My Methodology to AWS Detection Engineering (Part 1: Object Selection)
A security blog for the Cybersecurity & Cloud Security community by a guy named Le Bron. But seriously, no relation. Welcome to the first installment of my new blog series discussing my methodology for threat detection engineering in AWS. This blog assumes you are familiar with Splunk Enterprise Security, its terminology, and/or similar SIEM functionality related to "Risk-Based Alerting" concepts. If not, you can read some reference docs here and here or if you prefer videos you can go here and here. Also, if you need a refresher on AWS CloudTrail userIdentity fields, see the official documentation here. To be clear, this is just what I have been doing, and it doesn't mean that it is prescriptive. While this approach may use Splunk at its core, the concepts apply to any SIEM that allows you to perform risk scoring or has the components to do so, such as creating indices, performing lookups, and using eval commands. That said, this concept is better stated to be "tailored event aggrega
My Methodology to AWS Detection Engineering (Part 1: Object Selection) Get link Facebook X Pinterest Email Other Apps - August 13, 2024 Introduction Welcome to the first installment of my new blog series discussing my methodology for threat detection engineering in AWS. This blog assumes you are familiar with Splunk Enterprise Security, its terminology, and/or similar SIEM functionality related to "Risk-Based Alerting" concepts. If not, you can read some reference docs here and here or if you prefer videos you can go here and here . Also, if you need a refresher on AWS CloudTrail userIdentity
Explore this link on the map →related reading
- Anomalies detected by the Microsoft Sentinel machine learning engine | Microsoft Learnlearn.microsoft.com
- Creating Cost-Effective, Scalable Detectionsrippling.com
- How AWS tracks the cloud’s biggest security threats and helps shut them down | AWS Security Blogaws.amazon.com
- Create custom detection rules in Microsoft Defender XDR - Microsoft Defender XDR | Microsoft Learnlearn.microsoft.com
- A guide to threat hunting and monitoring in Snowflake | Datadog Security Labssecuritylabs.datadoghq.com
- Risk-Based Alerting: The New Frontier for SIEM | Splunksplunk.com
- Want Better Cloud Security? Make Your Detections Multi-Dimensionalomeronsecurity.com
- Tuning YARA-L Rules in Chronicle SIEM | by Chris Martin (@thatsiemguy) | Mediummedium.com
- Best practices for creating custom detection rules with Datadog Cloud SIEM | Datadogdatadoghq.com
- iot_to_timestream | Rules | Message routing | IoT Core | us-east-1us-east-1.console.aws.amazon.com
- What is Detection Engineering and Why do I Need it?cyberseccafe.com
- Exposing and shutting down an inbox heist in actionredcanary.com