Launch HN: Matano (YC W23) – Open-Source Security Lake Platform (SIEM) for AWS

📰 Hacker News · wizwit999

Hi HN! We’re Shaeq and Samrose, co-founders of Matano ( https://matano.dev ). Matano is a high-scale, low-cost alternative to traditional SIEM (e.g. Splunk, Elastic) built around a vendor-agnostic security data lake that deploys to your AWS account. Don’t worry — we’ll explain all this jargon in a second. SIEM stands for “Security Information and Event Management” and refers to log management tools used by security teams to detect threats from an organization's security logs (network, host, cloud, SaaS audit logs, etc.) and send alerts about them. Security engineers write detection rules inside the SIEM as queries to detect suspicious activity and create alerts. For example, a security engineer could write a detection rule that checks the fields in each CloudTrail log and creates an alert whenever an S3 bucket is modified with public access, to prevent data exfiltration. Traditional SIEM tools (e.g. Splunk, Elastic) used to analyze security data are difficult to manage f

Published 24 Jan 2023
Read full article → ← Back to Reads