> ## Documentation Index
> Fetch the complete documentation index at: https://cloud-architect.ipoint-labs.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Discover sensitive data present in S3 bucket using Amazon Macie

> Hands-on lab · 45m

Launch this lab in the IP Lab Portal, then follow the steps below in the AWS console.

<a className="ip-lab-portal-btn" href="https://labs.intellectualpoint.com/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie" target="_blank" rel="noreferrer">
  Open IP Lab Portal
</a>

## Overview

### Lab details

1. This lab walks you through the steps to create and configure an Amazon Macie job to discover sensitive data.
2. You will practice using a custom data identifier where you will write a regular expression that matches the pattern of data present in the S3 bucket.
3. Duration: **60 minutes**
4. AWS Region: **US East (N. Virginia) us-east-1**

### Introduction

#### What is Amazon Macie ?

* Amazon Macie uses pattern matching and machine learning to protect the sensitive data stored in S3 buckets.
* It detects a list of data types including PII (Personally identifiable information) such as names, addresses, credit card numbers, etc.
* Along with detecting data, it gives you complete visibility of your S3 buckets and its information like publicly accessible buckets, unencrypted buckets, and buckets shared with other accounts.
* To get started with Amazon Macie, you can use its free trial of 30 days for bucket evaluation.
* The free trial does not include the discovery of sensitive data present in S3 buckets.

### Architecture diagram

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OagrkbHBQ8SYHp5M/images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/001.png?fit=max&auto=format&n=OagrkbHBQ8SYHp5M&q=85&s=33d8b474b25874b6615ae531a44d849e" alt="" width="860" height="520" data-path="images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/001.png" />

### Task details

1. Sign in to AWS Management Console.
2. Enable Macie for the account.
3. Create a Macie job.
4. Macie job run and findings.
5. Validation of the lab.

### Launching the lab environment

1. To launch the lab environment, Click on the **Launch lab** button.
2. Please wait until the cloud environment is provisioned. It will take less than a minute to provision.
3. Once the Lab is started, you will be provided with **IAM user name**, **Password**, **Access** **Key**, and **Secret** **Access** **Key**.

<Note>
  You can only start one lab at any given time
</Note>

## Lab guide

**Lab Steps**

#### Task 1: Sign in to AWS Management Console

1. Click on the **Open console** button, and you will get redirected to AWS Console in a new browser tab.
2. On the AWS sign-in page,

   * Leave the Account ID as default. Never edit/remove the 12 digit Account ID present in the AWS Console. otherwise, you cannot proceed with the lab.
   * Now copy your **User Name** and **Password** in the Lab Console to the **IAM Username and Password** in AWS Console and click on the **Sign in** button.
3. Once Signed In to the AWS Management Console, Make the default AWS Region as **US East (N. Virginia) us-east-1.**

#### Task 2: Enable Macie for the account

1. Make sure you are in the **US East (N. Virginia) us-east-1** Region.
2. Navigate to **Amazon Macie** by clicking on the **Services** menu in the top, then click on  **Amazon Macie** in the **Security, Identity & Compliance** section.
3. On the home page, click on the **Get started** button to configure Amazon Macie.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/OagrkbHBQ8SYHp5M/images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/002.png?fit=max&auto=format&n=OagrkbHBQ8SYHp5M&q=85&s=721293dcfbfdafe87b966717a16a10d0" alt="" width="1716" height="906" data-path="images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/002.png" />

On the Get started page, click on the **Enable Macie** button.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OagrkbHBQ8SYHp5M/images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/003.png?fit=max&auto=format&n=OagrkbHBQ8SYHp5M&q=85&s=543ab20852470b748f6205d693421270" alt="" width="940" height="319" data-path="images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/003.png" />

#### Task 3: Create a Macie job

1. Macie will try to find out all the details of the account, which may take some time. No need to wait, simply click on the **Create job** button.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/OagrkbHBQ8SYHp5M/images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/004.png?fit=max&auto=format&n=OagrkbHBQ8SYHp5M&q=85&s=57e8830c80206859244f534b0fdf1bf0" alt="" width="2386" height="1134" data-path="images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/004.png" />
2. For Step-1, Choose S3 Bucket,

<Note>
  If you are getting any error notification, leave it and continue the rest steps.
</Note>

* If you can not See the bucket, click on the **Add filter criteria** field and click on the **Bucket name**.
* Type ***whizlabs*** and select the bucket name starting with **whizlabs**, and click on the **Next** button

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OagrkbHBQ8SYHp5M/images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/005.png?fit=max&auto=format&n=OagrkbHBQ8SYHp5M&q=85&s=f17de70bbf6b4e3cff311bbbd4652e64" alt="" width="1988" height="1072" data-path="images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/005.png" />

> **NOTE** : If bucket is not listed, wait for 2–5 minutes and **refresh** the page 2–3 times.

