Zero Trust in Action: Insider Threat Detection with Splunk on AWS
This event qualifies for:
Your Zero Trust controls verify identity, protect endpoints, and enforce access policies. But what happens when a user with valid credentials exploits trust between systems to reach data they should never touch and every control says "allow"?
Join us for a demonstration of insider threat detection and automated response on the AWS Zero Trust Accelerator for Government (ZTAG-I) architecture. In this session, you will watch a realistic attack unfold across six telemetry sources and see how Splunk correlates signals from Okta, CrowdStrike, AWS CloudTrail, VPC Flow Logs, and Windows to surface the complete attack chain and trigger automated containment through Splunk SOAR in seconds.
This is not a slide deck. This session is a demo on AWS GovCloud with real telemetry, real detections, and real automated response.
In this webinar, attendees will see:
- A realistic insider threat scenario where an authenticated user escalates privileges and moves laterally across AWS infrastructure
- How Okta, CrowdStrike, and AWS each detect activity within their domain and how Splunk connects those signals into a single correlated view
- The complete MITRE ATT&CK kill chain mapped in Splunk Cloud with cumulative risk scoring
- Splunk SOAR executing automated containment: endpoint isolation, credential revocation, session termination, and incident creation
- How this approach operationalizes the AWS ZTAG-I reference architecture for detection and response
Speaker Details
Dave Pannu
Amandeep Singh
Event Topic
Cybersecurity, Security, Digital TransformationRelevant Audiences
All Government Contractors