
AWS에서 페타바이트 규모의 위협 헌팅, 탐지 및 대응, 사이버 보안 분석을 위한 오픈 소스 보안 데이터 레이크
Matano 오픈소스 보안 데이터 레이크는 AWS상의 보안 팀을 위해 구축된 오픈소스 클라우드 네이티브 보안 데이터 레이크입니다.
[!NOTE] Matano는 완전한 엔터프라이즈 보안 운영 플랫폼을 위한 상용 관리형 Cloud SIEM을 제공합니다. 자세히 알아보기.
Matano CLI를 설치하여 AWS 계정에 Matano를 배포하고 배포를 관리합니다.
Linux```bash curl -OL https://github.com/matanolabs/matano/releases/download/nightly/matano-linux-x64.sh chmod +x matano-linux-x64.sh sudo ./matano-linux-x64.sh
**macOS**```bash
curl -OL https://github.com/matanolabs/matano/releases/download/nightly/matano-macos-x64.sh
chmod +x matano-macos-x64.sh
sudo ./matano-macos-x64.sh
시작하려면 matano init 명령어를 실행하세요.
초기화가 완료되면 Matano 디렉토리를 사용하여 프로젝트의 모든 리소스(예: 로그 소스, 탐지 규칙 및 기타 구성)를 제어하고 관리할 수 있습니다. 디렉토리 구조는 다음과 같습니다:```bash ➜ example-matano-dir git:(main) tree ├── detections │ └── aws_root_credentials │ ├── detect.py │ └── detection.yml ├── log_sources │ ├── cloudtrail │ │ ├── log_source.yml │ │ └── tables │ │ └── default.yml │ └── zeek │ ├── log_source.yml │ └── tables │ └── dns.yml ├── matano.config.yml └── matano.context.json
When onboarding a new log source or authoring a detection, run `matano deploy` from anywhere in your project to deploy the changes to your account.
## 🔧 로그 변환 및 데이터 정규화
[**커스텀 로그 소스 구성에 대한 전체 문서 읽기**](https://www.matano.dev/docs/log-sources/configuration)