",\r\n\"ec2:ModifyInstanceAttribute\",\r\n\"lambda:InvokeFunction\",\r\n\"cloudwatch:PutMetricData\",\r\n\"xray:PutTraceSegments\",\r\n\"xray:PutTelemetryRecords\"\r\n],\r\n\"Resource\" : \"*\",\r\n\"Effect\" : \"Allow\"\r\n},\r\n{\r\n\"Action\" : [\r\n\"logs:*\"\r\n],\r\n\"Resource\" : \"arn:aws:logs:*:*:*\",\r\n\"Effect\" : \"Allow\"\r\n},\r\n{\r\n\"Action\" : [\r\n\"sns:Publish\"\r\n],\r\n\"Resource\" : var.sns_topic_arn,\r\n\"Effect\" : \"Allow\"\r\n} \r\n]\r\n})\r\n}\r\n<\/code><\/pre>\n<\/div>\n<h5 id=\"7-3-%d9%88-%d8%a7%da%a9%d9%86%d9%88%d9%86-%d9%86%d9%82%d8%b4-iam-%d8%b1%d8%a7-%d8%a7%db%8c%d8%ac%d8%a7%d8%af-%da%a9%d9%86%db%8c%d8%af-%da%a9%d9%87-aws-lambda-%d8%a2%d9%86-%d8%b1%d8%a7-%d8%a8%d8%b1\">7.3. \u0648 \u0627\u06a9\u0646\u0648\u0646 \u0646\u0642\u0634 IAM \u0631\u0627 \u0627\u06cc\u062c\u0627\u062f \u06a9\u0646\u06cc\u062f \u06a9\u0647 AWS Lambda \u0622\u0646 \u0631\u0627 \u0628\u0631 \u0639\u0647\u062f\u0647 \u062e\u0648\u0627\u0647\u062f \u06af\u0631\u0641\u062a.<\/h5>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\"><code>resource \"aws_iam_role\" \"GD-Lambda-EC2MaliciousIPCaller-role\" {\r\nname = \"GD-Lambda-EC2MaliciousIPCaller-role1\"\r\nassume_role_policy = data.aws_iam_policy_document.GD-EC2MaliciousIPCaller-policy-document.json\r\n}\r\n<\/code><\/pre>\n<\/div>\n<h5 id=\"7-4-%db%8c%da%a9-%d9%85%d9%86%d8%a8%d8%b9-%d8%af%d8%a7%d8%af%d9%87-%d8%a8%d8%a7-%d8%a7%d8%b4%d8%a7%d8%b1%d9%87-%d8%a8%d9%87-%da%a9%d8%af-%d8%a7%db%8c%d8%ac%d8%a7%d8%af-%da%a9%d9%86%db%8c%d8%af\">7.4. \u06cc\u06a9 \u0645\u0646\u0628\u0639 \u062f\u0627\u062f\u0647 \u0628\u0627 \u0627\u0634\u0627\u0631\u0647 \u0628\u0647 \u06a9\u062f \u0627\u06cc\u062c\u0627\u062f \u06a9\u0646\u06cc\u062f.<\/h5>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\"><code>data \"archive_file\" \"python_lambda_package\" {\r\ntype = \"zip\"\r\nsource_file = \"${path.module}\/code\/index.py\"\r\noutput_path = \"index.zip\"\r\n}\r\n<\/code><\/pre>\n<\/div>\n<h5 id=\"7-5-%d8%af%d8%b1-%d9%85%d8%b1%d8%ad%d9%84%d9%87-%d8%a8%d8%b9%d8%af-%d8%a8%d8%a7%db%8c%d8%af-%d8%a8%d9%87-eventbridge-%d8%a7%d8%ac%d8%a7%d8%b2%d9%87-%d8%af%d8%b3%d8%aa%d8%b1%d8%b3%db%8c-%d8%a8%d9%87-l\">7.5. \u062f\u0631 \u0645\u0631\u062d\u0644\u0647 \u0628\u0639\u062f \u0628\u0627\u06cc\u062f \u0628\u0647 EventBridge \u0627\u062c\u0627\u0632\u0647 \u062f\u0633\u062a\u0631\u0633\u06cc \u0628\u0647 Lambda \u0631\u0627 \u0628\u062f\u0647\u06cc\u0645.<\/h5>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\"><code>resource \"aws_lambda_permission\" \"GuardDuty-Hands-On-RemediationLambda\" {\r\nstatement_id = \"GuardDutyTerraformRemediationLambdaEC2InvokePermissions\"\r\naction = \"lambda:InvokeFunction\"\r\nfunction_name = aws_lambda_function.GuardDuty-Example-Remediation-EC2MaliciousIPCaller.function_name\r\nprincipal = \"events.amazonaws.com\"\r\n}\r\n<\/code><\/pre>\n<\/div>\n<p>\u0628\u0644\u0648\u06a9 \u0641\u0648\u0642 \u0628\u0647 EventBridge \u0627\u062c\u0627\u0632\u0647 \u0645\u06cc \u062f\u0647\u062f \u062a\u0627 \u062a\u0627\u0628\u0639 Lambda \u0631\u0627 \u0641\u0631\u0627\u062e\u0648\u0627\u0646\u06cc \u06a9\u0646\u062f.<\/p>\n<h5 id=\"7-6-%d8%af%d8%b1-%d9%86%d9%87%d8%a7%db%8c%d8%aa-%d9%85%d8%a7-%d9%85%d9%86%d8%a8%d8%b9-%d8%aa%d8%a7%d8%a8%d8%b9-lambda-%d8%b1%d8%a7-%d8%a7%db%8c%d8%ac%d8%a7%d8%af-%d9%85%db%8c-%da%a9%d9%86%db%8c%d9%85\">7.6. \u062f\u0631 \u0646\u0647\u0627\u06cc\u062a \u0645\u0627 \u0645\u0646\u0628\u0639 \u062a\u0627\u0628\u0639 Lambda \u0631\u0627 \u0627\u06cc\u062c\u0627\u062f \u0645\u06cc \u06a9\u0646\u06cc\u0645. \u0628\u0631\u0627\u06cc \u0627\u06cc\u0646 \u06a9\u0627\u0631 \u0628\u0627\u06cc\u062f \u0686\u0646\u062f \u0645\u062a\u063a\u06cc\u0631 \u0627\u06cc\u062c\u0627\u062f \u06a9\u0646\u06cc\u0645 \u06a9\u0647 \u0628\u0647 \u0645\u0627 \u0627\u062c\u0627\u0632\u0647 \u0645\u06cc \u062f\u0647\u062f \u0627\u0637\u0644\u0627\u0639\u0627\u062a\u06cc \u0631\u0627 \u0645\u0646\u062a\u0642\u0644 \u06a9\u0646\u06cc\u0645. \u0641\u0627\u06cc\u0644 modules\/lambda\/variables.tf \u0631\u0627 \u0628\u0627 \u0645\u062a\u063a\u06cc\u0631\u0647\u0627\u06cc \u0632\u06cc\u0631 \u0648\u06cc\u0631\u0627\u06cc\u0634 \u06a9\u0646\u06cc\u062f:<\/h5>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\"><code>variable \"sns_topic_arn\" {\r\n}\r\nvariable \"compromised_instance_id\" {\r\n}\r\nvariable \"forensic_sg_id\" {\r\n}<\/code><\/pre>\n<\/div>\n<h5 id=\"7-7-%d8%b3%d9%be%d8%b3-%d8%a8%d9%87-%d9%81%d8%a7%db%8c%d9%84-modules-lambda-main-tf-%d8%a8%d8%b1%da%af%d8%b1%d8%af%db%8c%d8%af-%d9%88-%d9%85%d9%86%d8%a8%d8%b9-%d8%aa%d8%a7%d8%a8%d8%b9-lambda-%d8%b1\">7.7. \u0633\u067e\u0633 \u0628\u0647 \u0641\u0627\u06cc\u0644 modules\/lambda\/main.tf \u0628\u0631\u06af\u0631\u062f\u06cc\u062f \u0648 \u0645\u0646\u0628\u0639 \u062a\u0627\u0628\u0639 Lambda \u0631\u0627 \u0627\u06cc\u062c\u0627\u062f \u06a9\u0646\u06cc\u062f. \u062a\u0648\u062c\u0647 \u062f\u0627\u0634\u062a\u0647 \u0628\u0627\u0634\u06cc\u062f \u06a9\u0647 \u062f\u0631 \u0628\u0644\u0648\u06a9 \u06a9\u062f \u0632\u06cc\u0631 \u0627\u0632 Python 3.9 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc \u06a9\u0646\u06cc\u0645. \u0647\u0645\u0686\u0646\u06cc\u0646\u060c \u0645\u0627 \u0628\u0647 \u06a9\u062f \u067e\u0627\u06cc\u062a\u0648\u0646\u06cc \u06a9\u0647 \u062f\u0631 index.zip \u0632\u06cc\u067e \u06a9\u0631\u062f\u0647 \u0627\u06cc\u0645\u060c \u0627\u0631\u062c\u0627\u0639 \u0645\u06cc \u062f\u0647\u06cc\u0645. \u0648 \u062f\u0631 \u0622\u062e\u0631 \u0645\u0627 \u0686\u0646\u062f \u0645\u062a\u063a\u06cc\u0631 \u0645\u062d\u06cc\u0637\u06cc \u0631\u0627 \u062f\u0631 \u0645\u0646\u0628\u0639 \u062a\u0646\u0638\u06cc\u0645 \u0645\u06cc \u06a9\u0646\u06cc\u0645: INSTANCE_ID\u060c FORENSICS_SG\u060c \u0648 TOPIC_ARN. \u0627\u06cc\u0646\u0647\u0627 \u0627\u0632 \u0645\u062a\u063a\u06cc\u0631\u0647\u0627\u06cc\u06cc \u06a9\u0647 \u0627\u06cc\u062c\u0627\u062f \u06a9\u0631\u062f\u06cc\u0645 \u0628\u0647 \u0645\u062d\u06cc\u0637 \u062a\u0627\u0628\u0639 Lambda \u0645\u0627 \u0645\u0646\u062a\u0642\u0644 \u0645\u06cc \u0634\u0648\u0646\u062f.