File integrity monitoring with AWS Systems Manager and Amazon Security Lake
ID: bcdd7de4-8a0c-5161-93e7-f05d4ed25f54
STIX ID: report--bcdd7de4-8a0c-5161-93e7-f05d4ed25f54
Feed Name: AWS Security Blog
This post provides a step-by-step guide to implement a serverless file integrity monitoring solution on AWS that collects file metadata with Systems Manager Inventory, stores versioned snapshots in S3, triggers a Lambda function via S3 Event Notifications to detect file changes, and publishes findings to Security Hub and Security Lake for analysis in Athena, QuickSight, and OpenSearch. It includes setup of IAM roles and permissions, environment variables, a sample Lambda function, event configuration, and a walkthrough to test detection by modifying a monitored file, plus guidance on querying and visualizing findings and cleaning up resources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
