{"id":5455,"date":"2020-04-29T14:23:51","date_gmt":"2020-04-29T13:23:51","guid":{"rendered":"https:\/\/lcloud.pl\/?p=5455"},"modified":"2024-12-10T15:49:23","modified_gmt":"2024-12-10T14:49:23","slug":"security-investigatior-amazon-detective","status":"publish","type":"post","link":"https:\/\/lcloud.pl\/en\/security-investigatior-amazon-detective\/","title":{"rendered":"Security investigator &#8211; Amazon Detective"},"content":{"rendered":"<h4 style=\"text-align: justify;\"><strong><span style=\"font-size: 23px; color: #199ad8;\">Cybersecurity is one of the priorities in the age of the information society, where data is a value in itself. It is worth paying attention to properly designed security solutions. To be able to ensure compliance with the required standards and the highest quality of solutions, Amazon Web Services has prepared a number of services in the Security category: <a style=\"color: #199ad8;\" href=\"https:\/\/lcloud.pl\/ochrona-jednym-kliknieciem\/\">Amazon GuardDuty<\/a>, <a style=\"color: #199ad8;\" href=\"https:\/\/lcloud.pl\/aws-z-odsiecza-przy-zmianach-w-gdpr\/\">Amazon Macie<\/a> or <a style=\"color: #199ad8;\" href=\"https:\/\/lcloud.pl\/aws-security-hub\/\">AWS SecurityHub<\/a> (<a style=\"color: #199ad8;\" href=\"https:\/\/lcloud.pl\/wp-content\/uploads\/AWS-Security-Hub-Infografika-PL.pdf\">download the infographic<\/a>), which help provide the highest protection. In addition, the existing level of security at the customer can be extended with dedicated solutions of AWS partners. All these services and solutions enable the detection and elimination of security errors. However, when the cause lies deeper, Amazon Detective comes to the rescue.<\/span><\/strong><\/h4>\n<h6 style=\"text-align: justify;\"><span style=\"font-size: 22px;\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-5449\" src=\"https:\/\/lcloud.pl\/wp-content\/uploads\/detective-icon-150x150.png\" alt=\"\" width=\"116\" height=\"109\" srcset=\"https:\/\/lcloud.pl\/wp-content\/uploads\/detective-icon-300x283.png 300w, https:\/\/lcloud.pl\/wp-content\/uploads\/detective-icon-104x98.png 104w, https:\/\/lcloud.pl\/wp-content\/uploads\/detective-icon-143x135.png 143w, https:\/\/lcloud.pl\/wp-content\/uploads\/detective-icon-140x132.png 140w, https:\/\/lcloud.pl\/wp-content\/uploads\/detective-icon.png 326w\" sizes=\"auto, (max-width: 116px) 100vw, 116px\" \/><span style=\"color: #979797;\"><span style=\"color: #199ad8;\">Amazon Detective<\/span> is the latest security service from the AWS family. It uses machine learning, statistical analysis and graph theory, in combination with AWS resource log data to detect potentially dangerous activities and security issues. It allows clients to view summaries and analytical data related to events in AWS CloudTrail as well as VPC Flow Logs. For customers who have Amazon GuardDuty enabled, Amazon Detective also processes the results obtained from GuardDuty.<\/span><\/span><\/h6>\n<h6 style=\"text-align: justify;\"><span style=\"font-size: 22px; color: #979797;\">So how does the service work? Amazon Detective allows you to automate heavy operations related to the processing of large amounts of data from AWS logs, in order to determine the cause of the threat and its impact on security. It uses machine learning models to create graphical presentations of account behaviour and helps answer questions such as &#8220;is this a custom API call for this role?&#8221; or &#8220;is this increase in traffic expected for this instance?&#8221; There is no need to write new code, configure or customize your own queries.<\/span><\/h6>\n<p style=\"text-align: justify;\"><a href=\"https:\/\/lcloud.pl\/wp-content\/uploads\/how-amazon-detective-works-scheme.