<\/h5>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\"><code># Create the Lambda function Resource\r\nresource \"aws_lambda_function\" \"GuardDuty-Example-Remediation-EC2MaliciousIPCaller\" {\r\nfunction_name = \"GuardDuty-Example-Remediation-EC2MaliciousIPCaller\"\r\nfilename = \"index.zip\"\r\nsource_code_hash = data.archive_file.python_lambda_package.output_base64sha256\r\nrole = aws_iam_role.GD-Lambda-EC2MaliciousIPCaller-role.arn\r\nruntime = \"python3.9\"\r\nhandler = \"index.handler\"\r\ntimeout = 10\r\nenvironment {\r\nvariables = {\r\nINSTANCE_ID = var.compromised_instance_id\r\nFORENSICS_SG = var.forensic_sg_id\r\nTOPIC_ARN = var.sns_topic_arn\r\n}\r\n}\r\n}<\/code><\/pre>\n<\/div>\n<h5 id=\"7-8-%d8%af%d8%b1-%d9%81%d8%a7%db%8c%d9%84-root-main-tf-%d9%85%d8%a7%da%98%d9%88%d9%84-lambda-%d8%b1%d8%a7-%d9%81%d8%b1%d8%a7%d8%ae%d9%88%d8%a7%d9%86%db%8c-%da%a9%d9%86%db%8c%d8%af%d8%8c-%d9%85%d9%88\">7.8. \u062f\u0631 \u0641\u0627\u06cc\u0644 root\/main.tf \u0645\u0627\u0698\u0648\u0644 Lambda \u0631\u0627 \u0641\u0631\u0627\u062e\u0648\u0627\u0646\u06cc \u06a9\u0646\u06cc\u062f\u060c \u0645\u0648\u0636\u0648\u0639 SNS ARN\u060c \u0634\u0646\u0627\u0633\u0647 \u0646\u0645\u0648\u0646\u0647 \u062f\u0631 \u0645\u0639\u0631\u0636 \u062e\u0637\u0631 \u0648 \u06af\u0631\u0648\u0647 Forensic Security \u0631\u0627 \u062a\u0646\u0638\u06cc\u0645 \u06a9\u0646\u06cc\u062f. \u062a\u0648\u062c\u0647 \u062f\u0627\u0634\u062a\u0647 \u0628\u0627\u0634\u06cc\u062f \u06a9\u0647 \u0627\u06cc\u0646 \u0645\u0642\u0627\u062f\u06cc\u0631 \u0627\u0632 \u0645\u0627\u0698\u0648\u0644 GuardDuty\u060c \u0645\u0627\u0698\u0648\u0644 \u0645\u062d\u0627\u0633\u0628\u0647 \u0648 \u0645\u0627\u0698\u0648\u0644 VPC \u0645\u06cc \u0622\u06cc\u0646\u062f.<\/h5>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\"><code># CREATE THE LAMBDA FUNCTION\r\nmodule \"lambda\" {\r\nsource = \".\/modules\/lambda\"\r\nsns_topic_arn = module.guardduty_sns_topic.sns_topic_arn\r\ncompromised_instance_id = module.compute.compromised_instance_id\r\nforensic_sg_id = module.forensic-security-group.security_group_id\r\n}\r\n<\/code><\/pre>\n<\/div>\n<h5 id=\"7-9-%da%af%d8%b1%d9%88%d9%87-%d8%a7%d9%85%d9%86%db%8c%d8%aa-%d9%82%d8%a7%d9%86%d9%88%d9%86%db%8c-%d9%87%d9%86%d9%88%d8%b2-%d8%a7%db%8c%d8%ac%d8%a7%d8%af-%d9%86%d8%b4%d8%af%d9%87-%d8%a7%d8%b3%d8%aa\">7.9. \u06af\u0631\u0648\u0647 \u0627\u0645\u0646\u06cc\u062a \u0642\u0627\u0646\u0648\u0646\u06cc \u0647\u0646\u0648\u0632 \u0627\u06cc\u062c\u0627\u062f \u0646\u0634\u062f\u0647 \u0627\u0633\u062a. \u06cc\u06a9 \u06af\u0631\u0648\u0647 \u0627\u0645\u0646\u06cc\u062a\u06cc \u0628\u0631\u0627\u06cc \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u062f\u0631 \u0627\u0636\u0627\u0641\u0647 \u06a9\u0646\u06cc\u062f.<\/h5>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\"><code># CREATES THE FORENSICS_SG SECURITY GROUP\r\nmodule \"forensic-security-group\" {\r\nsource = \"terraform-aws-modules\/security-group\/aws\"\r\nversion = \"4.17.1\"\r\nname = \"FORENSIC_SG\"\r\ndescription = \"Forensic Security group \"\r\nvpc_id = module.iac_vpc.vpc_attributes.id\r\n}<\/code><\/pre>\n<\/div>\n<h5 id=\"7-10-%d8%a8%d8%b1%d8%a7%db%8c-%d8%af%d8%b3%d8%aa%d8%b1%d8%b3%db%8c-%d8%a8%d9%87-%da%af%d8%b1%d9%88%d9%87-%d8%a7%d9%85%d9%86%db%8c%d8%aa%db%8c-%d9%82%d8%a7%d9%86%d9%88%d9%86%db%8c%d8%8c-%d8%a8%d8%a7\">7.10. \u0628\u0631\u0627\u06cc \u062f\u0633\u062a\u0631\u0633\u06cc \u0628\u0647 \u06af\u0631\u0648\u0647 \u0627\u0645\u0646\u06cc\u062a\u06cc-\u0642\u0627\u0646\u0648\u0646\u06cc\u060c \u0628\u0627\u06cc\u062f \u0622\u0646 \u0631\u0627 \u062e\u0631\u0648\u062c\u06cc \u0628\u06af\u06cc\u0631\u06cc\u0645. \u062f\u0631 \u0641\u0627\u06cc\u0644 root\/outputs.tf \u0648 \u062e\u0631\u0648\u062c\u06cc \u0634\u0646\u0627\u0633\u0647 \u06af\u0631\u0648\u0647 \u0627\u0645\u0646\u06cc\u062a.<\/h5>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\">output \"forensic_sg_id\" {\r\nvalue = module.forensic-security-group.security_group_id\r\ndescription = \"Output of forensic sg id created - to place the EC2 instance(s).\"\r\n}<\/pre>\n<\/div>\n<h5 id=\"7-11-%d8%a7%da%a9%d9%86%d9%88%d9%86-%d8%a8%d8%a7%db%8c%d8%af-%d9%82%d8%a7%d9%86%d9%88%d9%86-eventbridge-%d8%b1%d8%a7-%d8%aa%d9%86%d8%b8%db%8c%d9%85-%da%a9%d9%86%db%8c%d9%85-%d8%aa%d8%a7-%d8%af%d8%a7\">7.11. \u0627\u06a9\u0646\u0648\u0646 \u0628\u0627\u06cc\u062f \u0642\u0627\u0646\u0648\u0646 EventBridge \u0631\u0627 \u062a\u0646\u0638\u06cc\u0645 \u06a9\u0646\u06cc\u0645 \u062a\u0627 \u062f\u0627\u062f\u0647 \u0647\u0627\u06cc \u06cc\u0627\u0641\u062a\u0647 \u0631\u0627 \u0628\u0647 Lambda \u0627\u0631\u0633\u0627\u0644 \u06a9\u0646\u06cc\u0645. \u062f\u0631 \u0628\u062e\u0634 \u0628\u0639\u062f\u06cc \u0627\u06cc\u0646 \u06a9\u0627\u0631 \u0631\u0627 \u0627\u0646\u062c\u0627\u0645 \u062e\u0648\u0627\u0647\u06cc\u0645 \u062f\u0627\u062f. \u0628\u0647 \u0641\u0627\u06cc\u0644 modules\/eventbridge\/main.tf \u0628\u0631\u06af\u0631\u062f\u06cc\u062f. \u06cc\u06a9 \u0645\u0646\u0628\u0639 \u0647\u062f\u0641 \u0631\u0648\u06cc\u062f\u0627\u062f \u0628\u0631\u0627\u06cc \u062a\u0627\u0628\u0639 Lambda \u0627\u0636\u0627\u0641\u0647 \u06a9\u0646\u06cc\u062f \u06a9\u0647 \u0628\u0647 \u0642\u0627\u0646\u0648\u0646 aws_cloudwatch_event_rule.GuardDuty-Event-EC2-MaliciousIPCaller.name \u0646\u06af\u0627\u0647 \u0645\u06cc \u06a9\u0646\u062f \u0648 \u0634\u0646\u0627\u0633\u0647 \u0647\u062f\u0641 \u0631\u0627 \u0631\u0648\u06cc GuardDuty-Example-Remediation \u062a\u0646\u0638\u06cc\u0645 \u0645\u06cc \u06a9\u0646\u062f. \u062f\u0631 \u0627\u06cc\u0646\u062c\u0627 \u0628\u0647 ARN \u062a\u0627\u0628\u0639 \u0644\u0627\u0645\u0628\u062f\u0627 \u0646\u06cc\u0627\u0632 \u062f\u0627\u0631\u06cc\u062f. \u0627\u06cc\u0646 \u0631\u0627 \u0645\u06cc \u062a\u0648\u0627\u0646 \u0627\u0632 \u0645\u0627\u0698\u0648\u0644 Lambda \u062e\u0631\u0648\u062c\u06cc \u06af\u0631\u0641\u062a.<\/h5>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\"><code>#EVENT TARGET RESOURCE FOR LAMBDA REMEDIATION FUNCTION\r\nresource \"aws_cloudwatch_event_target\" \"lambda_function\" {\r\nrule = aws_cloudwatch_event_rule.GuardDuty-Event-EC2-MaliciousIPCaller.name\r\ntarget_id = \"GuardDuty-Example-Remediation\"\r\narn = var.lambda_remediation_function_arn\r\n}<\/code><\/pre>\n<\/div>\n<h5 id=\"7-12-%d8%a7%da%af%d8%b1-%d9%82%d8%a8%d9%84%d8%a7%d9%8b-%d8%a7%db%8c%d9%86-%da%a9%d8%a7%d8%b1-%d8%b1%d8%a7-%d9%86%da%a9%d8%b1%d8%af%d9%87-%d8%a7%db%8c%d8%af%d8%8c-%d8%ae%d8%b1%d9%88%d8%ac%db%8c-%d8%b1\">7.12. \u0627\u06af\u0631 \u0642\u0628\u0644\u0627\u064b \u0627\u06cc\u0646 \u06a9\u0627\u0631 \u0631\u0627 \u0646\u06a9\u0631\u062f\u0647 \u0627\u06cc\u062f\u060c \u062e\u0631\u0648\u062c\u06cc \u0631\u0627 \u0628\u0647 \u0645\u0627\u0698\u0648\u0644 \u0644\u0627\u0645\u0628\u062f\u0627 (modules\/lambda\/outputs.tf) \u0627\u0636\u0627\u0641\u0647 \u06a9\u0646\u06cc\u062f.