Mitiga — RSA Conference 2024 Innovation Sandbox
RSA Conference 2024 · Innovation Sandbox
Overview
In an era where cloud adoption is not just prevalent but rapidly accelerating towards a projected $1 trillion market, the security operations center (SOC) faces unprecedented challenges. This talk, delivered by Ofer Maor, Co-founder and CTO of Mitiga, at the RSA Conference 2024 Innovation Sandbox, addresses a critical gap in modern cybersecurity: the lagging capabilities of SecOps teams in effectively detecting, investigating, and responding to threats within complex cloud and SaaS environments. Maor argues that while Cloud Native Application Protection Platforms (CNAPPs) have empowered DevOps and security teams to manage cloud scale and complexity, SecOps has been left behind, grappling with inadequate tools and expertise gaps.

Key moments
- 0:00 Introduction: The challenge of cloud SecOps
- 0:25 Mitiga's vision for empowered cloud SOC teams
- 0:35 Mitiga's core: Distributed cloud security data lake
- 0:46 Cloud attack scenario library for contextual alerts
- 0:56 Investigation workbench: Full attacker timeline across cloud
- 1:06 Automated hunt logic provides immediate breach visibility
- 1:25 Conclusion: Supercharging SOC for the cloud era
Supercharging Your SOC for the Cloud Era
Speakers: Ofer Maor, Co-founder and CTO, Mitiga
Conference: RSAC 2024
YouTube: https://www.youtube.com/watch?v=-kPbyayyBWQ
Overview
In an era where cloud adoption is not just prevalent but rapidly accelerating towards a projected $1 trillion market, the security operations center (SOC) faces unprecedented challenges. This talk, delivered by Ofer Maor, Co-founder and CTO of Mitiga, at the RSA Conference 2024 Innovation Sandbox, addresses a critical gap in modern cybersecurity: the lagging capabilities of SecOps teams in effectively detecting, investigating, and responding to threats within complex cloud and SaaS environments. Maor argues that while Cloud Native Application Protection Platforms (CNAPPs) have empowered DevOps and security teams to manage cloud scale and complexity, SecOps has been left behind, grappling with inadequate tools and expertise gaps.
Mitiga positions itself as the solution to this problem, aiming to "supercharge" the SOC for the cloud era. The company's platform is designed to provide clarity amidst the chaos of cloud security, offering a comprehensive suite of tools that enable SOC analysts to act with speed, scale, and specialized expertise. By building a distributed cloud security data lake, leveraging an extensive cloud attack scenario library, and providing an intuitive investigation workbench, Mitiga promises to transform cloud incident response from a days-long struggle into a minutes-long resolution. This presentation highlights the urgent need for specialized cloud SecOps capabilities and introduces Mitiga as a pivotal innovation in bridging this critical security divide.
Background
▶ Watch: Introduction: The challenge of cloud SecOps (0:00)
The rapid migration of enterprises to public cloud infrastructures and the proliferation of Software-as-a-Service (SaaS) applications have fundamentally reshaped the threat landscape. While the agility and scalability benefits of the cloud are undeniable, they introduce a new paradigm of security challenges that traditional, on-premise focused security tools and methodologies are ill-equipped to handle. The speaker underscored this point by recounting a recent experience with a CISO struggling to investigate a breach impacting a Sisense customer, illustrating a common scenario for many organizations. This anecdote serves as a potent reminder of the real-world operational difficulties SOC teams face daily.
The core problem, as articulated by Maor, is a significant disparity in the evolution of security tools. The public cloud market is projected to reach an astounding $1 trillion within the next three years, signifying a massive shift in IT infrastructure. To manage the inherent scale and complexity of this transition, solutions like CNAPPs have emerged, providing essential capabilities for security and DevOps teams to secure cloud-native applications and infrastructure. However, these advancements have largely bypassed SecOps. SOC teams are increasingly confronted with a fragmented, high-volume, and highly dynamic data environment, encompassing logs and telemetry from multiple cloud providers (AWS, Azure, GCP), numerous SaaS applications, and an ever-changing landscape of identities and resources.
This environment presents several critical pain points for SecOps:
- Lack of Unified Visibility: Cloud environments generate vast quantities of logs and events, often in disparate formats, making it exceedingly difficult to gain a holistic view of an attack across an entire cloud footprint. Correlating events from AWS CloudTrail, Azure Activity Logs, Okta identity logs, and SaaS application audit trails manually is a Herculean task.
- Expertise Gaps: Cloud security requires specialized knowledge of cloud provider APIs, services, and security models. Many SOC analysts, trained on traditional network and endpoint security, lack this deep cloud-native expertise, leading to slower investigations and an inability to accurately assess cloud-specific threats.
- Tooling Deficiencies: Existing Security Information and Event Management (SIEM) systems and Security Orchestration, Automation, and Response (SOAR) platforms often struggle with the sheer volume and unique characteristics of cloud data. They may lack native integrations, struggle with contextualizing cloud-specific events, or incur prohibitive costs for ingesting petabytes of cloud logs.
- Slow Response Times: The combination of fragmented data, lack of expertise, and inadequate tooling results in prolonged detection, investigation, and response times. What might take minutes or hours in a well-understood on-premise environment can stretch into days or weeks in the cloud, significantly increasing the potential impact and cost of a breach.
- Complexity of Identity-Based Attacks: Identity is the new perimeter in the cloud. Attacks often involve compromising cloud identities (e.g., IAM roles, service principals, user accounts) and moving laterally across cloud services or SaaS applications. Tracing these identity-based attack paths across different systems is exceptionally complex without specialized tools.
In essence, the "right tools" for cloud detection, investigation, and response are missing from the SOC analyst's arsenal, creating a significant security debt that Mitiga aims to resolve by enabling SOC teams to achieve the necessary speed, scale, and expertise required for the cloud era.
Key Findings
▶ Watch: Mitiga's core: Distributed cloud security data lake (0:35)
Mitiga's core contribution, as presented by Ofer Maor, is a comprehensive platform designed to bring "clarity in the chaos" of cloud security operations. The company's solution directly addresses the aforementioned challenges by offering a suite of integrated capabilities that empower SOC teams to effectively detect, investigate, and respond to threats across their entire cloud and SaaS footprint. The platform's main discoveries and contributions revolve around its unique architectural approach and its ability to synthesize complex, distributed cloud data into actionable intelligence.
The key findings and contributions of Mitiga, as highlighted in the talk, include:
- A Distributed Cloud Security Data Lake: At the foundation of Mitiga's platform is a purpose-built, distributed cloud security data lake. This infrastructure is engineered to collect and normalize petabytes of log data from various public cloud providers (e.g., AWS, Azure, GCP) and numerous SaaS applications, alongside critical context data. This unified data repository is crucial for overcoming the fragmentation inherent in multi-cloud and hybrid environments. By centralizing this vast amount of information, Mitiga enables a comprehensive view that is otherwise impossible to achieve with disparate log sources. The ability to ingest "context data" is particularly significant, as it allows for enrichment of raw logs with information about identities, resources, configurations, and network flows, which is vital for accurate threat detection and investigation.
- Cloud Attack Scenario Library: Running on top of the data lake is Mitiga's cloud attack scenario library. This library is the culmination of years of expertise and research into cloud-native attack techniques, adversary tactics, and common vulnerabilities. It serves as an intelligent layer that transforms raw, voluminous log data into "crisp, relevant, clear alerts" for SOC analysts. Instead of generic, high-volume alerts, the library focuses on identifying actual attack scenarios with high fidelity. This means analysts receive alerts that are highly contextualized, showing only the most relevant data needed to understand a threat, thereby significantly reducing alert fatigue and false positives. This library effectively encapsulates specialized cloud security expertise, making it accessible to generalist SOC analysts.
- Investigation Workbench for Full Cloud Investigations: Mitiga provides an investigation workbench designed to empower SOC teams to conduct thorough cloud investigations without requiring deep cloud expertise. A standout feature of this workbench is its ability to automatically construct complex timelines of an attacker's path. These timelines span across different cloud systems, identities, and resources, providing a chronological and contextualized narrative of an incident. This capability is critical for understanding lateral movement, privilege escalation, and data exfiltration within dynamic cloud environments. The workbench facilitates investigations across the entire identity, cloud, and SaaS footprints, offering a unified interface for analysts to correlate events, visualize relationships, and drill down into specific artifacts.
- Automated Hunt Logic for Major Breaches: In the event of a major breach, Mitiga's platform incorporates automated hunt logic. This feature provides immediate visibility into an organization's security posture and the scope of a compromise. Rather than requiring manual querying and extensive data analysis during a crisis, the automated hunt logic can rapidly zero in on cloud threats, providing crucial insights with speed and accuracy. This capability is particularly valuable for reducing dwell time and accelerating the incident response process during high-stakes situations.
The talk highlighted the tangible impact of these contributions, noting that "over 40 leading brands are already responding to cloud threats with Mitiga." This indicates a proven ability to address real-world security challenges effectively, transforming the ability of SOC teams to respond to cloud threats in "minutes, not days," a significant improvement over traditional methods.
Technical Deep Dive
▶ Watch: Cloud attack scenario library for contextual alerts (0:46)
Mitiga's approach to supercharging the SOC for the cloud era is rooted in several key technical components designed to overcome the inherent complexities of cloud security. While the presentation was a high-level pitch, the described functionalities imply sophisticated underlying architectures and processes.
At the heart of Mitiga's platform is the distributed cloud security data lake. This isn't just a simple log aggregation service; it's a sophisticated data platform built for the unique demands of cloud security. It's designed to ingest petabytes of cloud and SaaS logs and context data. This implies:
- Multi-Cloud and Multi-SaaS Ingestion: The data lake must have robust connectors and APIs to pull data from a diverse set of sources, including major cloud providers like AWS (CloudTrail, VPC Flow Logs, GuardDuty, S3 access logs), Azure (Activity Logs, Azure Monitor, Sentinel), GCP (Cloud Audit Logs, VPC Flow Logs), and a wide array of SaaS applications (e.g., Salesforce, Microsoft 365, Google Workspace, Okta, GitHub).
- Data Normalization and Enrichment: Raw logs from different sources come in varied formats. A crucial technical step is the normalization of this data into a common schema, making it searchable and correlatable. Furthermore, "context data" is vital. This includes enriching logs with information about the involved identities (users, roles, service principals), resources (EC2 instances, S3 buckets, Azure VMs, Kubernetes pods), network configurations (security groups, NACLs, firewalls), and geopolitical information. This enrichment process often involves integrating with asset inventory systems, identity providers, and threat intelligence feeds.
- Scalable Storage and Indexing: Handling petabytes of data requires highly scalable, cost-effective storage solutions (e.g., object storage like S3, Azure Blob Storage) coupled with powerful indexing and search capabilities (e.g., Elasticsearch, OpenSearch, or proprietary indexed databases). This ensures that queries for investigations can be executed with speed, even across vast datasets.
- Data Retention Policies: Implementing intelligent data retention policies, potentially tiered storage, is necessary to balance compliance requirements, investigative needs, and cost efficiency.
Layered upon this data lake is Mitiga's cloud attack scenario library. This is where raw data transforms into actionable intelligence. This library is not merely a collection of static rules but a dynamic, evolving knowledge base encompassing "years of expertise and research." Its technical underpinnings likely involve:
- Cloud-Native Threat Modeling: The library is built upon a deep understanding of cloud-specific attack techniques, such as IAM privilege escalation, misconfigured storage buckets leading to data exfiltration, container escape vulnerabilities, serverless function abuse, and supply chain attacks involving cloud services. This often maps to frameworks like MITRE ATT&CK for Cloud.
- Behavioral Analytics and Anomaly Detection: Beyond signature-based detections, the library likely leverages machine learning and behavioral analytics to identify deviations from normal cloud resource and identity behavior. This could include detecting unusual API calls, login patterns from new geographies, or unexpected data access attempts.
- Correlation Engine: The library's ability to provide "crisp, relevant, clear alerts" implies a powerful correlation engine that can connect disparate events across the data lake to form a coherent attack narrative. For example, correlating a suspicious login from a new IP, followed by an API call to modify an IAM policy, and subsequent data transfer to an external bucket.
- Contextualization: Alerts are "contextualized," meaning they don't just state "suspicious activity" but provide details on the affected identity, resource, the specific cloud service involved, and the potential impact, drawing directly from the enriched data lake.
