4 ms·
SANS has a slightly dated paper ([1]) about setting up this sort of thing that gives a flavor for how it can work. I think AWS's VPC Flow Logs are the foundati
by bbayles 10y ago
SANS has a slightly dated paper ([1]) about setting up this sort of thing that gives a flavor for how it can work.
I think AWS's VPC Flow Logs are the foundation for better tools (disclaimer, my company develops these tools - [2]). I hope Azure and others follow suit.
[1] https://www.sans.org/reading-room/whitepapers/cloud/security-onion-cloud-client-network-security-monitoring-cloud-34335 https://www.sans.org/reading-room/whitepapers/cloud/security...
[2] https://observable.net/blog/vpc-flow-logs-virtual-private-clouds-in-aws/ https://observable.net/blog/vpc-flow-logs-virtual-private-cl...
- spydum 10y agoIn fact Azure security center does quite a lot of threat and malicious traffic analysis. OMS is going to be rather interesting as it matures as well.