<\/h5>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\"><code>output \"lambda_remediation_function_arn\" {\r\nvalue = aws_lambda_function.GuardDuty-Example-Remediation-EC2MaliciousIPCaller.arn\r\n}\r\n<\/code><\/pre>\n<\/div>\n<h5 id=\"7-13-%d8%a7%db%8c%d9%86-%d9%85%d8%aa%d8%ba%db%8c%d8%b1-%d9%87%d9%85%da%86%d9%86%db%8c%d9%86-%d8%a8%d8%a7%db%8c%d8%af-%d8%af%d8%b1-%d9%85%d8%a7%da%98%d9%88%d9%84-eventbridge-modules-eventbridge-varia\">7.13. \u0627\u06cc\u0646 \u0645\u062a\u063a\u06cc\u0631 \u0647\u0645\u0686\u0646\u06cc\u0646 \u0628\u0627\u06cc\u062f \u062f\u0631 \u0645\u0627\u0698\u0648\u0644 EventBridge (modules\/eventbridge\/variables.tf) \u0627\u0639\u0645\u0627\u0644 \u0634\u0648\u062f.<\/h5>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\"><code>variable \"lambda_remediation_function_arn\" {\r\n}<\/code><\/pre>\n<\/div>\n<h5 id=\"7-14-%d9%88-%d8%af%d8%b1-%d9%86%d9%87%d8%a7%db%8c%d8%aa-lambda_remediation_function_arn-%d8%b1%d8%a7-%d8%a8%d9%87-%d9%81%d8%a7%db%8c%d9%84-root-main-tf-%d8%a7%d8%b6%d8%a7%d9%81%d9%87-%da%a9%d9%86\">7.14. \u0648 \u062f\u0631 \u0646\u0647\u0627\u06cc\u062a lambda_remediation_function_arn \u0631\u0627 \u0628\u0647 \u0641\u0627\u06cc\u0644 root\/main.tf \u0627\u0636\u0627\u0641\u0647 \u06a9\u0646\u06cc\u062f. \u0627\u06cc\u0646 \u062f\u0631 \u0642\u0627\u0646\u0648\u0646 EventBridge \u06a9\u0647 \u0642\u0628\u0644\u0627 \u0627\u06cc\u062c\u0627\u062f \u0634\u062f\u0647 \u0627\u0633\u062a \u0645\u06cc \u0631\u0648\u062f. \u062e\u0631\u0648\u062c\u06cc \u0632\u06cc\u0631 \u06a9\u0644 \u0628\u0644\u0648\u06a9 \u06a9\u062f \u0627\u0633\u062a \u06a9\u0647 \u0628\u0631\u062e\u06cc \u0627\u0632 \u0622\u0646\u0647\u0627 \u0642\u0628\u0644\u0627\u064b \u0648\u062c\u0648\u062f \u062f\u0627\u0631\u062f. \u0645\u0637\u0645\u0626\u0646 \u0634\u0648\u06cc\u062f \u06a9\u0647 \u0641\u0642\u0637 \u06a9\u062f lambda_remediation_function_arn = module.lambda.lambda_remediation_function_arn \u0631\u0627 \u0628\u0647 \u0628\u0644\u0648\u06a9 \u0645\u0648\u062c\u0648\u062f \u0627\u0636\u0627\u0641\u0647 \u06a9\u0646\u06cc\u062f.<\/h5>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-plain\" data-lang=\"Plain Text\"><code>module \"guardduty_eventbridge_rule\" {\r\nsource = \".\/modules\/eventbridge\"\r\nsns_topic_arn = module.guardduty_sns_topic.sns_topic_arn\r\nlambda_remediation_function_arn = module.lambda.lambda_remediation_function_arn\r\n}\r\n<\/code><\/pre>\n<\/div>\n<p>\u062f\u0631 \u0627\u06cc\u0646 \u0628\u062e\u0634 \u06cc\u06a9 \u062a\u0627\u0628\u0639 Lambda \u0627\u06cc\u062c\u0627\u062f \u06a9\u0631\u062f\u06cc\u062f \u06a9\u0647 \u06cc\u06a9 \u0645\u06cc\u0632\u0628\u0627\u0646 \u062f\u0631 \u0645\u0639\u0631\u0636 \u062e\u0637\u0631 \u0631\u0627 \u062f\u0631 \u06cc\u06a9 \u06af\u0631\u0648\u0647 \u0627\u0645\u0646\u06cc\u062a\u06cc \u0645\u062a\u0641\u0627\u0648\u062a \u062c\u062f\u0627 \u0645\u06cc \u06a9\u0646\u062f. \u0627\u06cc\u0646 \u062a\u0627\u0628\u0639 \u0644\u0627\u0645\u0628\u062f\u0627 \u0632\u0645\u0627\u0646\u06cc \u062a\u0648\u0633\u0637 EventBridge \u0641\u0631\u0627\u062e\u0648\u0627\u0646\u06cc \u0645\u06cc \u0634\u0648\u062f \u06a9\u0647 \u06cc\u06a9 \u06cc\u0627\u0641\u062a\u0647 GuardDuty \u0628\u0627 \u0642\u0627\u0646\u0648\u0646 EventBridge \u0645\u0637\u0627\u0628\u0642\u062a \u062f\u0627\u062f\u0647 \u0634\u0648\u062f. \u062f\u0631 \u0628\u062e\u0634 \u0628\u0639\u062f\u06cc \u06a9\u0644 \u062a\u0646\u0638\u06cc\u0645\u0627\u062a \u0631\u0627 \u0627\u0639\u0645\u0627\u0644 \u062e\u0648\u0627\u0647\u06cc\u062f \u06a9\u0631\u062f.<\/p>\n<h2 id=\"%d9%85%d8%b1%d8%ad%d9%84%d9%87-8-%d8%aa%d9%86%d8%b8%db%8c%d9%85%d8%a7%d8%aa-%d8%b1%d8%a7-%d8%af%d8%b1-%d8%ad%d8%b3%d8%a7%d8%a8-aws-%d8%ae%d9%88%d8%af-%d8%a7%d8%b9%d9%85%d8%a7%d9%84-%da%a9%d9%86%db%8c\">\u0645\u0631\u062d\u0644\u0647 8: \u062a\u0646\u0638\u06cc\u0645\u0627\u062a \u0631\u0627 \u062f\u0631 \u062d\u0633\u0627\u0628 AWS \u062e\u0648\u062f \u0627\u0639\u0645\u0627\u0644 \u06a9\u0646\u06cc\u062f<\/h2>\n<h5 id=\"8-1-%db%8c%da%a9-init-terraform-%d8%b1%d8%a7-%d8%a7%d8%ac%d8%b1%d8%a7-%da%a9%d9%86%db%8c%d8%af-%d8%a8%d8%a7-%d8%a7%db%8c%d9%86-%da%a9%d8%a7%d8%b1-%d8%aa%d9%85%d8%a7%d9%85-%d9%85%d8%a7%da%98%d9%88\">8.1. \u06cc\u06a9 init terraform \u0631\u0627 \u0627\u062c\u0631\u0627 \u06a9\u0646\u06cc\u062f. \u0628\u0627 \u0627\u06cc\u0646 \u06a9\u0627\u0631 \u062a\u0645\u0627\u0645 \u0645\u0627\u0698\u0648\u0644 \u0647\u0627\u06cc\u06cc \u06a9\u0647 \u062f\u0631 \u0627\u06cc\u0646 \u0622\u0645\u0648\u0632\u0634 \u06a9\u062f \u0627\u0636\u0627\u0641\u0647 \u06a9\u0631\u062f\u0647 \u0627\u06cc\u062f \u0645\u0642\u062f\u0627\u0631\u062f\u0647\u06cc \u0627\u0648\u0644\u06cc\u0647 \u0645\u06cc \u0634\u0648\u062f. \u062e\u0631\u0648\u062c\u06cc \u0628\u0627\u06cc\u062f \u0634\u0628\u06cc\u0647 \u0645\u0648\u0627\u0631\u062f \u0632\u06cc\u0631 \u0628\u0627\u0634\u062f.<\/h5>\n<h5 id=\"8-2-%db%8c%da%a9-%d9%be%d9%84%d8%a7%d9%86-%d8%b2%d9%85%db%8c%d9%86%db%8c-%d8%a7%d9%86%d8%ac%d8%a7%d9%85-%d8%af%d9%87%db%8c%d8%af\"><img  loading=\"lazy\"  decoding=\"async\"  src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABAQMAAAAl21bKAAAAA1BMVEUAAP+KeNJXAAAAAXRSTlMAQObYZgAAAAlwSFlzAAAOxAAADsQBlSsOGwAAAApJREFUCNdjYAAAAAIAAeIhvDMAAAAASUVORK5CYII=\"  alt=\"\"  width=\"750\"  height=\"515\"  class=\"aligncenter wp-image-15297 size-full pk-lazyload\"  data-pk-sizes=\"auto\"  data-ls-sizes=\"auto, (max-width: 750px) 100vw, 750px\"  data-pk-src=\"https:\/\/cdn.itpiran.net\/2024\/04\/13231811\/14.webp\"  data-pk-srcset=\"https:\/\/cdn.itpiran.net\/2024\/04\/13231811\/14.webp 750w, https:\/\/cdn.itpiran.net\/2024\/04\/13231811\/14-300x206.webp 300w, https:\/\/cdn.itpiran.net\/2024\/04\/13231811\/14-110x76.webp 110w, https:\/\/cdn.itpiran.net\/2024\/04\/13231811\/14-200x137.webp 200w, https:\/\/cdn.itpiran.net\/2024\/04\/13231811\/14-380x261.webp 380w, https:\/\/cdn.itpiran.net\/2024\/04\/13231811\/14-255x175.webp 255w, https:\/\/cdn.itpiran.net\/2024\/04\/13231811\/14-550x378.webp 550w\" ><br \/>\n8.2. \u06cc\u06a9 \u067e\u0644\u0627\u0646 \u0632\u0645\u06cc\u0646\u06cc \u0627\u0646\u062c\u0627\u0645 \u062f\u0647\u06cc\u062f.