Zero Trust in Action: Insider Threat Detection with Splunk on AWS

This event qualifies for:

1 CPEs

Your Zero Trust controls verify identity, protect endpoints, and enforce access policies. But what happens when a user with valid credentials exploits trust between systems to reach data they should never touch and every control says "allow"?

Join us for a demonstration of insider threat detection and automated response on the AWS Zero Trust Accelerator for Government (ZTAG-I) architecture. In this session, you will watch a realistic attack unfold across six telemetry sources and see how Splunk correlates signals from Okta, CrowdStrike, AWS CloudTrail, VPC Flow Logs, and Windows to surface the complete attack chain and trigger automated containment through Splunk SOAR in seconds.

This is not a slide deck. This session is a demo on AWS GovCloud with real telemetry, real detections, and real automated response.

In this webinar, attendees will see:

  • A realistic insider threat scenario where an authenticated user escalates privileges and moves laterally across AWS infrastructure
  • How Okta, CrowdStrike, and AWS each detect activity within their domain and how Splunk connects those signals into a single correlated view
  • The complete MITRE ATT&CK kill chain mapped in Splunk Cloud with cumulative risk scoring
  • Splunk SOAR executing automated containment: endpoint isolation, credential revocation, session termination, and incident creation
  • How this approach operationalizes the AWS ZTAG-I reference architecture for detection and response

Speaker Details

Dave Pannu

Solutions Architect, AWS

Amandeep Singh

Solutions Architect, AWS

Event Topic

Cybersecurity, Security, Digital Transformation

Relevant Audiences

All Government Contractors
Zero Trust in Action: Insider Threat Detection with Splunk on AWS
Event Type
Virtual / Online
Event Subtype
Webinar / Webcast
When
Wed, Jul 29, 2026 | 2:00 pm - 3:00 pm ET
Registration Cost
Complimentary
Website
Click here to view event website
Sponsors
Splunk