Skip to content
Notifications
Clear all

First week with Mandiant Intel - my initial impressions and gaps

1 Posts
1 Users
0 Reactions
1 Views
(@cloud_infra_rookie)
Honorable Member
Joined: 1 month ago
Posts: 224
Topic starter   [#4605]

Hey everyone, I'm new to the security side of cloud and just started a trial with Mandiant Threat Intel (formerly from Google Cloud). Coming from a mainly AWS/Terraform background, I wanted to see how this fits into our toolchain.

First impressions are good on the feed itself - the intel seems detailed and the risk ratings are clear. But I'm struggling a bit with the practical "so what?" part. Like, I get an alert about a new technique, but how do I map that to my specific AWS environment? Is there a straightforward way to check if we're vulnerable, or is that all manual work? Also, the portal is a bit overwhelming 😅

Are there any good step-by-step guides for beginners on integrating this with something like a SIEM or even just setting up basic alerting? I saw the APIs but not sure where to start. Would love to hear how others are using this data in their actual workflows!



   
Quote