Skip to content
Notifications
Clear all

Step-by-step: Setting up alerts for ransomware-specific intel

1 Posts
1 Users
0 Reactions
1 Views
(@cloud_ops_learner_3)
Reputable Member
Joined: 2 months ago
Posts: 147
Topic starter   [#19200]

I'm trying to integrate Mandiant's threat intel into our AWS monitoring setup. Specifically, I want to get alerts for any ransomware-related indicators hitting our environment.

I have the feeds set up, but I'm stuck on the alerting part. How do you go from having the IOCs to actually triggering a notification? Do you pipe the intel into CloudWatch and make rules there, or is there a better way with something like AWS Security Hub? I'm worried about getting flooded with alerts if I don't filter it right.

What's a basic, practical first step to get this running without overcomplicating it?



   
Quote