<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>IDS/IPS/UTM Threat Detection on SolCyber Knowledgebase</title><link>https://kb.solcyber.com/supported-data-sources-categories/ids-ips-utm-threat-detection/</link><description>Recent content in IDS/IPS/UTM Threat Detection on SolCyber Knowledgebase</description><generator>Hugo</generator><language>en</language><atom:link href="https://kb.solcyber.com/supported-data-sources-categories/ids-ips-utm-threat-detection/index.xml" rel="self" type="application/rss+xml"/><item><title>AWS Guard Duty</title><link>https://kb.solcyber.com/supported-data-sources-categories/ids-ips-utm-threat-detection/aws-guard-duty/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://kb.solcyber.com/supported-data-sources-categories/ids-ips-utm-threat-detection/aws-guard-duty/</guid><description>&lt;h2 id="retrieve-the-detector-id"&gt;Retrieve the Detector ID &lt;a href="#retrieve_the_detector_id" id="retrieve_the_detector_id"&gt;&lt;/a&gt;&lt;a class="anchor" href="#retrieve-the-detector-id"&gt;#&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;To find the &lt;code&gt;detectorId&lt;/code&gt; in the current Region, see the &lt;em&gt;&lt;strong&gt;Settings&lt;/strong&gt;&lt;/em&gt; page in the GuardDuty console, or run the &lt;a href="https://docs.aws.amazon.com/guardduty/latest/APIReference/API_ListDetectors.html"&gt;ListDetectors&lt;/a&gt; API.&lt;/p&gt;
&lt;figure&gt;&lt;img src="https://kb.solcyber.com/assets/Screenshot 2025-08-21 at 11.54.05 AM.png" alt=""&gt;&lt;figcaption&gt;&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;You will need to provide the &lt;strong&gt;detectorID&lt;/strong&gt; to SolCyber.&lt;/p&gt;
&lt;h2 id="authorize-the-iam-user"&gt;Authorize the IAM User &lt;a href="#authoriz" id="authoriz"&gt;&lt;/a&gt;&lt;a class="anchor" href="#authorize-the-iam-user"&gt;#&lt;/a&gt;&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;Create an IAM service account to user for Securonix log ingestion. You may already have one if you have previously configured CloudTrail logs for Securonix.&lt;/li&gt;
&lt;li&gt;Authorize the IAM User using the steps under &lt;a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users_change-permissions.html"&gt;Change permissions for an IAM user&lt;/a&gt;. When prompted during the configuration, attach the &lt;code&gt;AmazonGuardDutyReadOnlyAccess&lt;/code&gt; AWS managed policies to the authorized user.&lt;/li&gt;
&lt;li&gt;Copy and save the &lt;strong&gt;Secret Key&lt;/strong&gt;, and &lt;strong&gt;Access ID&lt;/strong&gt; and provide these values to SolCyber.&lt;/li&gt;
&lt;/ol&gt;</description></item><item><title>Azure Security Center</title><link>https://kb.solcyber.com/supported-data-sources-categories/ids-ips-utm-threat-detection/azure-security-center/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://kb.solcyber.com/supported-data-sources-categories/ids-ips-utm-threat-detection/azure-security-center/</guid><description>&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Open the &lt;strong&gt;Azure Active Directory&lt;/strong&gt; resource in the Azure Portal.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click &lt;strong&gt;App registrations&lt;/strong&gt; &amp;gt; &lt;strong&gt;New Registration&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;&lt;img src="https://documentation-be.securonix.com/bundle/securonix-cloud-user-guide/page/content/resources/images/active-deployment-guides/microsoft/azure-identity-protection-1.png?_LANG=enus" alt="" /&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Provide a name, and select the account scope to Single tenant.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click &lt;strong&gt;Register&lt;/strong&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click on the new application created on the App registration screen.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Copy the &lt;strong&gt;Client ID&lt;/strong&gt; and &lt;strong&gt;Tenant ID&lt;/strong&gt;, and then click &lt;strong&gt;View API permissions&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;&lt;img src="https://documentation-be.securonix.com/bundle/securonix-cloud-user-guide/page/content/resources/images/active-deployment-guides/microsoft/azure-identity-protection-2.png?_LANG=enus" alt="" /&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click &lt;strong&gt;Add a permission&lt;/strong&gt;, and then click the &lt;strong&gt;Microsoft Graph API&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;&lt;img src="https://documentation-be.securonix.com/bundle/securonix-cloud-user-guide/page/content/resources/images/active-deployment-guides/microsoft/azure-identity-protection-3.png?_LANG=enus" alt="" /&gt;&lt;/p&gt;</description></item></channel></rss>