2.3 Network Telemetry: VPC Flow Logs & Route 53 Resolver Logs

Key Takeaways

  • VPC Flow Logs capture IP traffic across network interfaces, subnets, or VPCs with zero impact on network latency or compute instance throughput.

  • Custom VPC Flow Log formats enable forensic visibility by capturing extended fields including pkt-srcaddr, pkt-dstaddr, flow-direction, traffic-path, and tcp-flags.

  • VPC Flow Logs have critical capture exclusions: they do not record traffic to the Amazon DNS resolver (.2 IP), IMDS (169.254.169.254), DHCP, or Windows activation services.

  • Route 53 Resolver query logging records all DNS queries originating within VPCs, enabling detection of DNS tunneling, domain generation algorithms (DGAs), and C2 callback infrastructure.

  • CloudWatch Logs Insights queries provide real-time threat hunting syntax to identify port scans, rejected connection surges, and high-volume data exfiltration beaconing.

Last updated: September 2026

Foundations of Network Telemetry in AWS

Network telemetry forms the first line of defense in detecting unauthorized perimeter reconnaissance, lateral movement, data exfiltration, and command-and-control (C2) communication. In AWS, network traffic inspection relies primarily on two complementary telemetry streams:

  1. Amazon VPC Flow Logs: Captures IP traffic flow metadata for Elastic Network Interfaces (ENIs), subnets, and VPCs. The companion Transit Gateway Flow Logs feature records the same kind of metadata at the transit gateway, per attachment, which is where inter-VPC and hybrid (VPN or Direct Connect) traffic is visible in a hub-and-spoke network. Both publish to CloudWatch Logs, Amazon S3, or Amazon Data Firehose.
  2. Amazon Route 53 Resolver Query Logs: Captures internal DNS resolution queries submitted to the Amazon-provided DNS resolver (Route 53 Resolver or the VPC .2 address).

Both services operate out-of-band at the hypervisor layer. They introduce zero impact on network latency, packet throughput, or compute instance performance.


VPC Flow Logs Architecture & Capture Mechanics

VPC Flow Logs can be attached at three hierarchical levels:

  • Individual ENI: Captures traffic on a single virtual network card.
  • Subnet: Automatically captures traffic across all existing and future ENIs within the subnet.
  • VPC: Automatically captures traffic across all existing and future ENIs across all subnets in the VPC.

Aggregation Intervals & Destinations

  • Aggregation Window: Flow logs aggregate packets into connection records. The default aggregation interval is 10 minutes. For security monitoring and incident response, you should always configure a 1-minute aggregation interval to capture high-frequency bursts, port scans, and short-lived connections with lower detection latency.
  • Delivery Destinations:
    • Amazon CloudWatch Logs: Ideal for real-time metric filters, CloudWatch alarms, and interactive threat hunting via CloudWatch Logs Insights.
    • Amazon S3: Optimal for cost-effective, long-term archival, compliance evidence storage, and Athena/Security Lake analytics.
    • Amazon Data Firehose: Designed for streaming delivery to third-party real-time SIEMs and streaming analytics platforms.

Anatomy of Flow Log Fields: Default vs. Custom Formats

The default format includes 14 basic network fields. However, the default format is insufficient for advanced security forensics because it obscures packet paths and middlebox transformations. Security engineers must deploy custom format flow logs to capture advanced metadata.

Field NameTypeDescriptionForensic Importance
versionIntegerVPC Flow Log version.Identifies format versioning.
account-idStringAWS account ID of the ENI owner.Multi-account attribution.
interface-idStringENI identifier (e.g., eni-0123456789abcdef0).Pinpoints the exact affected resource.
srcaddr / dstaddrIPv4/IPv6Source and destination IP of the flow.For ENIs behind NAT or middleboxes, these reflect interface-local IPs.
srcport / dstportIntegerSource and destination port numbers.Identifies target application service or ephemeral egress port.
protocolIntegerIANA protocol number (e.g., 6=TCP, 17=UDP, 1=ICMP).Distinguishes transport protocol.
packets / bytesIntegerTotal packets and bytes transferred during the window.Identifies data volume and exfiltration magnitude.
actionStringACCEPT or REJECT.Indicates whether Security Groups or NACLs permitted or denied the traffic.
log-statusStringOK, NODATA, or SKIPDATA.SKIPDATA indicates internal AWS capacity limits dropped records.
pkt-srcaddrIPv4/IPv6Real packet source IP address.Critical: Reveals original client IP even after traversing a NAT gateway.
pkt-dstaddrIPv4/IPv6Real packet destination IP address.Critical: Reveals true target IP before middlebox translation.
flow-directionStringingress or egress.Distinguishes whether connection was initiated inbound or outbound.
traffic-pathIntegerPath taken by egress traffic (e.g., 1 = another resource in the same VPC, 2 = internet gateway or gateway VPC endpoint, 3 = virtual private gateway, 4 or 5 = intra- or inter-Region peering, 7 = gateway VPC endpoint, 8 = internet gateway).Exposes anomalous network routing and unauthorized path traversal.
tcp-flagsIntegerBitmask of TCP flags observed during the aggregation window.Detects SYN floods, port scans, and incomplete handshakes.

