Workflow
AWS Security Hub
icon
Search documents
Cribl Supercharges Incident Response in Amazon Security Hub with Open Cybersecurity Schema Framework (OCSF) Support
Globenewswire· 2025-12-02 20:30
Core Insights - Cribl is a launch partner for the new AWS Security Hub, enhancing its capabilities for security operators to manage critical security issues at scale [1][3] - The integration allows for centralized viewing of AWS Security Hub events within Cribl Search, improving analysis and correlation of security incidents [2][3] - The enhanced capability leverages the Open Cybersecurity Schema Framework (OCSF) to standardize data interchange while incorporating AWS-specific resource details [3][6] Group 1: Integration Features - The integration enables security teams to query data stored in Cribl Lake and other object stores, facilitating quick correlation of past incidents with real-time events [3] - Cribl Stream's extension for AWS Security Hub allows for the normalization of findings from various services into a unified view, accelerating prioritization [6] - The OCSF standard enhances the integration by allowing for the conversion of third-party findings into a standardized format with AWS-specific context [6] Group 2: Operational Efficiency - The centralized view reduces the time spent switching between different tools, improving the efficiency of security investigations [2] - Cribl Copilot Editor utilizes AI to recommend optimal mappings to the OCSF standard, minimizing manual effort in writing and debugging pipelines [6] - The integration supports automated workflows, allowing for faster resolution of incidents through better data correlation [6] Group 3: Company Overview - Cribl provides vendor-agnostic solutions for analyzing, collecting, processing, and routing IT and security data, catering to the needs of Fortune 1000 companies globally [5] - The company’s product suite includes Cribl Stream, Cribl Edge, Cribl Search, and Cribl Lake, designed for telemetry volume and variety [5]
Varonis Announces Integration With AWS Security Hub
Globenewswire· 2025-12-02 19:42
Core Insights - Varonis Systems, Inc. has announced a new integration with AWS Security Hub to enhance security teams' capabilities in managing data security across AWS and the entire data estate [1][3] Group 1: Integration Benefits - The integration provides enhanced visibility, automated fixes, and proactive threat detection, allowing security teams to quickly identify and remediate data risks [2][3] - Varonis ingests prioritized findings from AWS Security Hub, adding context on data sensitivity, identity, and user behavior to deliver a unified view of risk [9] Group 2: Automated Remediation - Varonis expands its automated remediation capabilities for AWS, including blocking public access to AWS S3 buckets and resolving critical misconfigurations [5][9] - The combination of analysis from AWS Security Hub and automated remediation allows for quick fixes of misconfigurations and securing exposed data [9] Group 3: Data Security Approach - Varonis focuses on end-to-end data security, which includes data discovery and classification, posture and identity protection, and data-centric threat detection [9] - The company emphasizes protecting data first, rather than as a secondary concern, positioning itself differently from conventional cybersecurity firms [6][7]
SentinelOne Unveils New Innovations and Integrations with AWS to Accelerate Customers' AI Initiatives at AWS re:Invent 2025
Businesswire· 2025-12-02 16:01
Core Insights - SentinelOne announced new innovations and integrations with Amazon Web Services (AWS) to enhance AI initiatives and improve AI-powered security outcomes through data utilization [1] Group 1: Innovations and Integrations - The announcements were made at AWS re:Invent 2025, highlighting advanced integrations between SentinelOne's AI-native Singularity cybersecurity platform and AWS Security Hub [1] - Additional integrations were introduced with Amazon CloudWatch to further support security measures [1]