Vulnerable EC2 instance, accessed by an unmanaged device, through a compromised service account, which tool should catch that?
Had an incident last month that exposed a gap Im still thinking about. An attacker moved from a compromised endpoint to a cloud workload through a service account that had access to both. The CNAPP saw the cloud side. The EDR saw the endpoint side. The identity tool saw the service account. But what bugs me is no one saw the full chain.
We caught it eventually but the investigation took way longer than it should have because we had to manually connect dots across tools that dont talk to each other. The data was all there, was just in three different places and nobody was correlating it.
Is there another way of solving this this cross domain visibility problem, or is one of those things you stitch it together yourself during the incident?