Hey everyone, I'm new to the security side of cloud and just started a trial with Mandiant Threat Intel (formerly from Google Cloud). Coming from a mainly AWS/Terraform background, I wanted to see how this fits into our toolchain.
First impressions are good on the feed itself - the intel seems detailed and the risk ratings are clear. But I'm struggling a bit with the practical "so what?" part. Like, I get an alert about a new technique, but how do I map that to my specific AWS environment? Is there a straightforward way to check if we're vulnerable, or is that all manual work? Also, the portal is a bit overwhelming 😅
Are there any good step-by-step guides for beginners on integrating this with something like a SIEM or even just setting up basic alerting? I saw the APIs but not sure where to start. Would love to hear how others are using this data in their actual workflows!