AWSHow-To & HardeningRetrospectives

VPC Egress Filtering Checklist

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from November 2020, written in 2026 with the benefit of hindsight.

Egress filtering is one of the most effective controls against data exfiltration and malware. Use this checklist to put it in place across AWS VPCs.

Visibility first

  • VPC Flow Logs enabled on all production VPCs.
  • DNS query logging enabled (Route 53 Resolver query logs).
  • A baseline of normal outbound destinations per application.

Architecture

  • Workloads have no direct internet gateway access unless required.
  • Outbound traffic routes through NAT and a firewall (AWS Network Firewall or a third-party appliance).
  • VPC endpoints are used for AWS services (S3, DynamoDB, Secrets Manager, etc.) to keep that traffic off the internet.

Policy

  • Default-deny for outbound traffic from sensitive workloads, with an allow list of domains and ports.
  • Managed threat intelligence rule groups enabled.
  • Route 53 Resolver DNS Firewall blocks known malicious domains.
  • Non-standard outbound ports blocked by default.

Exceptions

  • Each allow-list entry has an owner and justification.
  • Temporary exceptions expire.

Monitoring

  • Alerts for denied outbound connections from production workloads.
  • Alerts for DNS queries to newly registered or suspicious domains.
  • Firewall and DNS logs sent to the SIEM.

Special cases

  • Build and CI systems restricted to required package repositories.
  • AI agents and evaluation sandboxes restricted to specific endpoints, with no general internet access.
vpc egress filtering checklistAWS Network Firewall2020

More on this story