SANS ISC Internship Setup: AWS DShield Sensor + DShield SIEM [Guest Diary], (Tue, Nov 26th)
ID: 3bfd08d2-75f7-554f-9a7e-5ed44a32d1ba
STIX ID: report--3bfd08d2-75f7-554f-9a7e-5ed44a32d1ba
Feed Name: SANS ISC Diary
This guide provides a consolidated walkthrough for setting up a DShield Sensor on AWS and a local DShield SIEM (ELK on Ubuntu), then integrating them with Filebeat to collect and visualize logs. It covers required hardware, software, and accounts (ISC, AWS, OTX), step-by-step SIEM and sensor configuration, security group and port settings, troubleshooting and service validation, dashboard access, and post-deployment hardening (non-root users, updates, unattended upgrades, SSH lockdown, Fail2ban, and general Linux hardening tips).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
