SecOps Confidential
In this episode of SecOps Confidential, James Berthoty talks with Bleon Proko, cloud security researcher at Exaforce, about why cloud security operations are still tripping up teams that are otherwise solid at traditional SOC work. Bleon breaks down the structural gap between cloud security engineers focused on posture and SOC teams drowning in raw log sources they don't know what to do with. They get into which log sources matter most (including S3 data events and Bedrock logs that most people skip), how to approach basic detection building without getting buried in false positives, and how attackers tend to stay basic while defenders often miss things hiding in plain sight. Bleon also shares lessons from his own cloud research, including a real honeypot that caught a full threat actor team, and his framework for building detection coverage you can actually maintain.
5 episoder
Kommentarer
0Vær den første til at kommentere
Tilmeld dig nu og bliv en del af SecOps Confidential-fællesskabet!