3. Review S3 buckets Keep everything as default and click on the **Next** button.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OagrkbHBQ8SYHp5M/images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/006.png?fit=max&auto=format&n=OagrkbHBQ8SYHp5M&q=85&s=05d463232a1e3ea720d1fd65bc545dd2" alt="" width="1966" height="764" data-path="images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/006.png" />

4. For Step-3, Refine the scope,

* In Sensitive data discover options: Select **One-time job**
* Click on the arrow to expand the window of **Additional settings**
* **Let the Object criteria be default as File name extensions.**
* **Write** ***csv*** **in the textbox and click on the Include button.**
* **Once done, click on the Next button to proceed.**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OagrkbHBQ8SYHp5M/images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/007.png?fit=max&auto=format&n=OagrkbHBQ8SYHp5M&q=85&s=34fbe5528a3ffe9bb71220453e2b9ede" alt="" width="1856" height="1196" data-path="images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/007.png" />

5. For Step-4, Select managed data identifiers,

* Selection type: Choose **Recommended**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OagrkbHBQ8SYHp5M/images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/008.png?fit=max&auto=format&n=OagrkbHBQ8SYHp5M&q=85&s=e851ef27675e44b7f8f339e9458089a3" alt="" width="1844" height="1162" data-path="images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/008.png" />

* Click on the **Next** button.

6. For Step-5, Custom data identifiers,

* Click on the **Manage custom identifiers**, to create one.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OagrkbHBQ8SYHp5M/images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/009.png?fit=max&auto=format&n=OagrkbHBQ8SYHp5M&q=85&s=c060a9b6b12886e2a2e29f975e8a296f" alt="" width="2000" height="780" data-path="images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/009.png" />

<Note>
  This will open in a new tab. Enable pop-ups if it does not open on the first click.
</Note>

7. Click on the **Create** option present on the top right.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OagrkbHBQ8SYHp5M/images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/010.png?fit=max&auto=format&n=OagrkbHBQ8SYHp5M&q=85&s=6dd0bb5db64b160dc600d6216d1e392e" alt="" width="2022" height="636" data-path="images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/010.png" />

8. Fill in the details, as follows:

* Name: Enter **Whiz**
* Description: Enter **This identifier finds the data present in the format of AB-01 i.e. two characters, dash and followed by two numbers.**

Regular expression: Enter **\[a-z]\{2}-\[0-9]\{2}**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OagrkbHBQ8SYHp5M/images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/011.png?fit=max&auto=format&n=OagrkbHBQ8SYHp5M&q=85&s=5ce3ce439818a6182255c33e4b2928e1" alt="" width="940" height="519" data-path="images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/011.png" />

* Keep all other options as default.
* Click on the **Submit** button to create the **Custom identifier.**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OagrkbHBQ8SYHp5M/images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/012.png?fit=max&auto=format&n=OagrkbHBQ8SYHp5M&q=85&s=0850e9b8d2eef32b1a5c3b073b2e71a4" alt="" width="2034" height="542" data-path="images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/012.png" />

9. Go back to the **previous tab** and click on the **refresh** icon to see the newly created Custom identifier.

* Once refreshed, you will be able to see the Whiz identifier listed here. Click on the **Next** button.

