Prevent data exfiltration: AWS egress controls for cloud workloads
Security Blog
This article presents a layered egress control architecture using AWS services to prevent unauthorized data exfiltration from cloud workloads and AI agents.
- Hub-and-spoke network pattern with Transit Gateway routes internet traffic through AWS Network Firewall for centralized inspection
- Route 53 Resolver DNS Firewall blocks DNS tunneling and unauthorized domain queries before connections establish
- Data perimeters using SCPs, RCPs, and VPC endpoint policies restrict API-level access to trusted resources within your organization
- GuardDuty detects behavioral anomalies and exfiltration attempts; IAM Access Analyzer identifies externally accessible resources
- Security Hub correlates findings across services; automated remediation via EventBridge and Lambda updates firewall rules in real time
- Phased implementation approach: Phase 1 enables DNS Firewall and GuardDuty; Phase 2 deploys data perimeters and Network Firewall; Phase 3 adds continuous monitoring and automation
Egress security requires layered preventive and detective controls applied equally to traditional workloads and AI agents to close outbound blind spots and prevent unauthorized data transfer.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
Jul 1
2026
2026
Secure Amazon container workloads using container attribute-based rules in AWS Network Firewall
May 21
2024
2024
Mitigating risks of data exfiltration with AWS AppFabric
Mar 17
2026
2026
Essential security controls to prevent unauthorized account removal in AWS Organizations
Sep 23
2025
2025
Minimize risk through defense in depth: Building a comprehensive AWS control framework
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.