<\/h5>\n<h5 id=\"8-3-%d8%a8%d8%b1%d8%a7%db%8c-%d8%a7%d8%b9%d9%85%d8%a7%d9%84-%d8%aa%d8%ba%db%8c%db%8c%d8%b1%d8%a7%d8%aa-%d8%a8%d9%87-aws%d8%8c-%db%8c%da%a9-terraform-application-%d8%a7%d9%86%d8%ac%d8%a7%d9%85-%d8%af\">8.3. \u0628\u0631\u0627\u06cc \u0627\u0639\u0645\u0627\u0644 \u062a\u063a\u06cc\u06cc\u0631\u0627\u062a \u0628\u0647 AWS\u060c \u06cc\u06a9 terraform application \u0627\u0646\u062c\u0627\u0645 \u062f\u0647\u06cc\u062f. \u067e\u0633 \u0627\u0632 \u0627\u0639\u0645\u0627\u0644\u060c \u062e\u0631\u0648\u062c\u06cc \u0634\u0645\u0627 \u0628\u0627\u06cc\u062f \u0634\u0628\u06cc\u0647 \u0645\u0648\u0627\u0631\u062f \u0632\u06cc\u0631 \u0628\u0627\u0634\u062f:<\/h5>\n<p><img  loading=\"lazy\"  decoding=\"async\"  src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABAQMAAAAl21bKAAAAA1BMVEUAAP+KeNJXAAAAAXRSTlMAQObYZgAAAAlwSFlzAAAOxAAADsQBlSsOGwAAAApJREFUCNdjYAAAAAIAAeIhvDMAAAAASUVORK5CYII=\"  alt=\"\"  width=\"750\"  height=\"59\"  class=\"aligncenter wp-image-15298 size-full pk-lazyload\"  data-pk-sizes=\"auto\"  data-ls-sizes=\"auto, (max-width: 750px) 100vw, 750px\"  data-pk-src=\"https:\/\/cdn.itpiran.net\/2024\/04\/13232023\/15.webp\"  data-pk-srcset=\"https:\/\/cdn.itpiran.net\/2024\/04\/13232023\/15.webp 750w, https:\/\/cdn.itpiran.net\/2024\/04\/13232023\/15-300x24.webp 300w, https:\/\/cdn.itpiran.net\/2024\/04\/13232023\/15-110x9.webp 110w, https:\/\/cdn.itpiran.net\/2024\/04\/13232023\/15-200x16.webp 200w, https:\/\/cdn.itpiran.net\/2024\/04\/13232023\/15-380x30.webp 380w, https:\/\/cdn.itpiran.net\/2024\/04\/13232023\/15-255x20.webp 255w, https:\/\/cdn.itpiran.net\/2024\/04\/13232023\/15-550x43.webp 550w\" ><br \/>\n\u062f\u0631 \u0627\u06cc\u0646 \u0628\u062e\u0634 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc Terraform \u0631\u0627 \u062f\u0631 \u062d\u0633\u0627\u0628 AWS \u062e\u0648\u062f \u0627\u0639\u0645\u0627\u0644 \u06a9\u0631\u062f\u06cc\u062f. \u062f\u0631 \u0627\u06cc\u0646 \u0645\u0631\u062d\u0644\u0647 \u0634\u0645\u0627 \u062f\u0648 \u0646\u0645\u0648\u0646\u0647 EC2 \u062f\u0627\u0631\u06cc\u062f \u06a9\u0647 \u0628\u0627 \u06cc\u06a9\u062f\u06cc\u06af\u0631 \u062f\u0631 \u0627\u0631\u062a\u0628\u0627\u0637 \u0647\u0633\u062a\u0646\u062f. One \u0645\u062e\u0631\u0628 \u0627\u0633\u062a \u0648 \u0622\u062f\u0631\u0633 IP \u0622\u0646 \u0628\u0647 \u0644\u06cc\u0633\u062a IP \u062a\u0647\u062f\u06cc\u062f \u0645\u0627 \u0627\u0636\u0627\u0641\u0647 \u0634\u062f\u0647 \u0627\u0633\u062a. \u0647\u0646\u06af\u0627\u0645\u06cc \u06a9\u0647 GuardDuty \u0645\u06cc \u0628\u06cc\u0646\u062f \u06a9\u0647 \u0627\u06cc\u0646 IP \u0628\u0627 \u0646\u0645\u0648\u0646\u0647 \u062f\u0631 \u0645\u0639\u0631\u0636 \u062e\u0637\u0631 \u0645\u0627 \u0635\u062d\u0628\u062a \u0645\u06cc \u06a9\u0646\u062f\u060c \u06cc\u0627\u0641\u062a\u0647 \u0627\u06cc \u0631\u0627 \u0627\u06cc\u062c\u0627\u062f \u0645\u06cc \u06a9\u0646\u062f. \u0645\u0627 \u06cc\u06a9 \u0642\u0627\u0646\u0648\u0646 EventBridge \u062f\u0627\u0631\u06cc\u0645 \u06a9\u0647 \u0628\u0627 \u0622\u0646 \u06cc\u0627\u0641\u062a\u0647 \u0645\u0637\u0627\u0628\u0642\u062a \u062f\u0627\u0631\u062f \u0648 \u062f\u0648 \u06a9\u0627\u0631 \u0631\u0627 \u0627\u0646\u062c\u0627\u0645 \u0645\u06cc \u062f\u0647\u062f: \u0627\u0648\u0644\u060c \u06cc\u06a9 \u0627\u06cc\u0645\u06cc\u0644 \u0628\u0631\u0627\u06cc \u0645\u0627 \u0627\u0631\u0633\u0627\u0644 \u0645\u06cc \u06a9\u0646\u062f \u06a9\u0647 \u0628\u0647 \u0645\u0627 \u0627\u0637\u0644\u0627\u0639 \u0645\u06cc \u062f\u0647\u062f \u06a9\u0647 \u0686\u0647 \u0627\u062a\u0641\u0627\u0642\u06cc \u0627\u0641\u062a\u0627\u062f\u0647 \u0627\u0633\u062a\u060c \u0648 \u062f\u0648\u0645\u060c \u062a\u0627\u0628\u0639 Lambda \u0631\u0627 \u0641\u0631\u0627\u062e\u0648\u0627\u0646\u06cc \u0645\u06cc \u06a9\u0646\u062f \u062a\u0627 \u06af\u0631\u0648\u0647 \u0627\u0645\u0646\u06cc\u062a\u06cc \u0645\u06cc\u0632\u0628\u0627\u0646 \u062f\u0631 \u0645\u0639\u0631\u0636 \u062e\u0637\u0631 \u0631\u0627 \u062a\u063a\u06cc\u06cc\u0631 \u062f\u0647\u062f. \u062f\u0631 \u0628\u062e\u0634 \u0628\u0639\u062f\u06cc\u060c \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u0631\u0627 \u062f\u0631 \u06a9\u0646\u0633\u0648\u0644 AWS \u062e\u0648\u062f \u062a\u0623\u06cc\u06cc\u062f \u062e\u0648\u0627\u0647\u06cc\u0645 \u06a9\u0631\u062f.<\/p>\n<h2 id=\"%d9%85%d8%b1%d8%ad%d9%84%d9%87-9-%d8%b1%d8%a7%d9%87-%d8%ad%d9%84-%d8%b1%d8%a7-%d8%af%d8%b1-%da%a9%d9%86%d8%b3%d9%88%d9%84-%d9%85%d8%af%db%8c%d8%b1%db%8c%d8%aa-aws-%d8%aa%d8%a3%db%8c%db%8c%d8%af\">\u0645\u0631\u062d\u0644\u0647 9: \u0631\u0627\u0647 \u062d\u0644 \u0631\u0627 \u062f\u0631 \u06a9\u0646\u0633\u0648\u0644 \u0645\u062f\u06cc\u0631\u06cc\u062a AWS \u062a\u0623\u06cc\u06cc\u062f \u06a9\u0646\u06cc\u062f<\/h2>\n<p>\u062f\u0631 \u0627\u06cc\u0646 \u0628\u062e\u0634\u060c \u06a9\u0644 \u0631\u0627\u0647\u200c\u062d\u0644 \u0645\u0648\u062c\u0648\u062f \u062f\u0631 \u06a9\u0646\u0633\u0648\u0644 AWS \u0631\u0627 \u0628\u0631\u0631\u0633\u06cc \u0645\u06cc\u200c\u06a9\u0646\u06cc\u0645 \u0648 \u0628\u0631\u0631\u0633\u06cc \u0645\u06cc\u200c\u06a9\u0646\u06cc\u0645 \u06a9\u0647 \u0648\u0642\u062a\u06cc \u06cc\u0627\u0641\u062a\u0647\u200c\u0647\u0627 \u062f\u0631 GuardDuty \u0638\u0627\u0647\u0631 \u0634\u062f \u0648 EventBridge \u0639\u0645\u0644\u06a9\u0631\u062f Lambda \u0631\u0627 \u0641\u0639\u0627\u0644 \u06a9\u0631\u062f\u060c \u06af\u0631\u0648\u0647 \u0627\u0645\u0646\u06cc\u062a\u06cc \u0645\u0646\u062a\u0642\u0644 \u0634\u062f\u0647 \u0627\u0633\u062a.<\/p>\n<p>\u0647\u0645\u0686\u0646\u06cc\u0646 \u0628\u0627\u06cc\u062f \u06cc\u06a9 \u0627\u06cc\u0645\u06cc\u0644 \u0628\u0631\u0627\u06cc \u062a\u0627\u06cc\u06cc\u062f \u0627\u0634\u062a\u0631\u0627\u06a9 \u062e\u0648\u062f \u062f\u0631\u06cc\u0627\u0641\u062a \u06a9\u0631\u062f\u0647 \u0628\u0627\u0634\u06cc\u062f. \u0628\u0647 \u06cc\u0627\u062f \u062f\u0627\u0634\u062a\u0647 \u0628\u0627\u0634\u06cc\u062f \u06a9\u0647 \u0628\u0631\u0627\u06cc \u062f\u0631\u06cc\u0627\u0641\u062a \u0627\u0639\u0644\u0627\u0646 \u0647\u0627\u06cc\u06cc \u06a9\u0647 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u06a9\u0631\u062f\u0647 \u0627\u06cc\u062f \u0628\u0627\u06cc\u062f \u0645\u0634\u062a\u0631\u06a9 \u0634\u0648\u06cc\u062f.<\/p>\n<p><img  loading=\"lazy\"  decoding=\"async\"  src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABAQMAAAAl21bKAAAAA1BMVEUAAP+KeNJXAAAAAXRSTlMAQObYZgAAAAlwSFlzAAAOxAAADsQBlSsOGwAAAApJREFUCNdjYAAAAAIAAeIhvDMAAAAASUVORK5CYII=\"  alt=\"\"  width=\"750\"  height=\"239\"  class=\"aligncenter wp-image-15299 size-full pk-lazyload\"  data-pk-sizes=\"auto\"  data-ls-sizes=\"auto, (max-width: 750px) 100vw, 750px\"  data-pk-src=\"https:\/\/cdn.itpiran.net\/2024\/04\/13232158\/16.webp\"  data-pk-srcset=\"https:\/\/cdn.itpiran.net\/2024\/04\/13232158\/16.webp 750w, https:\/\/cdn.itpiran.net\/2024\/04\/13232158\/16-300x96.webp 300w, https:\/\/cdn.itpiran.net\/2024\/04\/13232158\/16-110x35.webp 110w, https:\/\/cdn.itpiran.net\/2024\/04\/13232158\/16-200x64.webp 200w, https:\/\/cdn.itpiran.net\/2024\/04\/13232158\/16-380x121.webp 380w, https:\/\/cdn.itpiran.net\/2024\/04\/13232158\/16-255x81.webp 255w, https:\/\/cdn.itpiran.net\/2024\/04\/13232158\/16-550x175.webp 550w\" ><br \/>\n\u067e\u0633 \u0627\u0632 \u0627\u0634\u062a\u0631\u0627\u06a9\u060c \u0628\u0647 \u06a9\u0646\u0633\u0648\u0644 \u0645\u062f\u06cc\u0631\u06cc\u062a AWS \u0628\u0631\u0648\u06cc\u062f \u062a\u0627 \u0628\u0631\u0631\u0633\u06cc \u06a9\u0646\u06cc\u062f \u06a9\u0647 \u062f\u0648 \u0646\u0645\u0648\u0646\u0647 EC2 \u0648\u062c\u0648\u062f \u062f\u0627\u0631\u062f \u0648 \u0647\u0631 \u062f\u0648 \u062f\u0631 \u06af\u0631\u0648\u0647 \u0627\u0645\u0646\u06cc\u062a \u0627\u0648\u0644\u06cc\u0647 \u0647\u0633\u062a\u0646\u062f.