Company
Date Published
Author
Mallory Mooney
Word count
1750
Language
English
Hacker News points
None

Summary

Mallory Mooney discusses the importance of risk assessment in cloud environments and how it requires context beyond just monitoring activity. She identifies common categories of risky behavior, including anomalous user and admin activity, identity risks, and resource misconfigurations. To connect these behaviors to specific entities, she highlights the need for entity analytics, which correlates logs with users, service accounts, and roles. Datadog Cloud SIEM Risk Insights provides a comprehensive approach by aggregating security logs, analyzing patterns, and generating alerts based on predefined and custom rules. It also maps events to identities and resources, providing a better understanding of what the risky behavior is and how it should be prioritized. By leveraging these capabilities, organizations can identify and respond to potential threats in their cloud environments.