Skip to content

Commit 2d0dea3

Browse files
committed
AWS attack disruption integration - aws links - Ofer, Christos
1 parent c9e4421 commit 2d0dea3

1 file changed

Lines changed: 3 additions & 3 deletions

File tree

articles/sentinel/aws-disruption.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -10,11 +10,11 @@ ms.topic: how-to
1010

1111
# Enable attack disruption actions on AWS with Microsoft Sentinel (preview)
1212

13-
This article describes how to configure your AWS environment so that Microsoft Sentinel can take automated actions on a user that assumes a SAML role, or on an AWS IAM account when an alert is triggered. Attack disruption uses high-confidence signals to contain compromised assets and limit the impact of attacks, including actions on identities in AWS.
13+
This article describes how to configure your AWS environment so that Microsoft Sentinel can take automated actions on a user that assumes a SAML role, or on an AWS IAM account when an alert is triggered. Attack disruption uses high-confidence signals to contain compromised assets and limit the damage from attacks, including actions on identities in AWS.
1414

1515
## Prerequisites
1616

17-
Before you begin, ensure the following:
17+
Before you begin, you need the following prerequisites in place:
1818

1919
- You have an active AWS account with administrative privileges.
2020
- Your Microsoft Sentinel analytic workspace is connected to the unified security operations portal.
@@ -29,7 +29,7 @@ Before you begin, ensure the following:
2929

3030
1. [Create a new IAM role](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_create.html) in the AWS Management Console.
3131

32-
- Select **AWS service** as the trusted entity and choose **EC2** (you'll update the trust relationship later).
32+
- Select **AWS service** as the trusted entity and choose **EC2** (you'll update the trust relationship [next](#12-configure-trust-relationship)).
3333

3434
- Attach the following policy to the role (replace \<YOUR_ACCOUNT_ID\> as needed):
3535

0 commit comments

Comments
 (0)