  <img src="https://mintcdn.com/ip-cloud-architect-pathway/OagrkbHBQ8SYHp5M/images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/013.png?fit=max&auto=format&n=OagrkbHBQ8SYHp5M&q=85&s=22df0d41872313077c86b2d0dbcd4a3c" alt="" width="1962" height="730" data-path="images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/013.png" />

10. Select allow lists : Keep it default and click on **Next** button

11. In General Setting : Enter a name and description,

* Name: Enter ***WhizJob***
* Description: Enter **This job scans the bucket with a name starting as whizlabs and gathers its finding based on the regular expression pattern.**
* Click on the **Next** button.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OagrkbHBQ8SYHp5M/images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/014.png?fit=max&auto=format&n=OagrkbHBQ8SYHp5M&q=85&s=e76a61516d551102bc9d5ea58d227181" alt="" width="940" height="579" data-path="images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/014.png" />

12. For Step-8, Review and create,

13. Review everything, click on the **Submit** button present below. Job is now created successfully.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OagrkbHBQ8SYHp5M/images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/015.png?fit=max&auto=format&n=OagrkbHBQ8SYHp5M&q=85&s=566c57aa9ab86a43eb023adfd1332098" alt="" width="2284" height="888" data-path="images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/015.png" />

#### Task 4: Macie job run and findings

1. Once the job is created, it will start running immediately.
2. The job runs for approximately **10 minutes** and gathers the findings.
3. After **10 minutes**, the status is changed to Complete.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/OagrkbHBQ8SYHp5M/images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/016.png?fit=max&auto=format&n=OagrkbHBQ8SYHp5M&q=85&s=3e7324bb47dd07403744758d7ebff90b" alt="" width="1140" height="304" data-path="images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/016.png" />
4. To view the Findings for the job, perform the following:
5. Click on the **Job** present there.
6. Select **Show results**
7. And Choose **Show findings**

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/OagrkbHBQ8SYHp5M/images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/017.png?fit=max&auto=format&n=OagrkbHBQ8SYHp5M&q=85&s=25122046a60521fb25c010bb653d1201" alt="" width="940" height="355" data-path="images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/017.png" />
8. To check the exact results, open the finding.

   > **Note : If you can not see findings wait for more 2 minutes and refresh the page.**

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/OagrkbHBQ8SYHp5M/images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/018.png?fit=max&auto=format&n=OagrkbHBQ8SYHp5M&q=85&s=802e24a4f297eddd6a22d39fb351fbd1" alt="" width="2350" height="726" data-path="images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/018.png" />
9. Perform the following task:

   * **Select** the present finding
   * Click on the **Actions** button
   * And, Choose **Export (JSON)**

     <img src="https://mintcdn.com/ip-cloud-architect-pathway/OagrkbHBQ8SYHp5M/images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/019.png?fit=max&auto=format&n=OagrkbHBQ8SYHp5M&q=85&s=2dc720b62c22ce2fe779814971369038" alt="" width="940" height="261" data-path="images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/019.png" />
   * JSON present here is in Read-only format, you may choose to download the complete report.

     <img src="https://mintcdn.com/ip-cloud-architect-pathway/OagrkbHBQ8SYHp5M/images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/020.png?fit=max&auto=format&n=OagrkbHBQ8SYHp5M&q=85&s=236bc85e1eef660c9948bf2f12671e35" alt="" width="940" height="805" data-path="images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/020.png" />

<Tip>
  **Do you know?**

  Amazon Macie is an AWS service designed to enhance data security by automatically discovering, classifying, and protecting sensitive data in Amazon S3. It utilizes machine learning and natural language processing techniques to identify various types of sensitive information, such as personally identifiable information (PII), financial data, intellectual property, and more.
</Tip>

#### Task 5: Validation Test

1. Once the lab steps are completed, please click on the **Validate button** on the Right side panel.
2. This will validate the resources in the AWS account and displays whether you have completed this lab successfully or not.
3. Sample output :

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/OagrkbHBQ8SYHp5M/images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/021.gif?s=fe7679796489ff961308b5e5200c0011" alt="" width="999" height="592" data-path="images/labs/discover-sensitive-data-present-in-s3-bucket-using-amazon-macie/021.gif" />

### Completion and conclusion

1. You have successfully enabled Amazon Macie.
2. You have successfully created a Macie job.
3. You have successfully run the Macie job and retrieved the data.

### End lab

1. Sign out of AWS Account.
2. You have successfully completed the lab.
3. Once you have completed the steps, click on **End lab** in the IP Lab Portal and wait till the process gets completed.

## What gets checked

When you press **Check my work**, the platform verifies each of these:

* **Check Macie job findings** — Check whether Macie job findings are present or not
* **Create a Macie Classification job** — Check whether a Macie classification job is created or not
