Cloud
云活动关联分析
The process of linking and analyzing disparate cloud events, logs, and telemetry to detect patterns indicative of threats, policy violations, or misconfigurations.
Quick answer: The process of linking and analyzing disparate cloud events, logs, and telemetry to detect patterns indicative of threats, policy violations, or misconfigurations.
This term page is part of the Protermify Cybersecurity glossary and is published as static HTML for fast indexing and clear language coverage.
Definition
The process of linking and analyzing disparate cloud events, logs, and telemetry to detect patterns indicative of threats, policy violations, or misconfigurations.
Operational example
Use cloud activity correlation in your SIEM to detect suspicious logins, privilege escalations, and data transfers across SaaS and IaaS platforms.
Localized example
在您的SIEM中使用云活动关联分析,以检测SaaS和IaaS平台上的可疑登录、权限提升和数据传输。
Definition language
English reference definition
Source
ISO 27001, NIST Cybersecurity Framework, MITRE ATT&CK
Exam relevance
- CISSP
- CompTIA Security+
- CEH
Target audience
- SOC Analysts
- Security Engineers
- Incident Responders