AWS Serverless Application
Dexfense ReviewedCloud-native application on AWS Lambda, API Gateway, Aurora/DynamoDB, S3 and CloudWatch with a GitOps CI/CD pipeline.
Overview
Covers a serverless-first application on AWS using Lambda for compute, API Gateway for HTTP routing, Aurora/RDS for relational data, DynamoDB for high-throughput NoSQL storage, S3 for object storage, Cognito for authentication and MFA, AWS WAF for web protection, CloudWatch and CloudTrail for observability and audit, and a CI/CD pipeline. All compute runs inside a VPC with network segmentation; IAM roles follow least privilege throughout.
Intended for
Cloud architects, DevSecOps teams and security engineers working with AWS serverless workloads.
Architecture Assumptions
This template assumes the following conditions. If your environment differs, use Remix to adapt the component selection.
- All compute is serverless; no persistent EC2 instances in the production path
- IAM roles and resource policies follow the principle of least privilege
- VPC isolates database and compute tiers; NAT Gateway controls outbound traffic
- CloudTrail is enabled across all AWS regions in the account
- Container images are scanned for CVEs before deployment to ECR
Out of Scope
- Multi-account AWS Organisation structure and SCPs are not modelled
- AWS Bedrock and AI/ML services are not included in this template
- Data residency and cross-region replication are not assessed
Architecture Components15 components selected
Cloud
AWS Infrastructure
Amazon Web Services infrastructure
Serverless
Serverless compute functions
Web & APIs
API Services
API endpoints for application integration
Containers
Containers
Containerized applications and services
Databases
SQL Databases
Relational databases holding structured data
NoSQL Databases
Non-relational databases for unstructured data
Storage
Cloud Storage
Cloud-based object or file storage
Backup Systems
Data backup and recovery systems
Auth & IAM
OAuth/OIDC
Open authorization and identity protocols
Multi-Factor Auth
Additional authentication verification layer
Network
WAF
Web Application Firewall
Load Balancers
Traffic distribution systems
DNS Services
Domain name resolution services
Monitoring
Logging Systems
Centralized log collection and management
DevOps
CI/CD Pipeline
Continuous Integration/Continuous Deployment pipeline
Security Preview
Based on this architecture's component selection
Indicative Risk Score
58/100
13 techniques identified
2 Critical · 3 High
Top Attack Techniques
- CriticalT1068Exploitation for Privilege Escalation
- CriticalT1486Data Encrypted for Impact
- HighT1190Exploit Public-Facing Application
- HighT1574Hijack Execution Flow
- HighT1072Software Deployment Tools
Top Recommended Controls
- 1Implement Web Application Firewall (WAF) and regular security testing
- 2Adopt container security best practices including least privilege access and network policies
- 3Implement comprehensive cloud security posture management
The full defense plan — mitigations, detection methods, NIST CSF 2.0 mapping and exportable report — is available when you use this architecture in the planner.
Remix copies the components so you can add or remove items before generating your assessment.
Dexfense does not scan your systems. This template identifies threats and controls relevant to this architecture. Product and version validation is still required.