tracecat icon indicating copy to clipboard operation
tracecat copied to clipboard

Datadog Security Monitoring

Open topher-lo opened this issue 2 years ago • 0 comments

User Story: I want to build automated investigations given findings from Datadog security products.

Datadog's key security features can be grouped in the following:

  • CSPM findings
  • SIEM signals
  • SIEM signal state management
  • CSPM findings state management
  • SIEM detection rules
  • Suppressions for SIEM detections
  • Filters for SIEM detections

We will prioritize GET and UPDATE operations for alerts first.

API reference: https://docs.datadoghq.com/api/latest/security-monitoring/

TODOs

Note: this list is non-exhaustive. We are using this issue as the tracker for all Datadog integrations.

Use Cases

  • Run automated detection hardening with stratus-red-team and SIEM detections (LIST operation with date / account ID filter)
  • Automated threat intel to detections checker?

topher-lo avatar Apr 19 '24 09:04 topher-lo