{"id":19690,"date":"2022-07-26T17:20:56","date_gmt":"2022-07-27T01:20:56","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2022\/07\/26\/news-13423\/"},"modified":"2022-07-26T17:20:56","modified_gmt":"2022-07-27T01:20:56","slug":"news-13423","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2022\/07\/26\/news-13423\/","title":{"rendered":"Sophos announces support for the new Amazon GuardDuty Malware Protection Service"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/07\/sophos-cns-news-blog-image-1200x628px@2x.png\"\/><\/p>\n<p><strong>Credit to Author: Anthony Merry| Date: Tue, 26 Jul 2022 22:15:52 +0000<\/strong><\/p>\n<div class=\"entry-content lg:prose-lg mx-auto prose max-w-4xl\">\n<p><span data-contrast=\"none\">Today Amazon Web Services (AWS) launched the new Amazon GuardDuty Malware Protection service, delivering agentless detection of malware on AWS workloads. <\/span><\/p>\n<p><span data-contrast=\"none\">As a global leader in next-generation cybersecurity, we&#8217;re excited to integrate these advancements into our <a href=\"https:\/\/news.sophos.com\/en-us\/2022\/07\/26\/introducing-sophos-cloud-native-security\/\" target=\"_blank\" rel=\"noopener\">newly announced Cloud Native Security offering<\/a> to help automate, simplify, and enhance the detection and response to the Amazon GuardDuty Malware Protection findings.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:320,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<h1>What is Amazon GuardDuty Malware Protection?<\/h1>\n<p><span data-contrast=\"none\">Amazon GuardDuty Malware Protection helps detect malicious files on Amazon EC2 instances and container workloads without requiring the use of security software or agents<\/span><span data-contrast=\"auto\">.\u00a0 S<\/span><span data-contrast=\"auto\">uspicious GuardDuty findings initiate GuardDuty Malware Protection scans of volume snapshots of Amazon EBS volumes attached to your Amazon EC2 instance and container workloads.\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">It offers the following benefits:<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:320,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<ul>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"4\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Protect all AWS workloads from malware with a single click: enable the GuardDuty Malware Protection feature in the GuardDuty console across all workloads<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"4\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"2\" data-aria-level=\"1\"><span data-contrast=\"auto\">Scale and simplify operations by removing requirements for malware scanning software and agents<\/span><\/li>\n<li data-leveltext=\"\uf0b7\" data-font=\"Symbol\" data-listid=\"4\" data-list-defn-props=\"{&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf0b7&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"3\" data-aria-level=\"1\"><span data-contrast=\"auto\">Receive more accurate and actionable information for detecting files containing malware<\/span><\/li>\n<\/ul>\n<h1>Add critical full-estate context with the new Sophos Cloud Native Security offering<\/h1>\n<p><span data-contrast=\"none\">While Amazon GuardDuty Malware Protection is a great way to add additional AWS security protection, it, and GuardDuty in general, can only tell a company\u2019s security team part of an overall story. <\/span><\/p>\n<p><span data-contrast=\"none\">Our new Cloud Native Security offering, which combines <\/span><span data-contrast=\"auto\">Intercept X for Server with XDR and Cloud Optix,<\/span> <span data-contrast=\"auto\">integrates Amazon GuardDuty\u202f<\/span><span data-contrast=\"none\">findings into a full organizational security posture view through the Sophos Central management console.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:320,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">Sophos Central provides a clear, prioritized view of<\/span><span data-contrast=\"auto\"> threats across your entire enterprise attack surface. <\/span><span data-contrast=\"none\">Amazon GuardDuty alerts are seamlessly integrated into this single view, as well as layering in information from numerous other AWS security services, such as Amazon Inspector, AWS CloudTrail and AWS Security Hub, IAM role anomaly detection, and workload protection agent visibility.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:320,&quot;335559739&quot;:320,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">\u201cEase of integration with our partner and customer\u2019s systems is the true test of great security,\u201d said Scott Barlow, Sophos vice president of global MSP and cloud alliances. \u201cThat\u2019s why we\u2019ve engineered <\/span><a href=\"http:\/\/sophos.com\/cloud\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">Sophos Cloud Native Security<\/span><\/a><span data-contrast=\"none\"> to integrate with Amazon Simple Notification Service, security information and event management (SIEM) solutions, widely used collaboration services, and more. Two-way integration with ticketing tools allows your teams to easily embed cloud security and compliance response into standard workflows by creating tickets from inside the Cloud Optix console for new incidents, including Amazon GuardDuty.