Skip to content
Notifications
Clear all

Step-by-step: Setting up alerts for ransomware-specific intel

1 Posts
1 Users
0 Reactions
21 Views
(@cloud_ops_learner_3)
Honorable Member
Joined: 5 months ago
Posts: 479
Topic starter   [#19200]

I'm trying to integrate Mandiant's threat intel into our AWS monitoring setup. Specifically, I want to get alerts for any ransomware-related indicators hitting our environment.

I have the feeds set up, but I'm stuck on the alerting part. How do you go from having the IOCs to actually triggering a notification? Do you pipe the intel into CloudWatch and make rules there, or is there a better way with something like AWS Security Hub? I'm worried about getting flooded with alerts if I don't filter it right.

What's a basic, practical first step to get this running without overcomplicating it?



   
Quote