惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

U
Unit 42
Vercel News
Vercel News
博客园 - 叶小钗
大猫的无限游戏
大猫的无限游戏
MyScale Blog
MyScale Blog
P
Proofpoint News Feed
量子位
Engineering at Meta
Engineering at Meta
B
Blog RSS Feed
博客园 - 【当耐特】
Recent Announcements
Recent Announcements
Google DeepMind News
Google DeepMind News
D
DataBreaches.Net
Stack Overflow Blog
Stack Overflow Blog
博客园 - 聂微东
小众软件
小众软件
Hugging Face - Blog
Hugging Face - Blog
人人都是产品经理
人人都是产品经理
IT之家
IT之家
T
The Blog of Author Tim Ferriss
Last Week in AI
Last Week in AI
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Jina AI
Jina AI
博客园 - 三生石上(FineUI控件)

Datadog | The Monitor blog

Introducing our open source AI-native SAST Instrument and monitor Boomi integration flows with OpenTelemetry and Datadog Not all index scans are equal: How we cut query latency by over 99% Platform engineering metrics: What to measure and what to ignore Integrate Recorded Future threat intelligence with Datadog Cloud SIEM CI/CD security: threat modeling using a MITRE-style threat matrix CI/CD security: How to secure your GitHub ecosystem Ingress NGINX is EOL: A practical guide for migrating to Kubernetes Gateway API Operating agentic AI with Amazon Bedrock AgentCore and Datadog LLM Observability: Lessons from NTT DATA Introducing the Datadog Code Security MCP Capture and analyze custom heatmaps in Session Replay Understand session replays faster with AI summaries and smart chapters Monitor ClickHouse query performance with Datadog Database Monitoring How we designed empathetic alert sounds for on-call engineers Search and act across Datadog to resolve issues faster with Bits Assistant Measure the business impact of every product change with Datadog Experiments Analyzing round trip query latency Configuring JavaScript caches for better performance Introducing Bits AI Dev Agent for Code Security Datadog achieves ISO 42001 certification for responsible AI Monitor Nutanix clusters, hosts, and VMs with Datadog Monitor Juniper Mist in Datadog A new Host Map for modern infrastructure Annotate traces to improve LLM quality with Datadog LLM Observability What’s new in Cloud SIEM: AI-powered investigations, enhanced threat intelligence, and scalable security operations Explore Kubernetes with native OpenTelemetry data Monitor Oracle Fusion Cloud Applications with Datadog Announcing the Datadog Terraform provider v4.0.0 Scaling Kubernetes workloads on custom metrics How to design cloud environments for AI-powered threat analysis
Monitor AWS IAM Access Analyzer findings with Datadog
2019-12-05 · via Datadog | The Monitor blog

As you monitor the health and performance of your infrastructure and applications, you also need to be able to identify potential threats to the security of those components. To help address this challenge, Datadog integrates with AWS Identity and Access Management (IAM) Access Analyzer. This integration provides critical visibility into the security of your IAM resources alongside all of your other AWS resources all within a single pane of glass.

AWS recently announced the release of a new analyzer with IAM Access Analyzer called unused access. Once the analyzer is enabled, this feature helps administrators and security teams identify unused permissions, passwords, IAM users and roles, and access keys. With Datadog’s IAM Access Analyzer integration, you can easily discover and review any unused access granted to IAM resources.

What is AWS IAM Access Analyzer?

AWS IAM Access Analyzer uses automated reasoning to analyze resource policies and determine whether any AWS resources (e.g., IAM roles, S3 buckets, KMS keys) can be accessed outside your account. If you use AWS and want to ensure your policies grant the proper permissions, IAM Access Analyzer can help you detect unintended access to supported AWS resources.

AWS IAM Access Analyzer automatically analyzes resource policies for S3 buckets, IAM roles, KMS keys, Lambda functions, Amazon Relational Database snapshots, SQS queues and other supported resource types in your environment, and then reports possible issues in the form of findings, allowing you to update your policies as needed. If you change any of your policies, AWS IAM Access Analyzer will continuously analyze those updates and generate new findings to keep pace with the rate of change across your dynamic infrastructure.

Configure AWS IAM Access Analyzer to forward findings to Datadog logs

Collect findings on unused access

Removing unused IAM access credentials such as access keys, usernames, and passwords is a critical security best practice that enables you to reduce the attack surface of your AWS resources. In a large organization, however, it’s common for employees to switch teams or find roles elsewhere, and it can be difficult to keep track of which credentials are no longer needed.

IAM Access Analyzer’s unused access feature enables you to discover and review unused access across your AWS accounts or AWS organization. You can view these findings through Datadog’s IAM Access Analyzer integration so you can easily discover any unused permissions, access keys, user passwords, and unused services and actions for active IAM users and roles. You can then remove unused credentials to strengthen your security posture and prevent unintended access events.

AWS IAM Access Analyzer findings delivered straight to your Datadog account

Datadog integrates with AWS IAM Access Analyzer through an AWS Lambda function to receive findings as CloudWatch Events (in JSON format). These findings are then forwarded to your Datadog account as logs. Once you’re aggregating all of these findings with Datadog, you can keep tabs on the state of your resource policies and get alerted about critical issues or misconfigurations (e.g., if any resources can be accessed from outside of your AWS account) and take quick actions to ensure compliance and reduce the blast radius of a security incident.

Enable alerts to notify you automatically when resource policies are misconfigured or not behaving as expected

Monitor and protect your AWS services with Datadog

If you already use Datadog to monitor the health and performance of AWS services like S3 and SQS, now you can correlate that data with AWS IAM Access Analyzer findings to ensure that you’ve properly configured access to those services. For instance, if an AWS IAM Access Analyzer finding indicates that a policy is not granting permissions to S3 buckets as expected, you can investigate by correlating the log with metrics on your S3 dashboard. If you see an unexpected uptick in requests to those resources, it could mean the security of your account has been compromised.

Correlate Access Analyzer findings with AWS resource metrics like S3 to troubleshoot effectively

Performance, health, and security all in one place

Our integration with AWS IAM Access Analyzer complements our existing support for Amazon GuardDuty, which forwards threat detection logs to Datadog to help you identify unauthorized activity. With Datadog Cloud SIEM and integrations with more than 1,000 other technologies, you can monitor your services and keep them protected.

For even greater visibility into potential identity and access management risks, Datadog has integrated Cloud Security Identity Risks with AWS IAM Access Analyzer. This integration will provide richer insights into your IAM posture and streamline your team’s journey toward the principle of least privilege.

If you’re already using Datadog, you can start monitoring the security of your infrastructure here. Otherwise, sign up for a 14-day free trial.