Skip to content
Notifications
Clear all

Walkthrough: Correlating CloudTrail and VPC flow logs in Panther.

1 Posts
1 Users
0 Reactions
22 Views
(@jackd)
Estimable Member
Joined: 3 months ago
Posts: 102
Topic starter   [#12168]

Alright, let's cut through the usual "unified visibility" sales pitch. I've been testing Panther's correlation engine for a classic use case: tying VPC flow log rejects back to the CloudTrail API call that likely caused them. The promise is solid, but the implementation requires you to think like a platform engineer, not a security analyst.

Here's the core of it. You start with two separate Panther data sources: one ingesting CloudTrail to S3, another ingesting VPC flow logs. The correlation happens in a Python-based detection. You're not doing a simple JOIN; you're matching timestamps, source IPs, and destination IPs across two different schemas with a time window buffer because clocks are never perfectly synced.

```python
def rule(event):
# This is the VPC flow log event (reject)
if event.get('p_log_type') != 'AWS.VPCFlow':
return False
if event.get('action') != 'REJECT':
return False

# Look for a CloudTrail event from the same source IP within the last 60 seconds
src_addr = event.get('srcaddr')
flow_log_time = event.get('p_event_time')

filters = [
& PantherFilter('p_log_type', 'equals', 'AWS.CloudTrail'),
& PantherFilter('sourceIPAddress', 'equals', src_addr),
& PantherFilter('p_event_time', 'greater_than', flow_log_time - datetime.timedelta(seconds=60)),
& PantherFilter('p_event_time', 'less_than', flow_log_time)
]

matching_cloudtrail_events = pantherpy.get_matching_events(filters)

for ct_event in matching_cloudtrail_events:
# Check if the CloudTrail event was a SecurityGroup modification
if ct_event.get('eventName') in ['AuthorizeSecurityGroupIngress', 'AuthorizeSecurityGroupEgress']:
return True
return False
```

The real pitfall? Volume and cost. If you're running this detection in real-time across a large environment, those `pantherpy.get_matching_events` calls can get expensive. Panther bills on log volume processed *and* analyzed. You need to be surgical with your filters, and even then, the latency of the cross-table lookup can be noticeable. It works, but it's not magic. You're building and paying for a distributed query system.

Just my 2 cents


Just my 2 cents


   
Quote