Forum Discussion
santhoshmohd
May 02, 2022Copper Contributor
Defender for Cloud and Integration of Amazon Web Service Connector in Sentinel
Since we have an option in Defender for Cloud to add AWS environment. If we added those AWS accounts and In Sentinel if we have enabled the Microsoft Defender for Cloud data connector, is that will collect all the required logs from AWS?
Or did we need to enable "Amazon Web Services S3 (Preview)" connector as well which includes the data types AWS Cloud Trail , VPC Flow Logs & AWS Guard Duty?
santhoshmohd Yes... Now imagine that you want to activate the protection of these resources as well (AWS) ... Then you will have the EDR module and it will start reporting randsoware incidents as well in secitiy center (defender for Cloud) So you could see this incident too in Sentinel
- eduardmuCopper ContributorThe easiest way is that this conetor ingests data from AWS Security Hub which is the AWS CSPM. While sentinel's aws S3 brings alerts from user audits, incidents and network level traffic (VPC).
- santhoshmohdCopper ContributorThat means both can be used for 2 different purposes.
- eduardmuCopper Contributor
santhoshmohd Yes... Now imagine that you want to activate the protection of these resources as well (AWS) ... Then you will have the EDR module and it will start reporting randsoware incidents as well in secitiy center (defender for Cloud) So you could see this incident too in Sentinel