Darktrace launches fully automated cloud forensics
Briefly

Darktrace launches fully automated cloud forensics
"Darktrace introduces the industry's first fully automated cloud forensics solution. Forensic Acquisition & Investigation aims to reduce investigation times from days to minutes by collecting evidence immediately when threats are detected. A survey of 300 cloud security decision-makers shows that nearly 90 percent of organizations suffer damage before they can contain cloud incidents. Additionally, investigations in cloud environments take three to five days longer than those in on-premises environments."
"Cloud adoption has simply outpaced security operations, creating dangerous blind spots that attackers are all too happy to exploit. Traditional log-based alerts miss critical attacker behavior such as lateral movement or privilege escalation. New analysis from Darktrace's Cloudypot honeypots shows that attacks against cloud workloads are becoming increasingly aggressive. Attacks against tools such as Jupyter Notebooks often occur in sudden waves, with multiple attacks in a short period from a small group of persistent attackers."
"Darktrace's new Forensic Acquisition & Investigation is designed for the speed and complexity of modern cloud environments. It captures and analyzes host-level evidence, including disk, memory, and logs, at the exact moment a threat is detected. This even applies to short-lived assets such as containers or serverless workloads that often disappear before evidence can be collected. Investigations can be triggered by Darktrace itself or by detections from existing cloud security tools."
Cloud adoption has outpaced security operations, creating blind spots that enable attackers to exploit cloud workloads and tools like Jupyter Notebooks. Traditional log-based alerts miss key attacker behaviors such as lateral movement and privilege escalation, and a survey shows nearly 90 percent of organizations experience damage before containing cloud incidents. Investigations in cloud environments take three to five days longer than on-premises. Forensic Acquisition & Investigation captures disk, memory, and logs at the moment of detection, including for ephemeral containers and serverless workloads, collects evidence via cloud APIs, and reconstructs attacker behavior to accelerate root-cause analysis and response.
Read at Techzine Global
Unable to calculate read time
[
|
]