Hey everyone, I was reading about the new ransomware behavior detection in Cloud One. Sounds really promising on paper!
I'm just starting out with AWS security stuff. Has anyone actually tested this in a lab or real environment? I'm curious about:
- Does it play nice with other security tools already deployed?
- Any performance hit on workloads?
- How do you even set up the alerting? Is it just CloudWatch alarms?
I saw a snippet about needing certain IAM permissions. Is it something like this?
```json
{
"Effect": "Allow",
"Action": [
"cloudtrail:LookupEvents",
"guardduty:GetFindings"
],
"Resource": "*"
}
```
Would love to hear if it's caught anything for you, or if it's mostly quiet. Trying to learn what's useful vs. just marketing.