5 pro tips for detecting in AWS
ID: 628c6f91-7487-5086-99e7-2f58ac7bdbf0
STIX ID: report--628c6f91-7487-5086-99e7-2f58ac7bdbf0
Feed Name: Expel Blog
Date Published: 2022-02-15
Date Updated: 2026-04-27
Author: Brandon Dossantos; Britton Manahan; Sam Lipton; Ian Cooper; Christopher Vantine
This blog-style post presents five practical AWS threat-detection recommendations: (1) make security part of organizational culture and involve leadership, (2) establish what constitutes “normal” in each environment before tuning detections, (3) use strategic automation to reduce alert fatigue and speed time-to-detect, (4) ensure comprehensive CloudTrail logging and map API activity to MITRE ATT&CK for context, and (5) reinforce basic controls such as IAM and container security to reduce misconfiguration risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