<\/p>\n<p>\u0627\u0628\u062a\u062f\u0627 \u0647\u0627\u0633\u062a \u062f\u0631 \u0645\u0639\u0631\u0636 \u062e\u0637\u0631 \u0631\u0627 \u0628\u0631\u0631\u0633\u06cc \u06a9\u0646\u06cc\u062f.<\/p>\n<p><img  loading=\"lazy\"  decoding=\"async\"  src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABAQMAAAAl21bKAAAAA1BMVEUAAP+KeNJXAAAAAXRSTlMAQObYZgAAAAlwSFlzAAAOxAAADsQBlSsOGwAAAApJREFUCNdjYAAAAAIAAeIhvDMAAAAASUVORK5CYII=\"  alt=\"\"  width=\"750\"  height=\"364\"  class=\"aligncenter wp-image-15300 size-full pk-lazyload\"  data-pk-sizes=\"auto\"  data-ls-sizes=\"auto, (max-width: 750px) 100vw, 750px\"  data-pk-src=\"https:\/\/cdn.itpiran.net\/2024\/04\/13232406\/17.webp\"  data-pk-srcset=\"https:\/\/cdn.itpiran.net\/2024\/04\/13232406\/17.webp 750w, https:\/\/cdn.itpiran.net\/2024\/04\/13232406\/17-300x146.webp 300w, https:\/\/cdn.itpiran.net\/2024\/04\/13232406\/17-110x53.webp 110w, https:\/\/cdn.itpiran.net\/2024\/04\/13232406\/17-200x97.webp 200w, https:\/\/cdn.itpiran.net\/2024\/04\/13232406\/17-380x184.webp 380w, https:\/\/cdn.itpiran.net\/2024\/04\/13232406\/17-255x124.webp 255w, https:\/\/cdn.itpiran.net\/2024\/04\/13232406\/17-550x267.webp 550w\" ><br \/>\n\u0633\u067e\u0633 \u0647\u0627\u0633\u062a \u0645\u062e\u0631\u0628 \u0631\u0627 \u0628\u0631\u0631\u0633\u06cc \u06a9\u0646\u06cc\u062f.<\/p>\n<p><img  loading=\"lazy\"  decoding=\"async\"  src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABAQMAAAAl21bKAAAAA1BMVEUAAP+KeNJXAAAAAXRSTlMAQObYZgAAAAlwSFlzAAAOxAAADsQBlSsOGwAAAApJREFUCNdjYAAAAAIAAeIhvDMAAAAASUVORK5CYII=\"  alt=\"\"  width=\"750\"  height=\"364\"  class=\"aligncenter wp-image-15301 size-full pk-lazyload\"  data-pk-sizes=\"auto\"  data-ls-sizes=\"auto, (max-width: 750px) 100vw, 750px\"  data-pk-src=\"https:\/\/cdn.itpiran.net\/2024\/04\/13232454\/18.webp\"  data-pk-srcset=\"https:\/\/cdn.itpiran.net\/2024\/04\/13232454\/18.webp 750w, https:\/\/cdn.itpiran.net\/2024\/04\/13232454\/18-300x146.webp 300w, https:\/\/cdn.itpiran.net\/2024\/04\/13232454\/18-110x53.webp 110w, https:\/\/cdn.itpiran.net\/2024\/04\/13232454\/18-200x97.webp 200w, https:\/\/cdn.itpiran.net\/2024\/04\/13232454\/18-380x184.webp 380w, https:\/\/cdn.itpiran.net\/2024\/04\/13232454\/18-255x124.webp 255w, https:\/\/cdn.itpiran.net\/2024\/04\/13232454\/18-550x267.webp 550w\" ><br \/>\n\u0633\u067e\u0633 \u0627\u0637\u0645\u06cc\u0646\u0627\u0646 \u062d\u0627\u0635\u0644 \u06a9\u0646\u06cc\u062f \u06a9\u0647 GuardDuty \u06cc\u0627\u0641\u062a\u0647\u200c\u0647\u0627 \u0631\u0627 \u06af\u0632\u0627\u0631\u0634 \u0645\u06cc\u200c\u06a9\u0646\u062f.<\/p>\n<h5 id=\"%d8%a7%da%a9%d9%86%d9%88%d9%86-%d8%a8%d8%b1%d8%b1%d8%b3%db%8c-%da%a9%d9%86%db%8c%d8%af-%da%a9%d9%87-%d9%82%d8%a7%d9%86%d9%88%d9%86-eventbridge-%d8%a8%d9%87-%d8%af%d9%86%d8%a8%d8%a7%d9%84-%d8%a2%d9%86\"><img  loading=\"lazy\"  decoding=\"async\"  src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABAQMAAAAl21bKAAAAA1BMVEUAAP+KeNJXAAAAAXRSTlMAQObYZgAAAAlwSFlzAAAOxAAADsQBlSsOGwAAAApJREFUCNdjYAAAAAIAAeIhvDMAAAAASUVORK5CYII=\"  alt=\"\"  width=\"750\"  height=\"364\"  class=\"aligncenter wp-image-15302 size-full pk-lazyload\"  data-pk-sizes=\"auto\"  data-ls-sizes=\"auto, (max-width: 750px) 100vw, 750px\"  data-pk-src=\"https:\/\/cdn.itpiran.net\/2024\/04\/13232556\/19.webp\"  data-pk-srcset=\"https:\/\/cdn.itpiran.net\/2024\/04\/13232556\/19.webp 750w, https:\/\/cdn.itpiran.net\/2024\/04\/13232556\/19-300x146.webp 300w, https:\/\/cdn.itpiran.net\/2024\/04\/13232556\/19-110x53.webp 110w, https:\/\/cdn.itpiran.net\/2024\/04\/13232556\/19-200x97.webp 200w, https:\/\/cdn.itpiran.net\/2024\/04\/13232556\/19-380x184.webp 380w, https:\/\/cdn.itpiran.net\/2024\/04\/13232556\/19-255x124.webp 255w, https:\/\/cdn.itpiran.net\/2024\/04\/13232556\/19-550x267.webp 550w\" ><br \/>\n\u0627\u06a9\u0646\u0648\u0646 \u0628\u0631\u0631\u0633\u06cc \u06a9\u0646\u06cc\u062f \u06a9\u0647 \u0642\u0627\u0646\u0648\u0646 EventBridge \u0628\u0647 \u062f\u0646\u0628\u0627\u0644 \u0622\u0646 \u06cc\u0627\u0641\u062a\u0647 \u0627\u0633\u062a.<\/h5>\n<p><img  loading=\"lazy\"  decoding=\"async\"  src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABAQMAAAAl21bKAAAAA1BMVEUAAP+KeNJXAAAAAXRSTlMAQObYZgAAAAlwSFlzAAAOxAAADsQBlSsOGwAAAApJREFUCNdjYAAAAAIAAeIhvDMAAAAASUVORK5CYII=\"  alt=\"\"  width=\"750\"  height=\"364\"  class=\"aligncenter wp-image-15303 size-full pk-lazyload\"  data-pk-sizes=\"auto\"  data-ls-sizes=\"auto, (max-width: 750px) 100vw, 750px\"  data-pk-src=\"https:\/\/cdn.itpiran.net\/2024\/04\/13233106\/20.webp\"  data-pk-srcset=\"https:\/\/cdn.itpiran.net\/2024\/04\/13233106\/20.webp 750w, https:\/\/cdn.itpiran.net\/2024\/04\/13233106\/20-300x146.webp 300w, https:\/\/cdn.itpiran.net\/2024\/04\/13233106\/20-110x53.webp 110w, https:\/\/cdn.itpiran.net\/2024\/04\/13233106\/20-200x97.webp 200w, https:\/\/cdn.itpiran.net\/2024\/04\/13233106\/20-380x184.webp 380w, https:\/\/cdn.itpiran.net\/2024\/04\/13233106\/20-255x124.webp 255w, https:\/\/cdn.itpiran.net\/2024\/04\/13233106\/20-550x267.webp 550w\" ><br \/>\n\u0633\u067e\u0633 \u0647\u062f\u0641 \u0642\u0627\u0646\u0648\u0646 EventBridge \u0631\u0627 \u0628\u0631\u0631\u0633\u06cc \u06a9\u0646\u06cc\u062f. \u0634\u0645\u0627 \u0628\u0627\u06cc\u062f \u06cc\u06a9 \u0647\u062f\u0641 SNS \u0648 \u06cc\u06a9 \u0647\u062f\u0641 Lambda \u0631\u0627 \u0628\u0628\u06cc\u0646\u06cc\u062f.<\/p>\n<p><img  loading=\"lazy\"  decoding=\"async\"  src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABAQMAAAAl21bKAAAAA1BMVEUAAP+KeNJXAAAAAXRSTlMAQObYZgAAAAlwSFlzAAAOxAAADsQBlSsOGwAAAApJREFUCNdjYAAAAAIAAeIhvDMAAAAASUVORK5CYII=\"  alt=\"\"  width=\"750\"  height=\"364\"  class=\"aligncenter wp-image-15304 size-full pk-lazyload\"  data-pk-sizes=\"auto\"  data-ls-sizes=\"auto, (max-width: 750px) 100vw, 750px\"  data-pk-src=\"https:\/\/cdn.itpiran.net\/2024\/04\/13233254\/21.webp\"  data-pk-srcset=\"https:\/\/cdn.itpiran.net\/2024\/04\/13233254\/21.webp 750w, https:\/\/cdn.itpiran.net\/2024\/04\/13233254\/21-300x146.webp 300w, https:\/\/cdn.itpiran.net\/2024\/04\/13233254\/21-110x53.webp 110w, https:\/\/cdn.itpiran.net\/2024\/04\/13233254\/21-200x97.webp 200w, https:\/\/cdn.itpiran.net\/2024\/04\/13233254\/21-380x184.webp 380w, https:\/\/cdn.itpiran.net\/2024\/04\/13233254\/21-255x124.webp 255w, https:\/\/cdn.itpiran.net\/2024\/04\/13233254\/21-550x267.webp 550w\" ><br \/>\n\u0642\u0627\u0646\u0648\u0646 SNS \u0631\u0627 \u0628\u0631\u0631\u0633\u06cc \u06a9\u0646\u06cc\u062f \u062a\u0627 \u0628\u0628\u06cc\u0646\u06cc\u062f \u0686\u0647 \u06a9\u0627\u0631\u06cc \u0627\u0646\u062c\u0627\u0645 \u0645\u06cc \u062f\u0647\u062f. \u0628\u0627\u06cc\u062f \u0628\u0647 \u0622\u062f\u0631\u0633\u06cc \u06a9\u0647 \u062a\u0639\u06cc\u06cc\u0646 \u06a9\u0631\u062f\u0647 \u0627\u06cc\u062f \u0627\u06cc\u0645\u06cc\u0644 \u0628\u0641\u0631\u0633\u062a\u06cc\u062f.