Cloud Security Podcast by Google

EP103 Security Incident Response and Public Cloud - Exploring with Mandiant


Listen Later

Guest:  

  • Nader Zaveri, Senior Manager of IR and Remediation at Mandiant, now part of Google Cloud

Topics:

  • Could we start with a story of a cloud incident response (IR) failure and where things went wrong? 
  • What should that team have done to get it right? 
  • Are there skills that matter more in cloud incidents than they do for on-prem incidents? Are there on-prem instincts that will lead incident responders astray in cloud?
  • What 3 things an IR team leader needs to do to prepare his team for IR in the cloud?
  • Are there on-premise tools that can stay on prem and not join us in the cloud?
  • What processes should we leave behind? Keep with us?
  • What logs and context should we prepare for cloud IR?  What access should we have behind “break glass”?
  • While doing IR, what things should we look at in the cloud logs (which logs, also?) to expedite the investigation?

Resources:

  • “How to Cloud IR or Why Attackers Become Cloud Native Faster?” (ep98)
  • “How to prepare for detection & response in the cloud” Google Cloud Next 2022 presentation
  • “Security Incident Response in the Cloud: A Few Ideas” blog
  • GCP Cloud Logging
  • “Security at Scale: Logging in AWS” paper
  • “AWS Security Incident Response Whitepaper” paper
...more
View all episodesView all episodes
Download on the App Store

Cloud Security Podcast by GoogleBy Anton Chuvakin

  • 4.8
  • 4.8
  • 4.8
  • 4.8
  • 4.8

4.8

38 ratings


More shows like Cloud Security Podcast by Google

View all
Risky Business by Patrick Gray

Risky Business

363 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

633 Listeners

The Cloudcast by Massive Studios

The Cloudcast

154 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

372 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,007 Listeners

AWS Podcast by Amazon Web Services

AWS Podcast

199 Listeners

Smashing Security by Graham Cluley & Carole Theriault

Smashing Security

314 Listeners

Click Here by Recorded Future News

Click Here

390 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

141 Listeners

Kubernetes Podcast from Google by Abdel Sghiouar, Kaslin Fields

Kubernetes Podcast from Google

182 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

189 Listeners

Hacking Humans by N2K Networks

Hacking Humans

312 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

75 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

120 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

33 Listeners