flâneur — a map of the web's best reading

My Methodology to AWS Detection Engineering (Part 1: Object Selection)

chesterlebron.blogspot.com · 1,852 words · saved by 1 readers

A security blog for the Cybersecurity & Cloud Security community by a guy named Le Bron. But seriously, no relation. Welcome to the first installment of my new blog series discussing my methodology for threat detection engineering in AWS. This blog assumes you are familiar with Splunk Enterprise Security, its terminology, and/or similar SIEM functionality related to "Risk-Based Alerting" concepts. If not, you can read some reference docs here and here or if you prefer videos you can go here and here. Also, if you need a refresher on AWS CloudTrail userIdentity fields, see the official documentation here. To be clear, this is just what I have been doing, and it doesn't mean that it is prescriptive. While this approach may use Splunk at its core, the concepts apply to any SIEM that allows you to perform risk scoring or has the components to do so, such as creating indices, performing lookups, and using eval commands. That said, this concept is better stated to be "tailored event aggrega

My Methodology to AWS Detection Engineering (Part 1: Object Selection) Get link Facebook X Pinterest Email Other Apps - August 13, 2024 Introduction Welcome to the first installment of my new blog series discussing my methodology for threat detection engineering in AWS. This blog assumes you are familiar with Splunk Enterprise Security, its terminology, and/or similar SIEM functionality related to "Risk-Based Alerting" concepts. If not, you can read some reference docs here and here or if you prefer videos you can go here and here . Also, if you need a refresher on AWS CloudTrail userIdentity

Explore this link on the map →

related reading