Why most teams are flying blind in security operations with Bleon Proko

James Berthoty talks with Bleon Proko, cloud security researcher at Exaforce, about why cloud incident response is so much harder than traditional SOC work, what log sources most teams are ignoring, and how to build detection coverage that actually keeps up with attackers.

Why most teams are flying blind in security operations with Bleon Proko

Summary

In this episode of SecOps Confidential, James Berthoty talks with Bleon Proko, cloud security researcher at Exaforce, about why cloud security operations are still tripping up teams that are otherwise solid at traditional SOC work. Bleon breaks down the structural gap between cloud security engineers focused on posture and SOC teams drowning in raw log sources they don't know what to do with. They get into which log sources matter most (including S3 data events and Bedrock logs that most people skip), how to approach basic detection building without getting buried in false positives, and how attackers tend to stay basic while defenders often miss things hiding in plain sight. Bleon also shares lessons from his own cloud research, including a real honeypot that caught a full threat actor team, and his framework for building detection coverage you can actually maintain.

Show Notes

  • Why cloud security still catches SOC teams off guard, even years into cloud adoption
  • The gap between CNAPP-focused cloud engineers and traditional security operations teams
  • Where teams go wrong, collecting logs they never actually use for detection
  • Which CloudTrail event categories and data sources to prioritize first
  • Why Bedrock logs and S3 data events are underused and what attackers do with that gap
  • How to approach detection engineering for cloud without drowning in false positives
  • Why most attacks are still basic, and why that doesn't make them easier to catch
  • Novel techniques like AWS Cloud Control and GCP Sys projects used for evasion and persistence
  • A practical framework for building cloud detection coverage: start with what you use, watch what you don't

Links

Transcript

The dream SOC team.
Working with you 24/7.

Detection, triage, investigation, and response covered by four Exabots running on a unified, real-time view of your environment. Operate the platform yourself, or have Exaforce run it for you.