Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
23 changes: 14 additions & 9 deletions hugo/content/en/bits_ai/bits_security_analyst.md
Original file line number Diff line number Diff line change
Expand Up @@ -53,6 +53,7 @@ Additionally, when you use Cloud SIEM notifications to send new signal alerts to
### Supported sources

Bits AI can run investigations on the following Security log sources:\*
- 1Password
- Amazon GuardDuty, where supported [finding types][6] cover:
- Anomalous and compromised IAM credentials
- EC2 and resource credential exfiltration and misuse
Expand All @@ -62,28 +63,32 @@ Bits AI can run investigations on the following Security log sources:\*
- S3 anomalous behavior, data exposure, malicious callers, and penetration test activity
- CloudTrail or S3 defense evasion
- Attack sequences correlating IAM credential and S3 data compromise
- AWS CloudTrail
- Atlassian Event Logs
- Auth0
- AWS CloudTrail
- Azure
- Claude Compliance Logs
- Cloudflare
- Confluence Audit Records
- CrowdStrike
- Email phishing
- GCP
- GitHub
- GitLab
- Google Workspace
- Jira Audit Records
- JumpCloud
- Kubernetes
- Microsoft 365
- Microsoft Defender for EDR
- Microsoft Entra ID
- Okta
- Google Workspace
- Microsoft 365
- GitLab
- GitHub
- JumpCloud
- Jira Audit Records
- Salesforce
- SentinelOne
- Slack
- Snowflake
- SentinelOne
- Windows
- Email phishing
- Zendesk

\*In rare cases, an out-of-the-box rule for a supported source is ineligible for Bits investigations because the investigation requires additional non-SIEM telemetry. To view these rules, go to {{< ui >}}Security{{< /ui >}} > {{< ui >}}Settings{{< /ui >}} > {{< ui >}}Bits Security Analyst{{< /ui >}} > {{< ui >}}Analyst Configuration{{< /ui >}}, then turn on {{< ui >}}Show currently ineligible rules{{< /ui >}}.

Expand Down
Loading