Professional Documents
Culture Documents
Capability in AWS
Sponsored by
Security Orchestration,
Automation and Response (SOAR)
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential
Efficient SOC creates a foundation for threat hunting
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential
Planning for the threat hunting journey
Sweet
Spot!
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential
Key data sources for threat hunting
{"Records": [{
"eventVersion": "1.0",
"userIdentity": {
AWS Sources
"type": "IAMUser",
"principalId": "EX_PRINCIPAL_ID",
"arn": "arn:aws:iam::123456789012:user/Alice",
AWS CloudTrail
"accountId": "123456789012",
"accessKeyId": "EXAMPLE_KEY_ID",
"userName": "Alice"
•
},
"eventTime": "2014-03-06T21:01:59Z", • Amazon CloudWatch Events
Amazon GuardDuty Findings
"eventSource": "ec2.amazonaws.com",
"eventName": "StopInstances",
"awsRegion": "us-east-2",
•
"sourceIPAddress": "205.251.233.176",
"userAgent": "ec2-api-tools 1.6.12.2", • Amazon VPC Flow Logs
Amazon Inspector Findings
"requestParameters": {
"instancesSet": {"items": [{"instanceId": "i-ebeaf9e2"}]},
"force": false
•
},
"responseElements": {"instancesSet": {"items": [{ • DNS Logs
"instanceId": "i-ebeaf9e2",
"currentState": {
"code": 64,
"name": "stopping"
},
"previousState": {
"code": 16,
"name": "running"
}
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential
Defining the three data domains
Reveal
Relationships
Clarify the
Situation
Tell a Complete
Story
Amazon
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential
The building blocks for a threat hunting program
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential
Creating your threat hunting strategy
Where
do I • Your strategy determines the quality of
start? your results.
What’s
my path • Don’t underestimate the importance
to of good planning!
improve?
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential
The Hunting Maturity Model
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential
Example strategy: Extract value from existing data
Advantages Disadvantages
• Data is already being collected • Your ability to ask questions may
be limited by the available data
• Someone is already familiar with
its contents • External forces have more
influence over your results
• You may already have some
idea of the key questions you • Don’t confuse “easy” with
want answered “effective”
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential
Hunting is a journey, not a destination
• Figure out where you already are on the road, then make a plan to get to the next level.
• There’s no rush! Feel free to get off the bus for a while and hop back on later.
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential
Enabling threat hunting through
security efficiency in AWS
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Integrations that increase security efficiency
AWS
AWSSecurity
Security Amazon
Hub CloudWatch
Hub
Amazon
Macie
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
How are AWS customers leveraging Sumo Logic?
Increase analyst
productivity
Enhance threat
detection through
context
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Optimize security configuration and detection
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Pokémon creates SOC efficiencies
By leveraging cloud-native Machine Data Analytics Service
Benefits:
• Saved hundreds of hours
across security team through
automation
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Pokémon further improves SOC efficiencies
By adopting Demisto’s SOAR Platform
Benefits:
• Provided scaling for cloud
environment
IOCs
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Why AWS Marketplace?
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
How can you get started?
Find Buy Deploy
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Acknowledgments
Thanks to our sponsor: