# cloud siem

Published articles for cloud siem.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Centralize human and agentic work with Datadog Work Management

DevFeed: [Centralize human and agentic work with Datadog Work Management](<https://devfeed.tech/articles/centralize-human-and-agentic-work-with-datadog-work-management-2319.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/work-management/>)

Author: Roxanne Moslehi

Published: 2026-08-18T00:00:00Z

Content type: article

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [incident](<https://devfeed.tech/topics/incident.md>), [site-reliability-engineering](<https://devfeed.tech/topics/site-reliability-engineering.md>), [Slack](<https://devfeed.tech/topics/slack.md>), [SRE](<https://devfeed.tech/topics/sre.md>), [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [error tracking](<https://devfeed.tech/topics/error-tracking.md>), [dashboards](<https://devfeed.tech/topics/dashboards.md>), [Traces](<https://devfeed.tech/topics/traces.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [cloud-siem](<https://devfeed.tech/tags/cloud-siem.md>), [dashboards](<https://devfeed.tech/tags/dashboards.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [error-tracking](<https://devfeed.tech/tags/error-tracking.md>), [github](<https://devfeed.tech/tags/github.md>), [incident](<https://devfeed.tech/tags/incident.md>), [management](<https://devfeed.tech/tags/management.md>), [slack](<https://devfeed.tech/tags/slack.md>), [sre](<https://devfeed.tech/tags/sre.md>), [traces](<https://devfeed.tech/tags/traces.md>), [work-management](<https://devfeed.tech/tags/work-management.md>), [workflow-automation](<https://devfeed.tech/tags/workflow-automation.md>)

### AI overview

Datadog Work Management centralizes work created by people, automations, and Datadog AI agents. It preserves context from logs, traces, monitors, alerts, ownership, assignments, approvals, artifacts, and activity while integrating with Datadog and external collaboration systems.

### Source excerpt

Learn how Datadog Work Management helps you coordinate human and AI agent-driven work while preserving context, ownership, and activity across tools.

## How to manage risk from unfixed Kubernetes CVEs

DevFeed: [How to manage risk from unfixed Kubernetes CVEs](<https://devfeed.tech/articles/how-to-manage-risk-from-unfixed-kubernetes-cves-2281.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/how-to-manage-unfixed-kubernetes-cves/>)

Author: Mallory Mooney

Published: 2026-08-10T00:00:00Z

Content type: tutorial

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [Amazon Elastic Kubernetes Service](<https://devfeed.tech/topics/amazon-elastic-kubernetes-service.md>)

Tags: [cloud-siem](<https://devfeed.tech/tags/cloud-siem.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [logs](<https://devfeed.tech/tags/logs.md>), [security](<https://devfeed.tech/tags/security.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

The article explains how to assess exposure to four unfixed Kubernetes CVEs and use audit-log detection queries to investigate relevant activity.

### Source excerpt

Learn how to confirm whether your cluster is exposed to unfixed Kubernetes CVEs and build detection queries using Kubernetes audit logs.

## Investigate every security event with an AI agent, without the frontier bill

DevFeed: [Investigate every security event with an AI agent, without the frontier bill](<https://devfeed.tech/articles/investigate-every-security-event-with-an-ai-agent-without-the-frontier-bill-2230.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/ai/ai-security-detection-pipeline/>)

Author: Nicolas Grislain

Published: 2026-07-28T00:00:00Z

Content type: article

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [AI Bots](<https://devfeed.tech/topics/ai-bots.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [ai-research](<https://devfeed.tech/tags/ai-research.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [bits-ai](<https://devfeed.tech/tags/bits-ai.md>), [cloud-siem](<https://devfeed.tech/tags/cloud-siem.md>), [llm](<https://devfeed.tech/tags/llm.md>), [logs](<https://devfeed.tech/tags/logs.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Datadog describes a two-stage security detection pipeline in which Mambark scores audit-log events and routes only the most suspicious ones to an AI agent for deeper investigation.

### Source excerpt

Learn how Datadog built Mambark, a small state-space model that scores every security event and enables heavier AI agents to investigate only the events that matter.

## Entra Agent ID: Protect, detect, respond

DevFeed: [Entra Agent ID: Protect, detect, respond](<https://devfeed.tech/articles/entra-agent-id-protect-detect-respond-8270.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/agent-id-protect-detect-respond/>)

Author: Katie Knowles

Published: 2026-07-06T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [Entra ID](<https://devfeed.tech/topics/entra-id.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [agents](<https://devfeed.tech/tags/agents.md>), [cloud-siem](<https://devfeed.tech/tags/cloud-siem.md>), [entra-id](<https://devfeed.tech/tags/entra-id.md>), [identity](<https://devfeed.tech/tags/identity.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This concluding article in the Agent ID series explains how administrators and security teams can protect Entra agent blueprints and identities, detect suspicious activity, and respond to compromises. It recommends limiting privileged roles and permissions, reducing reliance on secrets, reviewing third-party blueprints, monitoring agent activity, and disabling or deleting compromised identities or blueprints.

