Company
Date Published
Author
Julie Agnes Sparks, Christopher Camacho
Word count
1331
Language
English
Hacker News points
None

Summary

Snowflake is a fully managed data platform that enables users to store, process, and analyze large volumes of data across their cloud environments. Datadog's Security Research Team has released an updated integration for Snowflake that converts many threat hunts into proactive detections, developed by detection engineers and tested by the internal security team. The new integration ingests additional data tables from Snowflake, making them available in Cloud SIEM, which provides out-of-the-box (OOTB) threat detections for Snowflake environments. These detections include Initial access, Persistence, Credential access, Defense evasion, Collection, Exfiltration, and signal correlation rules that combine multiple types of detections into a new rule. The team at Datadog has fine-tuned these detections using OOTB rule cloning, signal correlation rules, suppression rules, and workflows to adapt them for their environment. To get started with the new Snowflake detections in Cloud SIEM, users can configure log ingestion, review and customize detections, set up alerts and notifications, and monitor and refine their setup.