<\/p>\n<p><img  loading=\"lazy\"  decoding=\"async\"  src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABAQMAAAAl21bKAAAAA1BMVEUAAP+KeNJXAAAAAXRSTlMAQObYZgAAAAlwSFlzAAAOxAAADsQBlSsOGwAAAApJREFUCNdjYAAAAAIAAeIhvDMAAAAASUVORK5CYII=\"  alt=\"\"  width=\"750\"  height=\"364\"  class=\"aligncenter wp-image-15305 size-full pk-lazyload\"  data-pk-sizes=\"auto\"  data-ls-sizes=\"auto, (max-width: 750px) 100vw, 750px\"  data-pk-src=\"https:\/\/cdn.itpiran.net\/2024\/04\/13233442\/22.webp\"  data-pk-srcset=\"https:\/\/cdn.itpiran.net\/2024\/04\/13233442\/22.webp 750w, https:\/\/cdn.itpiran.net\/2024\/04\/13233442\/22-300x146.webp 300w, https:\/\/cdn.itpiran.net\/2024\/04\/13233442\/22-110x53.webp 110w, https:\/\/cdn.itpiran.net\/2024\/04\/13233442\/22-200x97.webp 200w, https:\/\/cdn.itpiran.net\/2024\/04\/13233442\/22-380x184.webp 380w, https:\/\/cdn.itpiran.net\/2024\/04\/13233442\/22-255x124.webp 255w, https:\/\/cdn.itpiran.net\/2024\/04\/13233442\/22-550x267.webp 550w\" ><br \/>\n\u0633\u067e\u0633 \u0639\u0645\u0644\u06a9\u0631\u062f Lambda \u0631\u0627 \u0628\u0631\u0631\u0633\u06cc \u06a9\u0646\u06cc\u062f. \u0645\u06cc \u062a\u0648\u0627\u0646\u06cc\u062f \u0627\u0632 \u0642\u0627\u0646\u0648\u0646 EventBridge \u06cc\u0627 \u0628\u0627 \u067e\u06cc\u0645\u0627\u06cc\u0634 \u0645\u0633\u062a\u0642\u06cc\u0645 \u0628\u0647 \u0622\u0646\u062c\u0627 \u0628\u0631\u0648\u06cc\u062f.<\/p>\n<p><img  loading=\"lazy\"  decoding=\"async\"  src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABAQMAAAAl21bKAAAAA1BMVEUAAP+KeNJXAAAAAXRSTlMAQObYZgAAAAlwSFlzAAAOxAAADsQBlSsOGwAAAApJREFUCNdjYAAAAAIAAeIhvDMAAAAASUVORK5CYII=\"  alt=\"\"  width=\"750\"  height=\"364\"  class=\"aligncenter wp-image-15306 size-full pk-lazyload\"  data-pk-sizes=\"auto\"  data-ls-sizes=\"auto, (max-width: 750px) 100vw, 750px\"  data-pk-src=\"https:\/\/cdn.itpiran.net\/2024\/04\/13233538\/23.webp\"  data-pk-srcset=\"https:\/\/cdn.itpiran.net\/2024\/04\/13233538\/23.webp 750w, https:\/\/cdn.itpiran.net\/2024\/04\/13233538\/23-300x146.webp 300w, https:\/\/cdn.itpiran.net\/2024\/04\/13233538\/23-110x53.webp 110w, https:\/\/cdn.itpiran.net\/2024\/04\/13233538\/23-200x97.webp 200w, https:\/\/cdn.itpiran.net\/2024\/04\/13233538\/23-380x184.webp 380w, https:\/\/cdn.itpiran.net\/2024\/04\/13233538\/23-255x124.webp 255w, https:\/\/cdn.itpiran.net\/2024\/04\/13233538\/23-550x267.webp 550w\" ><br \/>\n\u062f\u0631 \u0646\u0647\u0627\u06cc\u062a \u0628\u0631\u0631\u0633\u06cc \u06a9\u0646\u06cc\u062f \u06a9\u0647 \u062a\u0627\u0628\u0639 Lambda \u0645\u06cc\u0632\u0628\u0627\u0646 \u062f\u0631 \u0645\u0639\u0631\u0636 \u062e\u0637\u0631 \u0631\u0627 \u0628\u0647 \u06cc\u06a9 \u06af\u0631\u0648\u0647 \u0627\u0645\u0646\u06cc\u062a\u06cc \u062c\u062f\u06cc\u062f \u0645\u0646\u062a\u0642\u0644 \u06a9\u0631\u062f\u0647 \u0627\u0633\u062a.<\/p>\n<p><img  loading=\"lazy\"  decoding=\"async\"  src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABAQMAAAAl21bKAAAAA1BMVEUAAP+KeNJXAAAAAXRSTlMAQObYZgAAAAlwSFlzAAAOxAAADsQBlSsOGwAAAApJREFUCNdjYAAAAAIAAeIhvDMAAAAASUVORK5CYII=\"  alt=\"\"  width=\"750\"  height=\"364\"  class=\"aligncenter wp-image-15307 size-full pk-lazyload\"  data-pk-sizes=\"auto\"  data-ls-sizes=\"auto, (max-width: 750px) 100vw, 750px\"  data-pk-src=\"https:\/\/cdn.itpiran.net\/2024\/04\/13233748\/24.webp\"  data-pk-srcset=\"https:\/\/cdn.itpiran.net\/2024\/04\/13233748\/24.webp 750w, https:\/\/cdn.itpiran.net\/2024\/04\/13233748\/24-300x146.webp 300w, https:\/\/cdn.itpiran.net\/2024\/04\/13233748\/24-110x53.webp 110w, https:\/\/cdn.itpiran.net\/2024\/04\/13233748\/24-200x97.webp 200w, https:\/\/cdn.itpiran.net\/2024\/04\/13233748\/24-380x184.webp 380w, https:\/\/cdn.itpiran.net\/2024\/04\/13233748\/24-255x124.webp 255w, https:\/\/cdn.itpiran.net\/2024\/04\/13233748\/24-550x267.webp 550w\" ><br \/>\n\u0628\u0633\u062a\u0647 \u0628\u0647 \u0645\u062f\u062a \u0632\u0645\u0627\u0646\u06cc \u06a9\u0647 \u0645\u0646\u062a\u0638\u0631 \u0628\u0648\u062f\u0647 \u0627\u06cc\u062f\u060c \u0627\u06af\u0631 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u0634\u0645\u0627 \u0628\u0627 \u0627\u0633\u06a9\u0631\u06cc\u0646 \u0634\u0627\u062a \u0647\u0627\u06cc \u0628\u0627\u0644\u0627 \u0645\u0637\u0627\u0628\u0642\u062a \u062f\u0627\u0634\u062a\u0647 \u0628\u0627\u0634\u062f\u060c \u06cc\u06a9 \u0631\u0627\u0647 \u062d\u0644 \u0627\u0645\u0646\u06cc\u062a\u06cc \u06a9\u0627\u0645\u0644 AWS \u0631\u0627 \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 Terraform \u0628\u0627 \u0645\u0648\u0641\u0642\u06cc\u062a \u0627\u06cc\u062c\u0627\u062f \u06a9\u0631\u062f\u0647 \u0627\u06cc\u062f.<\/p>\n","protected":false},"excerpt":{"rendered":"Introduction In this tutorial, you will learn how to configure an AWS security solution using Terraform. You will\u2026","protected":false},"author":1,"featured_media":15309,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"\u0646\u062d\u0648\u0647 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u067e\u0627\u0633\u062e \u062e\u0648\u062f\u06a9\u0627\u0631 \u062d\u0627\u062f\u062b\u0647 \u0628\u0631\u0627\u06cc \u06cc\u0627\u0641\u062a\u0647 \u0647\u0627\u06cc Amazon GuardDuty \u0628\u0627 Terraform","_yoast_wpseo_title":"","_yoast_wpseo_metadesc":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_focuskeywords":"","_yoast_wpseo_primary_category":"220","footnotes":""},"categories":[220,193],"tags":[219],"class_list":{"0":"post-15285","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-amazon","8":"category-tutorials","9":"tag-aws"},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>\u0646\u062d\u0648\u0647 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u067e\u0627\u0633\u062e \u062e\u0648\u062f\u06a9\u0627\u0631 \u062d\u0627\u062f\u062b\u0647 \u0628\u0631\u0627\u06cc \u06cc\u0627\u0641\u062a\u0647 \u0647\u0627\u06cc Amazon GuardDuty \u0628\u0627 Terraform - \u0628\u0644\u0627\u06af ITPiran<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.itpiran.net\/blog\/en\/amazon\/using-terraform-to-configure-automated-guardduty\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u0646\u062d\u0648\u0647 