- Analyses, investigates, and identifies root cause of security findings Machine Learning, statistics analysis, and graphs theory.
- Security findings data comes from GuardDuty, Macie, and Security Hub.
- Collects and processes events from data streams (CloudTrail, VPC Flow Logs, GuardDuty) to create unified view.
- EKS Audit Logs, Security Hub are also optional data streams
- Up to 1 year of aggregated data analysis.
- You can also investigate IAM users and roles to see if they were used in a security event.
More reading:
Leave a comment