The pkt-* vs. srcaddr/dstaddr Distinction

At a middlebox such as a NAT gateway, srcaddr and dstaddr describe the network interface's view of each hop, while pkt-srcaddr and pkt-dstaddr preserve the original packet addresses. On the NAT gateway's network interface, the record for traffic arriving from a private instance shows srcaddr = the instance IP but dstaddr = the NAT gateway's own private IP; only pkt-dstaddr shows the real internet destination. The onward records show srcaddr = the NAT gateway's IP. Adding pkt-srcaddr and pkt-dstaddr to a custom format lets one record tie the internal instance IP to the external C2 address, so responders isolate the right host.

Decoding tcp-flags for Threat Hunting

The tcp-flags field represents a bitmask of TCP control bits:

  • 2 (SYN): Connection initiation.
  • 18 (SYN-ACK: 2 + 16): Response from open port.
  • 4 (RST): Connection refused / reset.
  • 1 (FIN): Normal connection teardown.
  • If a flow log shows action: REJECT and tcp-flags: 2 across hundreds of sequential ports, an external actor is actively conducting a TCP SYN port scan against the host.

Critical Blind Spots: What VPC Flow Logs DO NOT Capture

A critical objective on the AWS Security Specialty exam is knowing the operational limitations and blind spots of VPC Flow Logs. Flow logs do NOT record the following categories of traffic:

  1. Amazon Route 53 Resolver Queries: Traffic to the VPC DNS resolver (169.254.169.253 or the VPC network base address plus two, e.g., 10.0.0.2) is explicitly omitted from VPC Flow Logs.
  2. Instance Metadata Service (IMDS): Traffic to the link-local address 169.254.169.254 is not logged by VPC Flow Logs.
  3. Amazon Time Sync Service: Traffic to 169.254.169.123 is excluded.
  4. DHCP Traffic: Communications between instances and the Amazon VPC DHCP server are omitted.
  5. Windows License Activation: Traffic to AWS Windows licensing servers is not recorded.

Exam Trap: If an exam scenario describes an attacker performing DNS tunneling or exfiltrating data via DNS queries to the VPC .2 resolver, reviewing VPC Flow Logs will reveal nothing. You must enable Route 53 Resolver Query Logging to gain visibility into DNS traffic.


Route 53 Resolver Query Logging

Amazon Route 53 Resolver Query Logs record every DNS query initiated by resources within your VPCs (EC2 instances, Lambda functions in VPCs, ECS tasks, and EKS pods) directed to the Route 53 Resolver.

Query Log Attributes

Route 53 Resolver query logs are output in JSON format containing crucial threat hunting attributes:

  • query_timestamp: Exact timestamp of the DNS query.
  • query_name: The fully qualified domain name (FQDN) requested (e.g., malicious-c2.attacker-domain.com).
  • query_type: Resource record type requested (e.g., A, AAAA, TXT, CNAME).
  • rcode: DNS response code (NOERROR, NXDOMAIN, SERVFAIL, REFUSED).
  • answers: The DNS answer payload returned, including resolved IP addresses.
  • srcaddr: The private IP of the ENI that submitted the DNS query.
  • firewall_rule_action: When a Route 53 Resolver DNS Firewall rule with an alert or block action matched, the action applied (ALERT or BLOCK), alongside firewall_rule_group_id and firewall_domain_list_id.

Threat Hunting with DNS Telemetry

  1. Detecting DNS Tunneling: Attackers encapsulate stolen data (credit cards, credentials) into encoded subdomains (e.g., base64data.exfil.attacker.com) and issue DNS lookups. Query logs capture these queries, revealing unusually long subdomain strings, high entropy, and an excessive volume of TXT queries.
  2. Detecting Domain Generation Algorithms (DGAs): Malware infected hosts often query hundreds of algorithmically generated domain names daily seeking active C2 servers. Query logs reveal high volumes of consecutive NXDOMAIN (Non-Existent Domain) responses originating from a single internal IP.

Threat Hunting with CloudWatch Logs Insights

When flow logs and DNS query logs are streamed to CloudWatch Logs, CloudWatch Logs Insights provides an interactive, highly scalable query engine to hunt for threats.