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u067e\u0627\u0633\u062e \u062e\u0648\u062f\u06a9\u0627\u0631 \u062d\u0627\u062f\u062b\u0647 \u0628\u0631\u0627\u06cc \u06cc\u0627\u0641\u062a\u0647 \u0647\u0627\u06cc Amazon GuardDuty \u0628\u0627 Terraform - \u0628\u0644\u0627\u06af ITPiran\" \/>\n<meta property=\"og:description\" content=\"\u0645\u0642\u062f\u0645\u0647 \u062f\u0631 \u0627\u06cc\u0646 \u0622\u0645\u0648\u0632\u0634\u060c \u0646\u062d\u0648\u0647 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u0631\u0627\u0647 \u062d\u0644 \u0627\u0645\u0646\u06cc\u062a\u06cc AWS \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 Terraform \u0631\u0627 \u062e\u0648\u0627\u0647\u06cc\u062f \u0622\u0645\u0648\u062e\u062a. \u0634\u0645\u0627&hellip;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.itpiran.net\/blog\/en\/amazon\/using-terraform-to-configure-automated-guardduty\/\" \/>\n<meta property=\"og:site_name\" content=\"\u0628\u0644\u0627\u06af ITPiran\" \/>\n<meta property=\"article:published_time\" content=\"2024-04-13T20:15:23+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.itpiran.net\/2024\/04\/13234429\/AWSjpg.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1793\" \/>\n\t<meta property=\"og:image:height\" content=\"1110\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/amazon\\\/using-terraform-to-configure-automated-guardduty\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/amazon\\\/using-terraform-to-configure-automated-guardduty\\\/\"},\"author\":{\"name\":\"admin\",\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/#\\\/schema\\\/person\\\/04ed27b919baca468a2273f8e4318f81\"},\"headline\":\"\u0646\u062d\u0648\u0647 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u067e\u0627\u0633\u062e \u062e\u0648\u062f\u06a9\u0627\u0631 \u062d\u0627\u062f\u062b\u0647 \u0628\u0631\u0627\u06cc \u06cc\u0627\u0641\u062a\u0647 \u0647\u0627\u06cc Amazon GuardDuty \u0628\u0627 Terraform\",\"datePublished\":\"2024-04-13T20:15:23+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/amazon\\\/using-terraform-to-configure-automated-guardduty\\\/\"},\"wordCount\":488,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/amazon\\\/using-terraform-to-configure-automated-guardduty\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.itpiran.net\\\/2024\\\/04\\\/13234429\\\/AWSjpg.jpg\",\"keywords\":[\"AWS\"],\"articleSection\":[\"\u0622\u0645\u0627\u0632\u0648\u0646\",\"\u0622\u0645\u0648\u0632\u0634\u06cc\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/amazon\\\/using-terraform-to-configure-automated-guardduty\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/amazon\\\/using-terraform-to-configure-automated-guardduty\\\/\",\"url\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/amazon\\\/using-terraform-to-configure-automated-guardduty\\\/\",\"name\":\"\u0646\u062d\u0648\u0647 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u067e\u0627\u0633\u062e \u062e\u0648\u062f\u06a9\u0627\u0631 \u062d\u0627\u062f\u062b\u0647 \u0628\u0631\u0627\u06cc \u06cc\u0627\u0641\u062a\u0647 \u0647\u0627\u06cc Amazon GuardDuty \u0628\u0627 Terraform - \u0628\u0644\u0627\u06af ITPiran\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/amazon\\\/using-terraform-to-configure-automated-guardduty\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/amazon\\\/using-terraform-to-configure-automated-guardduty\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.itpiran.net\\\/2024\\\/04\\\/13234429\\\/AWSjpg.jpg\",\"datePublished\":\"2024-04-13T20:15:23+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/amazon\\\/using-terraform-to-configure-automated-guardduty\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/amazon\\\/using-terraform-to-configure-automated-guardduty\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/amazon\\\/using-terraform-to-configure-automated-guardduty\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.itpiran.net\\\/2024\\\/04\\\/13234429\\\/AWSjpg.jpg\",\"contentUrl\":\"https:\\\/\\\/cdn.itpiran.net\\\/2024\\\/04\\\/13234429\\\/AWSjpg.jpg\",\"width\":1793,\"height\":1110},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/amazon\\\/using-terraform-to-configure-automated-guardduty\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\u0622\u0645\u0627\u0632\u0648\u0646\",\"item\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/category\\\/amazon\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"\u0646\u062d\u0648\u0647 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u067e\u0627\u0633\u062e \u062e\u0648\u062f\u06a9\u0627\u0631 \u062d\u0627\u062f\u062b\u0647 \u0628\u0631\u0627\u06cc \u06cc\u0627\u0641\u062a\u0647 \u0647\u0627\u06cc Amazon GuardDuty \u0628\u0627 Terraform\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/\",\"name\":\"\u0628\u0644\u0627\u06af ITPiran\",\"description\":\"\u0627\u062e\u0628\u0627\u0631 \u0648 \u0645\u0642\u0627\u0644\u0627\u062a \u062a\u062c\u0627\u0631\u062a \u067e\u0627\u06cc\u062f\u0627\u0631 \u0627\u06cc\u0631\u0627\u0646\u06cc\u0627\u0646\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/#organization\",\"name\":\"\u0628\u0644\u0627\u06af \u062a\u062c\u0627\u0631\u062a \u067e\u0627\u06cc\u062f\u0627\u0631 \u0627\u06cc\u0631\u0627\u0646\u06cc\u0627\u0646\",\"alternateName\":\"ITPIran Blog\",\"url\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/cdn.itpiran.net\\\/2023\\\/12\\\/27150508\\\/cropped-ITPIRAN-BLOG-LOGO-2.png\",\"contentUrl\":\"https:\\\/\\\/cdn.itpiran.net\\\/2023\\\/12\\\/27150508\\\/cropped-ITPIRAN-BLOG-LOGO-2.png\",\"width\":512,\"height\":512,\"caption\":\"\u0628\u0644\u0627\u06af \u062a\u062c\u0627\u0631\u062a \u067e\u0627\u06cc\u062f\u0627\u0631 \u0627\u06cc\u0631\u0627\u0646\u06cc\u0627\u0646\"},\"image\":{\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/#\\\/schema\\\/person\\\/04ed27b919baca468a2273f8e4318f81\",\"name\":\"admin\",\"url\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/en\\\/author\\\/admin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How to Configure Automated Incident Response for Amazon GuardDuty Findings with Terraform - ITPiran Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.itpiran.net\/blog\/en\/amazon\/using-terraform-to-configure-automated-guardduty\/","og_locale":"en_US","og_type":"article","og_title":"\u0646\u062d\u0648\u0647 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u067e\u0627\u0633\u062e \u062e\u0648\u062f\u06a9\u0627\u0631 \u062d\u0627\u062f\u062b\u0647 \u0628\u0631\u0627\u06cc \u06cc\u0627\u0641\u062a\u0647 \u0647\u0627\u06cc Amazon GuardDuty \u0628\u0627 Terraform - \u0628\u0644\u0627\u06af ITPiran","og_description":"\u0645\u0642\u062f\u0645\u0647 \u062f\u0631 \u0627\u06cc\u0646 \u0622\u0645\u0648\u0632\u0634\u060c \u0646\u062d\u0648\u0647 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u0631\u0627\u0647 \u062d\u0644 \u0627\u0645\u0646\u06cc\u062a\u06cc AWS \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 Terraform \u0631\u0627 \u062e\u0648\u0627\u0647\u06cc\u062f \u0622\u0645\u0648\u062e\u062a. \u0634\u0645\u0627&hellip;","og_url":"https:\/\/www.itpiran.net\/blog\/en\/amazon\/using-terraform-to-configure-automated-guardduty\/","og_site_name":"\u0628\u0644\u0627\u06af ITPiran","article_published_time":"2024-04-13T20:15:23+00:00","og_image":[{"width":1793,"height":1110,"url":"https:\/\/cdn.itpiran.net\/2024\/04\/13234429\/AWSjpg.jpg","type":"image\/jpeg"}],"author":"admin","twitter_card":"summary_large_image","twitter_misc":{"Written by":"admin","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.itpiran.net\/blog\/amazon\/using-terraform-to-configure-automated-guardduty\/#article","isPartOf":{"@id":"https:\/\/www.itpiran.net\/blog\/amazon\/using-terraform-to-configure-automated-guardduty\/"},"author":{"name":"admin","@id":"https:\/\/www.itpiran.net\/blog\/#\/schema\/person\/04ed27b919baca468a2273f8e4318f81"},"headline":"\u0646\u062d\u0648\u0647 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u067e\u0627\u0633\u062e \u062e\u0648\u062f\u06a9\u0627\u0631 \u062d\u0627\u062f\u062b\u0647 \u0628\u0631\u0627\u06cc \u06cc\u0627\u0641\u062a\u0647 \u0647\u0627\u06cc Amazon GuardDuty \u0628\u0627 Terraform","datePublished":"2024-04-13T20:15:23+00:00","mainEntityOfPage":{"@id":"https:\/\/www.itpiran.net\/blog\/amazon\/using-terraform-to-configure-automated-guardduty\/"},"wordCount":488,"commentCount":0,"publisher":{"@id":"https:\/\/www.itpiran.net\/blog\/#organization"},"image":{"@id":"https:\/\/www.itpiran.net\/blog\/amazon\/using-terraform-to-configure-automated-guardduty\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.itpiran.net\/2024\/04\/13234429\/AWSjpg.jpg","keywords":["AWS"],"articleSection":["\u0622\u0645\u0627\u0632\u0648\u0646","\u0622\u0645\u0648\u0632\u0634\u06cc"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.itpiran.net\/blog\/amazon\/using-terraform-to-configure-automated-guardduty\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.itpiran.net\/blog\/amazon\/using-terraform-to-configure-automated-guardduty\/","url":"https:\/\/www.itpiran.net\/blog\/amazon\/using-terraform-to-configure-automated-guardduty\/","name":"How to Configure Automated Incident Response for Amazon GuardDuty Findings with Terraform - ITPiran Blog","isPartOf":{"@id":"https:\/\/www.itpiran.net\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.itpiran.net\/blog\/amazon\/using-terraform-to-configure-automated-guardduty\/#primaryimage"},"image":{"@id":"https:\/\/www.itpiran.net\/blog\/amazon\/using-terraform-to-configure-automated-guardduty\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.itpiran.net\/2024\/04\/13234429\/AWSjpg.jpg","datePublished":"2024-04-13T20:15:23+00:00","breadcrumb":{"@id":"https:\/\/www.itpiran.net\/blog\/amazon\/using-terraform-to-configure-automated-guardduty\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.itpiran.net\/blog\/amazon\/using-terraform-to-configure-automated-guardduty\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.itpiran.net\/blog\/amazon\/using-terraform-to-configure-automated-guardduty\/#primaryimage","url":"https:\/\/cdn.itpiran.net\/2024\/04\/13234429\/AWSjpg.jpg","contentUrl":"https:\/\/cdn.itpiran.net\/2024\/04\/13234429\/AWSjpg.jpg","width":1793,"height":1110},{"@type":"BreadcrumbList","@id":"https:\/\/www.itpiran.net\/blog\/amazon\/using-terraform-to-configure-automated-guardduty\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.itpiran.net\/blog\/"},{"@type":"ListItem","position":2,"name":"\u0622\u0645\u0627\u0632\u0648\u0646","item":"https:\/\/www.itpiran.net\/blog\/category\/amazon\/"},{"@type":"ListItem","position":3,"name":"\u0646\u062d\u0648\u0647 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u067e\u0627\u0633\u062e \u062e\u0648\u062f\u06a9\u0627\u0631 \u062d\u0627\u062f\u062b\u0647 \u0628\u0631\u0627\u06cc \u06cc\u0627\u0641\u062a\u0647 \u0647\u0627\u06cc Amazon GuardDuty \u0628\u0627 Terraform"}]},{"@type":"WebSite","@id":"https:\/\/www.itpiran.net\/blog\/#website","url":"https:\/\/www.itpiran.net\/blog\/","name":"ITPiran Blog","description":"Iranian Sustainable Trade News and Articles","publisher":{"@id":"https:\/\/www.itpiran.net\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.itpiran.net\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.itpiran.net\/blog\/#organization","name":"Sustainable Iranian Business Blog","alternateName":"ITPIran Blog","url":"https:\/\/www.itpiran.net\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.itpiran.net\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/cdn.itpiran.net\/2023\/12\/27150508\/cropped-ITPIRAN-BLOG-LOGO-2.png","contentUrl":"https:\/\/cdn.itpiran.net\/2023\/12\/27150508\/cropped-ITPIRAN-BLOG-LOGO-2.png","width":512,"height":512,"caption":"\u0628\u0644\u0627\u06af \u062a\u062c\u0627\u0631\u062a \u067e\u0627\u06cc\u062f\u0627\u0631 \u0627\u06cc\u0631\u0627\u0646\u06cc\u0627\u0646"},"image":{"@id":"https:\/\/www.itpiran.net\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.itpiran.net\/blog\/#\/schema\/person\/04ed27b919baca468a2273f8e4318f81","name":"admin","url":"https:\/\/www.itpiran.net\/blog\/en\/author\/admin\/"}]}},"_links":{"self":[{"href":"https:\/\/www.itpiran.net\/blog\/en\/wp-json\/wp\/v2\/posts\/15285","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.itpiran.net\/blog\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.itpiran.net\/blog\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.itpiran.net\/blog\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.itpiran.net\/blog\/en\/wp-json\/wp\/v2\/comments?post=15285"}],"version-history":[{"count":1,"href":"https:\/\/www.itpiran.net\/blog\/en\/wp-json\/wp\/v2\/posts\/15285\/revisions"}],"predecessor-version":[{"id":15308,"href":"https:\/\/www.itpiran.net\/blog\/en\/wp-json\/wp\/v2\/posts\/15285\/revisions\/15308"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.itpiran.net\/blog\/en\/wp-json\/wp\/v2\/media\/15309"}],"wp:attachment":[{"href":"https:\/\/www.itpiran.net\/blog\/en\/wp-json\/wp\/v2\/media?parent=15285"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.itpiran.net\/blog\/en\/wp-json\/wp\/v2\/categories?post=15285"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.itpiran.net\/blog\/en\/wp-json\/wp\/v2\/tags?post=15285"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}