Your SOC should have detection rules for every system that can move money.
Starting today,
@dfnsHQ can export its audit trail to your SIEM, starting with
@datadoghq Cloud SIEM đ
Privileged action signed on DFNS, like moving funds, exporting a key, changing a user, a policy, or an access control, arrives in your security operations as a structured log the moment it resolves.
It will show you: đŽđšđšđŧđđ˛đą, đąđ˛đģđļđ˛đą, or đŗđŽđļđšđ˛đą. This includes the attempts, such as a transfer signed and denied by policy. The type of signal that reveals stolen credentials or insider testing limits...
What your SOC can now do with it:
â ī¸ Alert on any key export, anywhere, instantly
â ī¸ Flag policy changes outside the change window
â ī¸ Catch a spike in denied actions from one user
â ī¸ Surface a transfer at 3am from someone who's never operated at night
â ī¸ Correlate a DFNS action with the same user's suspicious IdP login 20 minutes earlier
đĄī¸ We built SIEM Export like a security control. It never blocks the action it observes, but instead runs on an isolated channel so a SIEM outage can't touch your webhooks. Your API key is encrypted and never logged.
When your analysts see something, DFNS can:
â suspend an Org
â revoke a User
â tighten a Policy
â deny a Wallet
Your SIEM also holds an independent copy of the record, in your domain. Even if DFNS itself were ever compromised, your SOC keeps the history.
That's what onchain core banking is for.
đ Read the announcement:
â¨ī¸ Start building today: