Cloud Detection
Identifying malicious or anomalous activity in a cloud environment by analyzing control-plane logs, identity events, network flows, and managed threat-detection services. It focuses on the signals unique to cloud, especially identity and API abuse.
Concept Neighborhood
Start here
Audit Log Analysis
The foundation Cloud Detection builds on, worth understanding first.
Cloud Containment
The actions taken to stop an active cloud incident from spreading, using cloud-native controls, such as isolating a workload, revoking credentials and sessions, restricting a resource's network access, or quarantining an account.
1
lesson
Detection Automation
Automating cloud detection and the response to it, so that suspicious activity is identified and acted on, alerting, enriching, or even containing, without waiting for manual intervention, reducing the time attackers have to operate.
1
lesson
Related Lessons
1 lesson covers this conceptSign in to open lesson content directly.
