Forum Discussion

santhoshmohd's avatar
santhoshmohd
Copper Contributor
May 02, 2022
Solved

Defender for Cloud and Integration of Amazon Web Service Connector in Sentinel

Since we have an option in Defender for Cloud to add AWS environment. If we added those AWS accounts and In Sentinel if we have enabled the Microsoft Defender for Cloud data connector, is that will collect all the required logs from AWS?
Or did we need to enable "Amazon Web Services S3 (Preview)" connector as well which includes the data types AWS Cloud Trail , VPC Flow Logs & AWS Guard Duty?

 

  • eduardmu's avatar
    eduardmu
    May 04, 2022

    santhoshmohd Yes... Now imagine that you want to activate the protection of these resources as well (AWS) ... Then you will have the EDR module and it will start reporting randsoware incidents as well in secitiy center (defender for Cloud) So you could see this incident too in Sentinel 

  • eduardmu's avatar
    eduardmu
    Copper Contributor
    The easiest way is that this conetor ingests data from AWS Security Hub which is the AWS CSPM. While sentinel's aws S3 brings alerts from user audits, incidents and network level traffic (VPC).
      • eduardmu's avatar
        eduardmu
        Copper Contributor

        santhoshmohd Yes... Now imagine that you want to activate the protection of these resources as well (AWS) ... Then you will have the EDR module and it will start reporting randsoware incidents as well in secitiy center (defender for Cloud) So you could see this incident too in Sentinel 

Resources