May 2025 Summaries
3 posts from Stream.Security
Filter
Month:
Year:
Post Summaries
Back to Blog
Stream's Engineering Desk discusses the challenges and solutions related to fileless execution attacks, which bypass traditional security measures by executing directly in memory without leaving a disk footprint. These attacks are particularly stealthy and can evade detection from traditional tools like anti-virus and endpoint protection systems, as they rely on legitimate tools already present in the operating system. Stream.Security addresses these challenges using extended Berkeley Packet Filter (eBPF) technology to monitor system activities at the kernel level, capturing detailed event summaries in real time whenever fileless execution occurs. Their CloudTwin™ technology further enhances detection by analyzing behavioral patterns and identity correlations across cloud environments, allowing for immediate flagging of suspicious activities without relying on static malware signatures. This approach provides security teams with enriched forensic details and prioritization for rapid response, effectively closing the detection gaps left by traditional methods.
May 19, 2025
1,025 words in the original blog post.
Cloud environments present unique challenges for security operations due to their dynamic and complex nature, where assets can rapidly change and ownership is often fragmented across teams. This complexity necessitates real-time visibility to effectively detect, contain, and respond to threats, yet many security operations centers (SOCs) lack this capability, leading to delays in threat mitigation. Traditional security tools often fall short in the cloud, where alerts lack context, making investigations slow and containment difficult. Stream Security addresses these challenges with the CloudTwin, a digital twin model that provides a continuously updated, comprehensive view of the cloud environment, allowing SOCs to quickly assess, prioritize, and act on threats. By enhancing alerts with real-time cloud context and automating owner mapping, Stream Security enables security teams to streamline their response processes, reducing mean time to detect, contain, and respond (MTTD, MTTC, and MTTR) and ensuring that responses are precise and effective. This unified approach transforms scattered workflows into a seamless response, empowering SOCs to operate at the necessary speed to counter cloud threats.
May 13, 2025
1,001 words in the original blog post.
Reflecting on RSAC 2025, the author emphasizes the limitations of focusing solely on technical specifications and ROI, advocating instead for storytelling and metaphor as tools to inspire and engage audiences. The Stream Security team demonstrated this by creating a unique "SOC Museum" using socks as metaphors to explain cloud security challenges, which successfully captured attendees' imaginations and sparked meaningful conversations. The experience underscored the importance of connecting with innovation on a human level and the potential of creative storytelling to stand out in a crowded market. Looking ahead to RSAC 2026, the author suggests balancing creative engagement with practical measures like pre-scheduled meetings to maximize both tangible and intangible value.
May 07, 2025
666 words in the original blog post.