### Source excerpt

This post continues and concludes our series on Agent ID, by outlining steps that an administrator or security team can take to secure blueprints and agent identities created in their local Entra ID tenant.

## Preparing for OMB M-26-14: How Datadog supports federal logging maturity

DevFeed: [Preparing for OMB M-26-14: How Datadog supports federal logging maturity](<https://devfeed.tech/articles/preparing-for-omb-m-26-14-how-datadog-supports-federal-logging-maturity-2302.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/omb-m-26-14-federal-logging-maturity/>)

Author: Chris Leffler; Sophie Wang

Published: 2026-06-29T00:00:00Z

Content type: article

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>), [log management](<https://devfeed.tech/topics/log-management.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>), [observability](<https://devfeed.tech/topics/observability.md>), [Security](<https://devfeed.tech/topics/security.md>), [Security Operations Center](<https://devfeed.tech/topics/security-operations-center.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [bits-ai](<https://devfeed.tech/tags/bits-ai.md>), [cloud-siem](<https://devfeed.tech/tags/cloud-siem.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [govcloud](<https://devfeed.tech/tags/govcloud.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [log-management](<https://devfeed.tech/tags/log-management.md>), [logging](<https://devfeed.tech/tags/logging.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [observability](<https://devfeed.tech/tags/observability.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [security](<https://devfeed.tech/tags/security.md>), [security-operations-center](<https://devfeed.tech/tags/security-operations-center.md>), [soc](<https://devfeed.tech/tags/soc.md>), [systems](<https://devfeed.tech/tags/systems.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>), [workflow-automation](<https://devfeed.tech/tags/workflow-automation.md>)

### AI overview

This article explains how OMB Memorandum M-26-14 changes federal logging guidance from prescriptive requirements to a risk- and maturity-based model. It describes continuous event monitoring and threat hunting, investigation, response, and forensics, including centralized security telemetry, visibility across IT, OT, and IoT environments, threat detection, searchable and retrievable logs, cross-source correlation, incident response, and forensic analysis. It also presents Datadog as a unified observability and security platform for helping agencies meet these requirements.

### Source excerpt

Learn how Datadog helps federal agencies prepare for OMB M-26-14 by providing centralized telemetry data, threat detection, and automated incident response.

## Automatically enrich security logs with MITRE ATT&CK context before they reach your SIEM

DevFeed: [Automatically enrich security logs with MITRE ATT&CK context before they reach your SIEM](<https://devfeed.tech/articles/automatically-enrich-security-logs-with-mitre-att-ck-context-before-they-reach-your-siem-2291.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/mitre-attack-enrichment-packs-observability-pipelines/>)

Author: Danielle Park

Published: 2026-06-24T00:00:00Z

Content type: article

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [observability pipelines](<https://devfeed.tech/topics/observability-pipelines.md>), [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>), [log management](<https://devfeed.tech/topics/log-management.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>), [Threat Hunting & Intel](<https://devfeed.tech/topics/threat-hunting-intel.md>), [Firewall](<https://devfeed.tech/topics/firewall.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [aws](<https://devfeed.tech/tags/aws.md>), [cloud-siem](<https://devfeed.tech/tags/cloud-siem.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [incident](<https://devfeed.tech/tags/incident.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [log-management](<https://devfeed.tech/tags/log-management.md>), [logs](<https://devfeed.tech/tags/logs.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [network](<https://devfeed.tech/tags/network.md>), [observability](<https://devfeed.tech/tags/observability.md>), [observability-pipelines](<https://devfeed.tech/tags/observability-pipelines.md>), [security](<https://devfeed.tech/tags/security.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>)

### AI overview

This article explains how Observability Pipelines uses MITRE ATT&CK Enrichment Packs to automatically map security logs and events to common attacker tactics and techniques before they reach a SIEM, data lake, or archive. It describes the initial packs for Okta, Palo Alto, FortiGate, and AWS WAF, covering identity, firewall, network, and web security activity.

### Source excerpt

Learn how Observability Pipelines enriches security logs with MITRE ATT&CK tactics and techniques before routing them to your SIEM or storage destination.

