Cloud-Specific Hunts
Threat hunts tailored to cloud environments, searching cloud telemetry, identity, control-plane, and network logs, for cloud-specific adversary behaviors like credential abuse, privilege escalation, and resource hijacking that on-premises hunts would miss.
Concept Neighborhood
Explore this concept’s connections in the groups below.
Start here
Hunt Hypothesis
The foundation Cloud-Specific Hunts builds on, worth understanding first.
Hunt HypothesisStart here
A specific, testable statement of what malicious activity might be present and how it would show up in data, that drives a threat hunt, giving it a clear question to investigate rather than aimless searching.
12
lessons
Cloud Hunting Data Sources
The telemetry a threat hunter draws on to hunt in cloud environments, such as control-plane and audit logs, identity sign-in logs, network flow logs, and managed detection findings. They are the raw material for cloud hunts.
6
lessons
Related Lessons
1 lesson covers this conceptSign in to open lesson content directly.
