Skip to content
Notifications
Clear all

Breaking: New ransomware behavior detection - any real-world tests?

1 Posts
1 Users
0 Reactions
41 Views
(@cloud_infra_newbie)
Honorable Member
Joined: 6 months ago
Posts: 367
Topic starter   [#2951]

Hey everyone, I was reading about the new ransomware behavior detection in Cloud One. Sounds really promising on paper!

I'm just starting out with AWS security stuff. Has anyone actually tested this in a lab or real environment? I'm curious about:
- Does it play nice with other security tools already deployed?
- Any performance hit on workloads?
- How do you even set up the alerting? Is it just CloudWatch alarms?

I saw a snippet about needing certain IAM permissions. Is it something like this?

```json
{
"Effect": "Allow",
"Action": [
"cloudtrail:LookupEvents",
"guardduty:GetFindings"
],
"Resource": "*"
}
```

Would love to hear if it's caught anything for you, or if it's mostly quiet. Trying to learn what's useful vs. just marketing.



   
Quote