Skip to content

Update Bits Security Analyst supported sources - #38543

Merged
feldmanr merged 1 commit into
masterfrom
ron.feldman/update-bits-supported-sources
Jul 30, 2026
Merged

Update Bits Security Analyst supported sources#38543
feldmanr merged 1 commit into
masterfrom
ron.feldman/update-bits-supported-sources

Conversation

@feldmanr

Copy link
Copy Markdown
Contributor

What changed

  • Add Cloudflare, Windows, Slack, and GitLab to the supported Security log sources for Bits Security Analyst.
  • Expand the Amazon GuardDuty coverage description to include the existing finding types plus the new IAM, Bedrock, EKS, ECS, Kubernetes, and S3 finding coverage.

Why

Bits Security Analyst supports additional log sources and GuardDuty finding types that are not represented in the current documentation.

Impact

Customers can see a more complete and accurate view of the sources and GuardDuty findings that Bits Security Analyst can investigate.

Validation

  • Confirmed the branch is one commit ahead of master.
  • Confirmed the diff changes only content/en/bits_ai/bits_security_analyst.md.
  • Reviewed the rendered Markdown list structure and source names.

@github-actions

Copy link
Copy Markdown
Contributor

Preview links (active after the build_preview check completes)

Modified Files

@feldmanr
feldmanr force-pushed the ron.feldman/update-bits-supported-sources branch 3 times, most recently from 022992d to fa35285 Compare July 29, 2026 01:38
@feldmanr
feldmanr force-pushed the ron.feldman/update-bits-supported-sources branch from fa35285 to c05442d Compare July 29, 2026 01:42
@feldmanr feldmanr closed this Jul 29, 2026
@feldmanr feldmanr reopened this Jul 29, 2026
@janine-c janine-c self-assigned this Jul 30, 2026

@janine-c janine-c left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks great! I think adding bullets to the list might make it a little easier to parse. Feel free to take this PR out of draft and merge it whenever you're ready 🙂

@@ -47,18 +47,22 @@ Additionally, when you use Cloud SIEM notifications to send new signal alerts to

Bits AI can run investigations on the following Security log sources:
- Amazon GuardDuty

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
- Amazon GuardDuty
- Amazon GuardDuty, where supported [finding types][6] cover:

Bits AI can run investigations on the following Security log sources:
- Amazon GuardDuty
- [Finding categories][6] include anomalous IAM behavior, EC2 credential exfiltration and misuse, S3 data exposure, CloudTrail or S3 defense evasion, and attack sequences correlating IAM credential and S3 data compromise
- Supported [finding types][6] cover anomalous and compromised IAM credentials; EC2 and resource credential exfiltration and misuse; Bedrock logging changes, anomalous model invocation, cost harvesting, and direct prompt injection; compromised EKS and ECS cluster attack sequences; Kubernetes credential access, anomalous behavior, execution, privilege escalation, persistence, policy changes, and malicious callers; S3 anomalous behavior, data exposure, malicious callers, and penetration test activity; CloudTrail or S3 defense evasion; and attack sequences correlating IAM credential and S3 data compromise.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
- Supported [finding types][6] cover anomalous and compromised IAM credentials; EC2 and resource credential exfiltration and misuse; Bedrock logging changes, anomalous model invocation, cost harvesting, and direct prompt injection; compromised EKS and ECS cluster attack sequences; Kubernetes credential access, anomalous behavior, execution, privilege escalation, persistence, policy changes, and malicious callers; S3 anomalous behavior, data exposure, malicious callers, and penetration test activity; CloudTrail or S3 defense evasion; and attack sequences correlating IAM credential and S3 data compromise.
- Anomalous and compromised IAM credentials
- EC2 and resource credential exfiltration and misuse
- Bedrock logging changes, anomalous model invocation, cost harvesting, and direct prompt injection
- Compromised EKS and ECS cluster attack sequences
- Kubernetes credential access, anomalous behavior, execution, privilege escalation, persistence, policy changes, and malicious callers
- S3 anomalous behavior, data exposure, malicious callers, and penetration test activity
- CloudTrail or S3 defense evasion
- Attack sequences correlating IAM credential and S3 data compromise

@feldmanr
feldmanr marked this pull request as ready for review July 30, 2026 18:25
@feldmanr
feldmanr requested a review from a team as a code owner July 30, 2026 18:25
@feldmanr
feldmanr merged commit 68d928c into master Jul 30, 2026
28 of 30 checks passed
@feldmanr
feldmanr deleted the ron.feldman/update-bits-supported-sources branch July 30, 2026 18:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants