August 2025 Summaries
5 posts from Stream.Security
Filter
Month:
Year:
Post Summaries
Back to Blog
Snowflake, a popular cloud data warehouse platform, is increasingly targeted by attackers due to its central role in storing sensitive business and customer data. The 2024 Snowflake data breach highlighted the risks associated with inadequate access controls, where attackers exploited credentials stolen via malware to access accounts lacking multi-factor authentication (MFA), affecting major companies like AT&T and Neiman Marcus. In response, Snowflake has mandated MFA for user interactions, but further security measures are necessary. Stream has integrated Snowflake audit logs into its SaaS and cloud detection framework, offering a comprehensive detection approach that includes machine learning-based behavioral analysis, threat intelligence enrichment, and customizable detection rules to identify and mitigate suspicious activities in real time. This integration provides Security Operations (SecOps) teams with enhanced visibility and a unified view of potential threats across cloud services, aiming to protect Snowflake within the broader cloud ecosystem and improve response times to security incidents.
Aug 28, 2025
943 words in the original blog post.
The recent security conferences showcased innovative research, including the introduction of EntraGoat, an open-source project from Semperis designed to simulate real-world identity security vulnerabilities for educational purposes. EntraGoat is part of the GOAT project family, which was developed to help security professionals enhance their skills by providing environments with intentional vulnerabilities. The tool focuses on Microsoft Entra ID infrastructure, offering scenarios that simulate common attack vectors and misconfigurations. Stream.Security leverages EntraGoat to validate its detection capabilities, allowing for real-time identification of attacks. The platform also enhances threat investigations by consolidating related logs into comprehensive visual narratives, significantly reducing the time required for analysis and response. Stream.Security's AI Investigator further empowers analysts by summarizing attack storylines and offering response recommendations, thus streamlining the process of mitigating cloud-native threats. This integration of tools like EntraGoat into professional security workflows helps organizations improve their defenses against increasingly sophisticated cyber threats.
Aug 26, 2025
1,186 words in the original blog post.
Security teams face challenges managing conflicting signals in the cloud, leading to unnecessary escalations and missed threats. To address this, an integration has been developed between Fortinet FortiGate Next-Generation Firewalls (NGFW) and Stream.Security's Cloud Detection and Response (CDR) platform to connect perimeter activities with cloud events. This integration enables the FortiGate NGFWs to feed critical data into Stream's CloudTwin™ engine, creating a real-time model of the cloud environment and providing accurate visibility of resource accessibility. By incorporating firewall rules and routing data from Fortinet, Stream reduces false alarms, streamlines alert triage, and clarifies real attack paths. This unified approach allows security teams to focus on genuine threats, reduce alert fatigue, improve response times, and enhance patching workflows, ultimately helping Security Operations Center (SOC) and SecOps teams prioritize and respond to cloud-native threats more effectively.
Aug 21, 2025
590 words in the original blog post.
Stream's Model Context Protocol (MCP) is a new offering that allows users to interact with their CloudTwin using natural language, integrating these interactions into workflows and AI tools to improve security operations. While Large Language Models (LLMs) have limitations when processing raw logs due to a lack of contextual understanding, the CloudTwin offers real-time, structured, and context-rich data that enhances LLMs' ability to provide accurate insights. MCP simplifies security processes by enabling analysts to ask direct questions and receive precise, actionable answers quickly, bypassing the need for complex queries or data aggregation from multiple sources. This system translates questions into operations on the live CloudTwin model, facilitating faster and more efficient security investigations. Examples include identifying network access across cloud platforms, detecting recent configuration changes leading to vulnerabilities, and tracking unusual activities of IAM roles. By providing a real-time, comprehensive view of cloud environments, MCP empowers security teams to make informed decisions based on reliable and up-to-date information.
Aug 07, 2025
671 words in the original blog post.
Stream.Security introduces new SaaS-sourced threat detections designed to enhance visibility and security for SecOps teams by integrating SaaS platforms into their cloud security strategy. This approach addresses potential blind spots by unifying detection capabilities across both cloud environments and the SaaS services they depend on, providing a comprehensive view of security threats. By integrating with platforms like GitHub, GitLab, Okta, Salesforce, and Snowflake, Stream.Security offers real-time threat detection across identity providers, version control systems, and databases. The solution uses a detection-first methodology that includes behavioral baselines, AI-driven threat prioritization, and enriched threat intelligence to identify unusual patterns and potential security breaches. This holistic approach helps organizations detect and respond to threats that exploit the boundaries between cloud and SaaS services, thereby reducing gaps in security and enabling faster, more informed responses to potential attacks.
Aug 07, 2025
963 words in the original blog post.