TL;DR

['AWS introduces a serverless solution for tracking file changes across EC2 instances, using Systems Manager Inventory and Security Lake.']

What happened

['AWS released guidance on implementing a serverless file integrity monitoring system using AWS Systems Manager Inventory and Amazon Security Lake to detect unauthorized changes in EC2 environments.']

Why it matters for ops

['Operators need real-time alerts for security compliance and incident response, provided by the integration of AWS Systems Manager Inventory and Amazon Security Lake.']

Mitigation

  • Implement serverless FIM solution with AWS SSM and Security Lake
  • Monitor alerts for suspicious activity

Action items

  • Configure AWS Systems Manager Inventory to collect file metadata
  • Integrate Amazon Security Lake for real-time alerting

Detection IOCs

  • Unusual file access patterns
  • Unexpected changes in file attributes or permissions

Source link

https://aws.amazon.com/blogs/security/file-integrity-monitoring-with-aws-systems-manager-and-amazon-security-lake/