Notifications
Clear all
Mandiant Threat Intel Reviews
1
Posts
1
Users
0
Reactions
1
Views
Topic starter
21/07/2026 4:03 am
I'm trying to integrate Mandiant's threat intel into our AWS monitoring setup. Specifically, I want to get alerts for any ransomware-related indicators hitting our environment.
I have the feeds set up, but I'm stuck on the alerting part. How do you go from having the IOCs to actually triggering a notification? Do you pipe the intel into CloudWatch and make rules there, or is there a better way with something like AWS Security Hub? I'm worried about getting flooded with alerts if I don't filter it right.
What's a basic, practical first step to get this running without overcomplicating it?