Notifications
Clear all
Topic starter
14/07/2026 3:29 pm
Hey everyone. We had a scary moment last week where we suspected a VM in our dev AWS account was acting weird. We're on a tight budget but security can't wait, so we're evaluating CloudGuard.
Can someone walk me through the actual steps to isolate a compromised instance? The marketing docs are high-level. I need the nitty-gritty:
* How fast can the automation actually kick in after an alert?
* Does it just change security groups, or is there more to the workflow?
* What's the real cost impact if this runs a few times a month? 😅
Looking for real-world workflow steps, not theory. We use Terraform for most of our infra, if that matters.