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-5447 size-full\" src=\"https:\/\/lcloud.pl\/wp-content\/uploads\/how-amazon-detective-works-scheme.png\" alt=\"\" width=\"1600\" height=\"622\" srcset=\"https:\/\/lcloud.pl\/wp-content\/uploads\/how-amazon-detective-works-scheme.png 1600w, https:\/\/lcloud.pl\/wp-content\/uploads\/how-amazon-detective-works-scheme-300x117.png 300w, https:\/\/lcloud.pl\/wp-content\/uploads\/how-amazon-detective-works-scheme-1024x398.png 1024w, https:\/\/lcloud.pl\/wp-content\/uploads\/how-amazon-detective-works-scheme-768x299.png 768w, https:\/\/lcloud.pl\/wp-content\/uploads\/how-amazon-detective-works-scheme-1536x597.png 1536w, https:\/\/lcloud.pl\/wp-content\/uploads\/how-amazon-detective-works-scheme-252x98.png 252w, https:\/\/lcloud.pl\/wp-content\/uploads\/how-amazon-detective-works-scheme-161x63.png 161w, https:\/\/lcloud.pl\/wp-content\/uploads\/how-amazon-detective-works-scheme-140x54.png 140w\" sizes=\"auto, (max-width: 1600px) 100vw, 1600px\" \/><\/a><\/p>\n<p style=\"text-align: justify;\"><span style=\"font-size: 18px;\"><span style=\"color: #199ad8;\">Source: <a style=\"color: #199ad8;\" href=\"https:\/\/aws.amazon.com\/detective\/\">https:\/\/aws.amazon.com\/detective\/<\/a><\/span><\/span><\/p>\n<h6 style=\"text-align: justify;\"><span style=\"font-size: 22px; color: #979797;\">The Amazon Detective service can be used in 3 cases:<\/span><\/h6>\n<ul style=\"text-align: justify;\">\n<li><span style=\"font-size: 22px;\"><span style=\"color: #199ad8;\"><strong>Triage security findings<\/strong><\/span> &#8211; a trio is usually the first step in an investigation process, necessary to decide if an incident is an actual or apparent threat. Thanks to the visualization provided by the Amazon Detective service, it is possible to determine the incident related IP addresses, resources and accounts of AWS as well as activities at the time when the event took place and determine whether it is really malicious activity or a false alarm.<\/span><\/li>\n<li><span style=\"font-size: 22px;\"><span style=\"color: #199ad8;\"><strong>Incident investigation<\/strong><\/span> &#8211; Amazon Detective allows conducting an investigation process, with in-depth analysis of malicious activity detected by services such as Amazon GuardDuty, along with determining its impact on security. The analysis consists of comparing archival activities with current ones and identifying unusual patterns to determine why the current action caused an alert.<\/span><\/li>\n<li><span style=\"font-size: 22px;\"><span style=\"color: #199ad8;\"><strong>Threat hunting<\/strong> <\/span>&#8211; this is a proactive analysis, which aims to locate hidden threats based on hypotheses and tips. The service provides explanations based on time analysis and the possibility of sinking to determine changes that have occurred in a given time period.<\/span><\/li>\n<\/ul>\n<h6 style=\"text-align: justify;\"><span style=\"font-size: 22px; color: #979797;\">The service is available in these AWS regions in Europe: Dublin, Frankfurt, London, Paris, Stockholm. Availability updates can be found in <span style=\"color: #199ad8;\"><a style=\"color: #199ad8;\" href=\"https:\/\/aws.amazon.com\/about-aws\/global-infrastructure\/regional-product-services\/\">this link<\/a>.<\/span><\/span><\/h6>\n<h6 style=\"text-align: justify;\"><span style=\"font-size: 22px; color: #979797;\">The costs of using the service are calculated on the basis of the amount of data used by AWS CloudTrail, VPC Flow Logs and results from Amazon GuardDuty. Below is a sample price list for the region in Ireland.<\/span><\/h6>\n<p style=\"text-align: justify;\"><a href=\"https:\/\/lcloud.pl\/wp-content\/uploads\/amazon-detective-ireland.