Skip to content
Cloud Security DeskSearch
Menu

Evidence search

Search

Search titles, summaries, topics, providers, authors, and the full open-access corpus.

Results for “detection coverage”

7 publications
Technical guideSource-based analysis

Move cloud logs to cheaper tiers without losing detection coverage

CloudWatch Infrequent Access, the Sentinel data lake and Cloud Logging exclusions all cut ingestion cost by removing real-time detection hooks. Place each source by the rules that read it, then prove the replacements fire.

Detection & response · AWS / Microsoft Azure / Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Get an alert when Google Cloud project access changes

Build a Google Cloud log-based alert for project IAM changes, verify the filter and notification channel, and understand incident limits.

Detection & response · Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Triage a Google Cloud Security Command Center finding

Review a Security Command Center finding, choose repair or a documented exception, and distinguish resource verification from muting and closure.

Detection & response · Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Read VPC Flow Logs without overclaiming network evidence

Interpret aggregation, address translation, skipped records and delivery clocks before turning a VPC flow record into an incident conclusion.

Detection & response · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Testing Sigma detections before a backend change

Keep rule structure, field transformations, query conversion and event matching as separate checks when changing a Sigma detection backend.

Detection & response · SigmaHQ · By Cloud Security Desk
Technical guideSource-based analysis

Turn SBOM and VEX records into patch decisions

A VEX statement is an assertion about a specific product and vulnerability. Match its scope and conditions before using it to suppress a finding.

Workload security · CISA / OpenVEX / CycloneDX / OASIS · By Cloud Security Desk
Technical guideSource-based analysis

Cloud detection coverage after the ATT&CK data model change

Connect current ATT&CK strategies and analytics to available events, implemented rules and test evidence, while keeping taxonomy counts separate from protection.

Detection & response · MITRE · By Cloud Security Desk