## Detecting the Klue supply chain attack in Salesforce instances

DevFeed: [Detecting the Klue supply chain attack in Salesforce instances](<https://devfeed.tech/articles/detecting-the-klue-supply-chain-attack-in-salesforce-instances-8286.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/detecting-the-klue-supply-chain-attack-in-salesforce/>)

Author: Julie Agnes Sparks

Published: 2026-06-22T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [REST API](<https://devfeed.tech/topics/rest-api.md>), [OAuth](<https://devfeed.tech/topics/oauth.md>), [API](<https://devfeed.tech/topics/api.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Python](<https://devfeed.tech/topics/python.md>), [data](<https://devfeed.tech/topics/data.md>), [Back end](<https://devfeed.tech/topics/backend.md>), [Network](<https://devfeed.tech/topics/network.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [backend](<https://devfeed.tech/tags/backend.md>), [cloud-siem](<https://devfeed.tech/tags/cloud-siem.md>), [data](<https://devfeed.tech/tags/data.md>), [external](<https://devfeed.tech/tags/external.md>), [incident](<https://devfeed.tech/tags/incident.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [integration](<https://devfeed.tech/tags/integration.md>), [logs](<https://devfeed.tech/tags/logs.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [python](<https://devfeed.tech/tags/python.md>), [rest-api](<https://devfeed.tech/tags/rest-api.md>), [salesforce](<https://devfeed.tech/tags/salesforce.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [tokens](<https://devfeed.tech/tags/tokens.md>)

### AI overview

This article summarizes the Klue supply chain attack, in which a threat actor abused a dormant integration credential to obtain OAuth tokens and query connected Salesforce environments through automated Python REST API calls. It reconstructs the attack timeline and provides detection guidance for Salesforce environments monitored by Datadog Cloud SIEM.

### Source excerpt

We summarize the Klue supply chain attack and provide detection guidance for Salesforce environments monitored by Datadog Cloud SIEM.

## Automate threat hunting with Datadog Cloud SIEM

DevFeed: [Automate threat hunting with Datadog Cloud SIEM](<https://devfeed.tech/articles/automate-threat-hunting-with-datadog-cloud-siem-2237.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/bits-threat-hunting/>)

Author: Vera Chan; Sean Storer

Published: 2026-06-09T00:00:00Z

Content type: article

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [AI Bots](<https://devfeed.tech/topics/ai-bots.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [ai](<https://devfeed.tech/tags/ai.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [autonomous](<https://devfeed.tech/tags/autonomous.md>), [cloud-siem](<https://devfeed.tech/tags/cloud-siem.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [logs](<https://devfeed.tech/tags/logs.md>), [security](<https://devfeed.tech/tags/security.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>)

### AI overview

Datadog introduces Bits Threat Hunting, an autonomous Cloud SIEM agent that performs AI-driven, hypothesis-based searches of telemetry to identify attacker behavior and deviations before alerts fire.

### Source excerpt

Learn how Bits Threat Hunting helps security teams proactively identify attacker behavior with AI-driven, hypothesis-based threat hunting.

## DASH 2026 Security & Compliance: Guide to Datadog's newest announcements

DevFeed: [DASH 2026 Security & Compliance: Guide to Datadog's newest announcements](<https://devfeed.tech/articles/dash-2026-security-compliance-guide-to-datadog-s-newest-announcements-2251.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/dash-2026-new-feature-roundup-secure/>)

Author: Datadog

Published: 2026-06-09T00:00:00Z

Content type: news

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>), [MCP](<https://devfeed.tech/topics/mcp.md>), [Securing AI](<https://devfeed.tech/topics/securing-ai.md>), [MCP Server](<https://devfeed.tech/topics/mcp-server.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Routing (disambiguation)](<https://devfeed.tech/topics/routing.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [announcements](<https://devfeed.tech/tags/announcements.md>), [api](<https://devfeed.tech/tags/api.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [claude](<https://devfeed.tech/tags/claude.md>), [claude-code](<https://devfeed.tech/tags/claude-code.md>), [cloud-siem](<https://devfeed.tech/tags/cloud-siem.md>), [codex](<https://devfeed.tech/tags/codex.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cursor](<https://devfeed.tech/tags/cursor.md>), [dash](<https://devfeed.tech/tags/dash.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [mcp-server](<https://devfeed.tech/tags/mcp-server.md>), [openai](<https://devfeed.tech/tags/openai.md>), [security](<https://devfeed.tech/tags/security.md>), [slack](<https://devfeed.tech/tags/slack.md>), [sql](<https://devfeed.tech/tags/sql.md>), [ticketing](<https://devfeed.tech/tags/ticketing.md>)

### AI overview

A roundup of Datadog security and compliance announcements presented at DASH, covering AI-assisted investigation and remediation across code, cloud, APIs, and sensitive data. It highlights expanded SIEM capabilities, the Security MCP toolset for governed AI-agent access, and dynamic routing of security notifications to team channels.

### Source excerpt

A roundup of everything we announced at DASH 2025, including Datadog's new API authentication model, Bits AI Threat Hunting for Cloud SIEM, and Bits AI Security Analyst.