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-5439 size-full\" src=\"https:\/\/lcloud.pl\/wp-content\/uploads\/amazon-detective-ireland.png\" alt=\"\" width=\"1189\" height=\"295\" srcset=\"https:\/\/lcloud.pl\/wp-content\/uploads\/amazon-detective-ireland.png 1189w, https:\/\/lcloud.pl\/wp-content\/uploads\/amazon-detective-ireland-300x74.png 300w, https:\/\/lcloud.pl\/wp-content\/uploads\/amazon-detective-ireland-1024x254.png 1024w, https:\/\/lcloud.pl\/wp-content\/uploads\/amazon-detective-ireland-768x191.png 768w, https:\/\/lcloud.pl\/wp-content\/uploads\/amazon-detective-ireland-312x77.png 312w, https:\/\/lcloud.pl\/wp-content\/uploads\/amazon-detective-ireland-161x40.png 161w, https:\/\/lcloud.pl\/wp-content\/uploads\/amazon-detective-ireland-140x35.png 140w\" sizes=\"auto, (max-width: 1189px) 100vw, 1189px\" \/><\/a><\/p>\n<h6 style=\"text-align: justify;\"><span style=\"font-size: 22px;\"><span style=\"color: #979797;\">The exact cost calculation method can be found<\/span><span style=\"color: #199ad8;\"> <a style=\"color: #199ad8;\" href=\"https:\/\/aws.amazon.com\/detective\/pricing\/\">here<\/a>.<\/span><\/span><\/h6>\n<h6 style=\"text-align: justify;\"><span style=\"font-size: 22px; color: #979797;\">The benefits of using Amazon Detective include, first and foremost, simplifying the investigation process and improving the detection of potential threats. It allows obtaining detailed data related to unwanted incidents (e.g. calling the API to log into the console &#8211; we get data such as information about the time, login attempt, geolocation) and analysis whether the given action is a threat. It gives continuous data update, combined with saving time. The service processes terabytes of event data records for IP traffic, AWS management operations, and malicious or unauthorized activity. When new data appears or changes &#8211; the model created in the service is updated, which allows you to limit the time it takes to manage it. Information from the analyzes is presented in the form of convenient visualizations that allow you to make accurate decisions and determine the answers to such questions as whether traffic on the instance is expected, or issues related to unsuccessful API calls for given roles. In addition, all analyzed data are stored up to a year back, and the service fee applies to the analyzed events.<\/span><\/h6>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity is one of the priorities in the age of the information society, where data is a value in itself. It is worth paying attention to properly designed security solutions. To be able to ensure compliance with the required standards and the highest quality of solutions, Amazon Web Services has prepared a number of services [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":9949,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[3],"tags":[30,37,35,34],"class_list":["post-5455","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-aws-en","tag-cloud","tag-cloud-computing","tag-security"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Security investigator - Amazon Detective | LCloud<\/title>\n<meta name=\"description\" content=\"Cybersecurity is one of the priorities in the age of the information society, where data is a value in itself. It is worth paying attention to properly...\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Security investigator - Amazon Detective | LCloud\" \/>\n<meta property=\"og:description\" content=\"Cybersecurity is one of the priorities in the age of the information society, where data is a value in itself. It is worth paying attention to properly designed safeguards.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/lcloud.pl\/en\/security-investigatior-amazon-detective\/\" \/>\n<meta property=\"og:site_name\" content=\"LCloud\" \/>\n<meta property=\"article:published_time\" content=\"2020-04-29T13:23:51+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-12-10T14:49:23+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/lcloud.pl\/wp-content\/uploads\/amazon-detective-mini.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"512\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"LCloud\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Security investigator - Amazon Detective | LCloud\" \/>\n<meta name=\"twitter:description\" content=\"Cybersecurity is one of the priorities in the age of the information society, where data is a value in itself. It is worth paying attention to properly designed safeguards.\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/lcloud.pl\/wp-content\/uploads\/amazon-detective-mini.png\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"LCloud\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/lcloud.pl\/en\/security-investigatior-amazon-detective\/\",\"url\":\"https:\/\/lcloud.pl\/en\/security-investigatior-amazon-detective\/\",\"name\":\"Security investigator - Amazon Detective | LCloud\",\"isPartOf\":{\"@id\":\"https:\/\/lcloud.pl\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/lcloud.pl\/en\/security-investigatior-amazon-detective\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/lcloud.pl\/en\/security-investigatior-amazon-detective\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/lcloud.pl\/wp-content\/uploads\/Sledczy-ds.-bezpieczenstwa-\u2013-Amazon-Detective.jpg\",\"datePublished\":\"2020-04-29T13:23:51+00:00\",\"dateModified\":\"2024-12-10T14:49:23+00:00\",\"author\":{\"@id\":\"https:\/\/lcloud.pl\/#\/schema\/person\/4e56c347d5a37e0bd0ae7d8353ac1b0a\"},\"description\":\"Cybersecurity is one of the priorities in the age of the information society, where data is a value in itself. It is worth paying attention to properly...\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/lcloud.pl\/en\/security-investigatior-amazon-detective\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/lcloud.pl\/en\/security-investigatior-amazon-detective\/#primaryimage\",\"url\":\"https:\/\/lcloud.pl\/wp-content\/uploads\/Sledczy-ds.-bezpieczenstwa-\u2013-Amazon-Detective.jpg\",\"contentUrl\":\"https:\/\/lcloud.pl\/wp-content\/uploads\/Sledczy-ds.-bezpieczenstwa-\u2013-Amazon-Detective.jpg\",\"width\":1440,\"height\":274,\"caption\":\"\u015aledczy ds. bezpiecze\u0144stwaa \u2013 Amazon Detective\"},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/lcloud.pl\/#website\",\"url\":\"https:\/\/lcloud.pl\/\",\"name\":\"LCloud\",\"description\":\"AWS Advanced Consulting Partner | APN Well-Architected Partner\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/lcloud.pl\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/lcloud.pl\/#\/schema\/person\/4e56c347d5a37e0bd0ae7d8353ac1b0a\",\"name\":\"LCloud\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/lcloud.pl\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/0d1d7540a45e57ac9534226adcc4ce4700cdb19ae67e134ae46e7f5d9fce93e8?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/0d1d7540a45e57ac9534226adcc4ce4700cdb19ae67e134ae46e7f5d9fce93e8?s=96&d=mm&r=g\",\"caption\":\"LCloud\"},\"url\":\"https:\/\/lcloud.pl\/en\/author\/wpdev\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Security investigator - Amazon Detective | LCloud","description":"Cybersecurity is one of the priorities in the age of the information society, where data is a value in itself. It is worth paying attention to properly...","og_locale":"en_US","og_type":"article","og_title":"Security investigator - Amazon Detective | LCloud","og_description":"Cybersecurity is one of the priorities in the age of the information society, where data is a value in itself. It is worth paying attention to properly designed safeguards.","og_url":"https:\/\/lcloud.pl\/en\/security-investigatior-amazon-detective\/","og_site_name":"LCloud","article_published_time":"2020-04-29T13:23:51+00:00","article_modified_time":"2024-12-10T14:49:23+00:00","og_image":[{"width":1024,"height":512,"url":"https:\/\/lcloud.pl\/wp-content\/uploads\/amazon-detective-mini.png","type":"image\/png"}],"author":"LCloud","twitter_card":"summary_large_image","twitter_title":"Security