Home / Companies / Datadog / Blog / Post Details
Content Deep Dive

Detect unauthorized third parties in your AWS account

Blog post from Datadog

Post Details
Company
Date Published
Author
Justin Massey, Jonathan Epstein
Word Count
642
Company Posts That Month
18
Language
English
Hacker News Points
-
Post removed?
No
Summary

In the context of AWS security, detecting unauthorized access to an account is crucial. This can occur when a third-party tool is granted access to monitor infrastructure or optimize bills, making it hard to track due to permission models. Datadog Cloud SIEM offers a solution by automatically detecting when a user assumes a role, allowing teams to investigate and take action before the threat propagates further. The platform analyzes log data over a chosen period to establish a baseline of expected behavior, generating Security Signals for anomalous activity. By setting up a term-based rule, teams can be alerted whenever an unfamiliar AWS account assumes a role in their environment, enabling swift investigation and response.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.