Slide 7
Slide 7 text
Luckily, we have our CDR set up quite
well. (DataDog Cloud SIEM)
We can see the Cloudtrail stopped
event. This is a trigger for an
appropriate response.
One lesson though ! The MTTD was
roughly 6 minutes … can be
improved !
What if the CDR set up was broken ?
How do you know ? Happens all the
time -> misconfigured S3 bucket,
broken lambda forwarder …
@run2obtain