investigator - Amazon Detective | LCloud","twitter_description":"Cybersecurity is one of the priorities in the age of the information society, where data is a value in itself. It is worth paying attention to properly designed safeguards.","twitter_image":"https:\/\/lcloud.pl\/wp-content\/uploads\/amazon-detective-mini.png","twitter_misc":{"Written by":"LCloud","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/lcloud.pl\/en\/security-investigatior-amazon-detective\/","url":"https:\/\/lcloud.pl\/en\/security-investigatior-amazon-detective\/","name":"Security investigator - Amazon Detective | LCloud","isPartOf":{"@id":"https:\/\/lcloud.pl\/#website"},"primaryImageOfPage":{"@id":"https:\/\/lcloud.pl\/en\/security-investigatior-amazon-detective\/#primaryimage"},"image":{"@id":"https:\/\/lcloud.pl\/en\/security-investigatior-amazon-detective\/#primaryimage"},"thumbnailUrl":"https:\/\/lcloud.pl\/wp-content\/uploads\/Sledczy-ds.-bezpieczenstwa-\u2013-Amazon-Detective.jpg","datePublished":"2020-04-29T13:23:51+00:00","dateModified":"2024-12-10T14:49:23+00:00","author":{"@id":"https:\/\/lcloud.pl\/#\/schema\/person\/4e56c347d5a37e0bd0ae7d8353ac1b0a"},"description":"Cybersecurity is one of the priorities in the age of the information society, where data is a value in itself. It is worth paying attention to properly...","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/lcloud.pl\/en\/security-investigatior-amazon-detective\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/lcloud.pl\/en\/security-investigatior-amazon-detective\/#primaryimage","url":"https:\/\/lcloud.pl\/wp-content\/uploads\/Sledczy-ds.-bezpieczenstwa-\u2013-Amazon-Detective.jpg","contentUrl":"https:\/\/lcloud.pl\/wp-content\/uploads\/Sledczy-ds.-bezpieczenstwa-\u2013-Amazon-Detective.jpg","width":1440,"height":274,"caption":"\u015aledczy ds. bezpiecze\u0144stwaa \u2013 Amazon Detective"},{"@type":"WebSite","@id":"https:\/\/lcloud.pl\/#website","url":"https:\/\/lcloud.pl\/","name":"LCloud","description":"AWS Advanced Consulting Partner | APN Well-Architected Partner","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/lcloud.pl\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/lcloud.pl\/#\/schema\/person\/4e56c347d5a37e0bd0ae7d8353ac1b0a","name":"LCloud","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/lcloud.pl\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/0d1d7540a45e57ac9534226adcc4ce4700cdb19ae67e134ae46e7f5d9fce93e8?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/0d1d7540a45e57ac9534226adcc4ce4700cdb19ae67e134ae46e7f5d9fce93e8?s=96&d=mm&r=g","caption":"LCloud"},"url":"https:\/\/lcloud.pl\/en\/author\/wpdev\/"}]}},"_links":{"self":[{"href":"https:\/\/lcloud.pl\/en\/wp-json\/wp\/v2\/posts\/5455","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lcloud.pl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lcloud.pl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lcloud.pl\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/lcloud.pl\/en\/wp-json\/wp\/v2\/comments?post=5455"}],"version-history":[{"count":5,"href":"https:\/\/lcloud.pl\/en\/wp-json\/wp\/v2\/posts\/5455\/revisions"}],"predecessor-version":[{"id":9953,"href":"https:\/\/lcloud.pl\/en\/wp-json\/wp\/v2\/posts\/5455\/revisions\/9953"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lcloud.pl\/en\/wp-json\/wp\/v2\/media\/9949"}],"wp:attachment":[{"href":"https:\/\/lcloud.pl\/en\/wp-json\/wp\/v2\/media?parent=5455"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lcloud.pl\/en\/wp-json\/wp\/v2\/categories?post=5455"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lcloud.pl\/en\/wp-json\/wp\/v2\/tags?post=5455"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}