The investigation workbench is the analyst's interface to this powerful backend. It's designed to abstract away the underlying cloud complexity, allowing analysts to "conduct full cloud investigation across their entire identity, cloud and SAS footprints without needing to be an expert." Key technical aspects would include:
- Automated Timeline Construction: This is a sophisticated capability requiring a graph database or similar technology to map relationships between identities, resources, events, and time. When an alert triggers, the workbench automatically queries the data lake to reconstruct the sequence of events, showing the attacker's path chronologically across different cloud services and SaaS applications.
- Interactive Visualization: Analysts need intuitive ways to visualize complex relationships. This could involve interactive graphs showing identity relationships, resource dependencies, network flows, and event chains. The ability to pivot from an alert to related identities, resources, or logs is crucial.
- Cross-Footprint Correlation: The workbench must seamlessly integrate data from various cloud providers and SaaS applications, allowing an analyst to follow an attack that starts in Azure, moves to an Okta identity, and then impacts a Salesforce instance, all within a single pane of glass.
- Guided Investigations: To enable non-experts, the workbench might offer guided workflows, pre-built queries, and contextual information about cloud services and attack techniques.
Finally, the automated hunt logic for major breaches suggests a specialized set of capabilities. During a breach, immediate visibility is paramount. This logic likely involves:
- Pre-defined Threat Hunting Playbooks: Based on common breach scenarios (e.g., ransomware, supply chain compromise, insider threat), the system can automatically execute pre-optimized queries and analytical procedures across the data lake.
- Real-time Anomaly Detection: Continuously monitoring for indicators of compromise (IoCs) and advanced persistent threats (APTs) that might signal an ongoing breach, even before a specific alert is triggered.
- Rapid Scope Assessment: Quickly identifying affected identities, compromised resources, and potential data exfiltration points to help incident responders contain the breach effectively.
While specific code examples, API details, or architectural diagrams were not presented in the brief pitch, the description of Mitiga's capabilities points to a robust, data-intensive platform that leverages advanced analytics and cloud-native understanding to streamline and enhance cloud security operations. The emphasis is on abstracting complexity and providing actionable intelligence, making advanced cloud security accessible to a broader range of SOC analysts.
Demo / Proof of Concept
▶ Watch: Automated hunt logic provides immediate breach visibility (1:06)
The presentation by Ofer Maor at the RSA Conference 2024 Innovation Sandbox was primarily a high-level pitch, designed to introduce Mitiga's vision and core value proposition within a constrained timeframe. As such, it did not include a live, interactive demonstration or a detailed, step-by-step proof of concept of the platform's technical functionalities.
Instead, Maor effectively conveyed the capabilities and impact of Mitiga through vivid, scenario-based descriptions. He invited the audience to "imagine what it would feel like to have a team who immediately springs into action, seeing across the whole cloud, detecting threats with rich context, automatically constructing complex timelines across your entire cloud footprint, and responding to the threats in minutes, not days." This narrative served as a conceptual demonstration, painting a clear picture of the ideal state that Mitiga aims to enable for SecOps teams.
The talk highlighted the results of Mitiga's functionalities, such as providing "crisp, relevant, clear alerts" and empowering analysts to "jump into a full timeline of the attacker's path across different systems." While not a visual, interactive demo, these descriptions functioned as a powerful articulation of the product's value, demonstrating its potential to solve real-world problems like the Sisense breach investigation challenge mentioned at the outset. The implicit proof of concept lies in the claim that "over 40 leading brands are already responding to cloud threats with Mitiga," suggesting that the platform's capabilities have been validated in real-world deployments.
Defensive Implications
▶ Watch: Conclusion: Supercharging SOC for the cloud era (1:25)
Mitiga's platform offers profound defensive implications for organizations struggling to secure their cloud and SaaS environments. By addressing the critical gaps in cloud SecOps, it empowers defenders with capabilities that were previously difficult, if not impossible, to achieve with traditional tools or fragmented approaches.
- Enhanced Cloud Visibility and Context: The distributed cloud security data lake provides a centralized, normalized view of all cloud and SaaS activities. This eliminates blind spots and allows defenders to see across their entire digital footprint, from AWS to Azure to Okta and Salesforce. This unified visibility is crucial for understanding the full scope of an attack, including lateral movement and privilege escalation across different services. The enrichment with "context data" means that alerts are not just raw logs but actionable insights, detailing the involved identities, resources, and configurations.
- Accelerated Detection and Response: By leveraging the cloud attack scenario library and automated hunt logic, defenders can significantly reduce their mean time to detect (MTTD) and mean time to respond (MTTR) to cloud threats. The platform's ability to provide "crisp, relevant, clear alerts" drastically cuts down on alert fatigue and false positives, allowing SOC analysts to focus on real threats. Responding in "minutes, not days," as Mitiga promises, translates directly into reduced potential damage, lower breach costs, and improved business continuity.
- Democratization of Cloud Security Expertise: One of the most significant defensive implications is the ability for generalist SOC analysts to perform advanced cloud investigations. The investigation workbench abstracts away the intricate details of cloud provider APIs and service-specific logging, presenting a unified, intuitive interface. This means organizations don't need to hire an army of highly specialized cloud security engineers for their SOC, effectively bridging the industry's pervasive cybersecurity skills gap. Analysts can leverage the platform's built-in expertise to understand attacker timelines and paths without needing to be cloud experts themselves.
- Proactive Threat Hunting Capabilities: The automated hunt logic is a powerful tool for proactive defense. Instead of merely reacting to alerts, defenders can use Mitiga to actively search for sophisticated threats that might evade traditional signature-based detections. During major breaches, this capability provides immediate insights, enabling rapid containment and eradication efforts. This shifts the SOC from a purely reactive stance to a more proactive and resilient security posture.
- Improved Compliance and Audit Readiness: With a centralized data lake housing petabytes of normalized cloud and SaaS logs, organizations can more easily demonstrate compliance with various regulatory frameworks (e.g., GDPR, HIPAA, SOC 2). The ability to quickly reconstruct attack timelines and provide detailed audit trails simplifies internal and external audits, proving that security controls are effective and incidents can be thoroughly investigated.
- Reduced Operational Overhead: By automating data collection, normalization, correlation, and initial investigation steps, Mitiga helps reduce the manual burden on SOC teams. This allows analysts to spend less time on tedious data wrangling and more time on high-value activities like threat analysis, remediation planning, and strategic security improvements.
In summary, Mitiga empowers defenders to move beyond the limitations of traditional SecOps in the cloud. It provides the necessary tools and intelligence to manage the scale, complexity, and dynamic nature of cloud environments, ultimately enabling a more robust, efficient, and expert-driven cloud security operation.
Key Takeaways
- Cloud SecOps is Lagging: Despite rapid cloud adoption and the growth of CNAPPs for DevOps, SOC teams lack adequate tools and expertise for effective detection, investigation, and response in the complex cloud and SaaS landscape.
- Mitiga Offers a Unified Cloud Security Platform: The company provides a comprehensive solution designed to "supercharge" SOCs by centralizing cloud and SaaS security data and intelligence.
- Core Components for Clarity: Mitiga's platform is built on a distributed cloud security data lake, a cloud attack scenario library, an intuitive investigation workbench, and automated hunt logic.
- Faster, More Accurate Response: The platform enables SOC teams to detect and respond to cloud threats in minutes, not days, by providing rich context, clear alerts, and automated timeline construction.
- Empowering Generalist Analysts: Mitiga's tools reduce the need for deep cloud-specific expertise within the SOC, allowing analysts to conduct full cloud investigations across identity, cloud, and SaaS footprints.
- Proven Impact: Over 40 leading brands are already leveraging Mitiga to enhance their cloud threat response capabilities, demonstrating the platform's real-world effectiveness.
About the Speaker(s)
Ofer Maor is the Co-founder and CTO of Mitiga, a company focused on enhancing security operations for the cloud era. The presentation at RSAC 2024 highlighted his leadership in developing solutions for significant market problems. Maor's background suggests a strong entrepreneurial spirit and a proven track record of innovation within the cybersecurity industry, having previously demonstrated an ability to tackle complex challenges. He has also been instrumental in assembling an "elite team" at Mitiga, indicating a commitment to leveraging top-tier talent to drive the company's growth and mission. As CTO, Maor is responsible for the technological vision and development of Mitiga's platform, which aims to bridge the gap between cloud complexity and SOC team capabilities.