Query 1: Hunting for Inbound Port Scans & Brute Force Reconnaissance

Identifies external IP addresses generating the highest volume of rejected connections:

fields @timestamp, srcAddr, dstPort, protocol
| filter action = "REJECT"
| stats count(*) as rejectCount by srcAddr, dstPort
| sort rejectCount desc
| limit 20

Query 2: Hunting for High-Volume Outbound Data Exfiltration

Aggregates outbound bytes transferred to non-RFC1918 public IP addresses to identify potential data exfiltration:

fields @timestamp, srcAddr, dstAddr, dstPort, bytes
| filter flowDirection = "egress" and action = "ACCEPT"
| filter not (isIpv4InSubnet(dstAddr, "10.0.0.0/8") or isIpv4InSubnet(dstAddr, "172.16.0.0/12") or isIpv4InSubnet(dstAddr, "192.168.0.0/16"))
| stats sum(bytes) as totalBytesSent by srcAddr, dstAddr, dstPort
| sort totalBytesSent desc
| limit 25

Query 3: Hunting for High-Volume NXDOMAIN Spikes in Route 53 Resolver Logs

Identifies internal hosts generating excessive NXDOMAIN errors indicative of DGA malware:

fields @timestamp, srcaddr, query_name, rcode
| filter rcode = "NXDOMAIN"
| stats count(*) as nxCount by srcaddr
| sort nxCount desc
| limit 15
Loading diagram...
VPC Network Telemetry Pipeline & Threat Hunting Flow
Test Your Knowledge

A production web application resides in a private subnet behind a NAT Gateway. Security analysts reviewing default VPC Flow Logs see outbound connections to a known malicious command-and-control IP, but the srcaddr field consistently shows the NAT Gateway's private IP. Which modification will allow analysts to identify the specific EC2 instance initiating the connection?

A

Enable VPC Traffic Mirroring on the NAT Gateway's elastic network interface and route the mirrored packets to an Amazon OpenSearch cluster.

B

Install the AWS Systems Manager Agent on all EC2 instances and query the network connection table using SSM Run Command.

C

Create a custom VPC Flow Log format that adds the pkt-srcaddr and pkt-dstaddr fields and apply it to the VPC, including the NAT gateway's network interface.

D

Attach an AWS Network Firewall to the subnet and configure stateful domain list filtering.

Test Your Knowledge

A financial services institution suspects that malware inside its VPC is exfiltrating sensitive data via DNS tunneling using queries directed to the VPC's Amazon-provided DNS server (10.0.0.2). Why did the security operations team find zero evidence of this activity in their VPC Flow Logs?

A

VPC Flow Logs explicitly exclude DNS traffic directed to the Amazon Route 53 Resolver (.2 address) at the hypervisor level.

B

The VPC Flow Log aggregation interval was set to 10 minutes rather than 1 minute, causing DNS UDP packets to be dropped.

C

The destination S3 bucket policy contained an invalid service principal that blocked DNS packet delivery.

D

Security Groups operate statefully and automatically redact DNS payload records from flow logs.

Test Your Knowledge

During an active incident investigation, an engineer needs to determine whether an EC2 instance is infected with malware that utilizes a Domain Generation Algorithm (DGA) to establish command-and-control communication. Which pattern in Route 53 Resolver Query Logs confirms this hypothesis?

A

A high volume of DNS queries resulting in NOERROR status codes with A record responses matching RFC1918 private IP addresses.

B

Periodic PTR record lookups against the AWS Instance Metadata Service link-local address (169.254.169.254).

C

A single high-bandwidth TCP connection over port 53 transferring multiple megabytes of data to an external DNS root server.

D

A large volume of queries for pseudo-random, high-entropy domain names originating from the instance and resulting in NXDOMAIN response codes.

Test Your Knowledge

A security engineer must identify unauthorized external entities conducting TCP port scans against internal EC2 instances. Flow logs are streaming to Amazon CloudWatch Logs. Which CloudWatch Logs Insights query logic accurately detects this threat?

A

Filter for action equals 'ACCEPT', calculate the sum of packets grouped by srcAddr, and filter for results where sum(packets) is less than 5.

B

Filter for action equals 'REJECT', group by srcAddr and dstPort, calculate count(*), sort in descending order, and limit the results.

C

Filter for protocol equals 17 (UDP), filter for flowDirection equals 'egress', and sort by dstPort ascending.

D

Filter for logStatus equals 'SKIPDATA', extract the interfaceId, and correlate with AWS CloudTrail DescribeInstances calls.

Sections you finish are checked off in the contents.