\u201d<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:320,&quot;335559739&quot;:320,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">\u201cWe know how critical contextual data is when investigating and confidently responding to cloud security threat incidents,\u201d added Barlow.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:320,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<h1>Sophos enhances and extends Amazon GuardDuty capabilities<\/h1>\n<p><span data-contrast=\"none\">While full-estate context is critical to understanding an attack, added capabilities through Sophos makes IT security pros jobs easier and helps them sleep better at night. <\/span><\/p>\n<p><span data-contrast=\"none\">For example, the <\/span><span data-contrast=\"auto\">Cloud Native Security feature <\/span><a href=\"https:\/\/docs.sophos.com\/pcg\/optix\/help\/en-us\/MonitorAlerts\/ActivityInsights\/index.html\"><span data-contrast=\"none\">Activity Insights<\/span><\/a><span data-contrast=\"auto\">\u00a0enhances GuardDuty alert notification services by using AI to build out a timeline of events and assign a confidence score, saving security pros invaluable incident triage time.\u00a0 <\/span><\/p>\n<p><span data-contrast=\"auto\">Sophos Cloud Native Security will also soon be able to (currently in pre-release) scan files going into or leaving S3 (Amazon Simple Storage Service) for malware, as well as optionally scanning static files, enabling scans of both types of AWS\u2019 primary storage services.\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">Sophos Cloud Native Security also<\/span><span data-contrast=\"none\"> provides telemetry from Sophos workload protection agents to add further context to threats identified by Amazon GuardDuty. Security pros can then act confidently to mitigate a threat, reducing incident mean time to resolve (MTTR).<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:448,&quot;335559739&quot;:256,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<h1>Enable Sophos 24\/7 threat protection, monitoring, and response on AWS<\/h1>\n<p><span data-contrast=\"none\">\u201cAs an AWS Level 1 Managed Security Service Partner, we know that a proactive defense requires 24\/7 monitoring and response, but for a lot of IT teams, large and small, it\u2019s not realistic to keep a team monitoring security around the clock,\u201d added Barlow.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:320,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><a href=\"https:\/\/aws.amazon.com\/marketplace\/pp\/prodview-lf3bvvntwjlei?sr=0-14&amp;ref_=beagle&amp;applicationId=AWSMPContessa\"><span data-contrast=\"none\">Available in AWS Marketplace<\/span><\/a><span data-contrast=\"none\">, <\/span><a href=\"https:\/\/www.sophos.com\/en-us\/solutions\/public-cloud\/aws\/managed-threat-protection.aspx\"><span data-contrast=\"none\">the Sophos Threat Protection, Monitoring and Response for AWS package<\/span><\/a><span data-contrast=\"none\">\u202fcombines cloud security posture management and compliance, firewall, cloud workload and endpoint protection, a number of AWS services, and the Sophos Managed Threat Response service to continuously monitor AWS environments, and analyze and triage security events. <\/span><\/p>\n<p><span data-contrast=\"none\">This support helps companies increase the efficiency of their security programs and internal teams, pre-emptively advising on recommended next steps and acting on their behalf, if desired.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:320,&quot;335559739&quot;:320,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"none\">Learn more or speak with an expert to dive deeper on a specific topic at\u202f<\/span><\/b><a href=\"https:\/\/www.sophos.com\/aws-mssp\"><b><span data-contrast=\"none\">sophos.com\/aws-mssp<\/span><\/b><\/a>.<span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559738&quot;:320,&quot;335559739&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<\/p><\/div>\n<p><a href=\"https:\/\/news.sophos.com\/en-us\/2022\/07\/26\/sophos-announces-support-for-the-new-amazon-guardduty-malware-protection-service\/\" target=\"bwo\" >http:\/\/feeds.feedburner.com\/sophos\/dgdY<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/07\/sophos-cns-news-blog-image-1200x628px@2x.png\"\/><\/p>\n<p><strong>Credit to Author: Anthony Merry| Date: Tue, 26 Jul 2022 22:15:52 +0000<\/strong><\/p>\n<p>Sophos&#8217; new Cloud Native Security offering helps automate, simplify and enhance response to malicious files detected by the new Amazon service <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10377],"tags":[12010,11728,21508,27083,24562,27097],"class_list":["post-19690","post","type-post","status-publish","format-standard","hentry","category-security","category-sophos","tag-aws","tag-cloud","tag-cloud-optix","tag-cns","tag-products-services","tag-workload-protection"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19690","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=19690"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19690\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=19690"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=19690"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=19690"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}