Skip to content
Cloud Security DeskSearch
Menu

Research topic

Detection & response

A detection is only as complete as its evidence path.

26 publications

Practical analysis of cloud telemetry, detection coverage, investigation quality, and recovery readiness.

View every topic

From the desk

26 publications
Technical guide · September 12, 2026 · Source-based analysis

Choose and verify CloudWatch Logs retention

Choose CloudWatch Logs retention from supported values, verify the saved setting, and account for delayed deletion, archives, and log-group ownership.

Technical guide · September 12, 2026 · Source-based analysis

Make CloudWatch alarms handle missing data correctly

Choose how CloudWatch alarms treat missing data, understand evaluation surprises, test notifications, and preserve useful alarm evidence.

Technical guide · September 12, 2026 · Source-based analysis

Get an alert when Google Cloud project access changes

Build a Google Cloud log-based alert for project IAM changes, verify the filter and notification channel, and understand incident limits.

Technical guide · September 12, 2026 · Source-based analysis

Triage a Google Cloud Security Command Center finding

Review a Security Command Center finding, choose repair or a documented exception, and distinguish resource verification from muting and closure.

Technical guide · September 12, 2026 · Source-based analysis

Get an Azure alert when a role assignment changes

Detect successful RBAC changes and test alert delivery without expanding a production role.

Technical guide · September 12, 2026 · Source-based analysis

Find why an Azure VM cannot reach a service

Use a specific source and destination with Network Watcher and separate network reachability from app health.

Technical guide · September 2, 2026 · Source-based analysis

Keep Kubernetes audit records useful without logging secrets

Design a question-led Kubernetes audit policy with explicit body limits, rule precedence, lifecycle stages and provider-specific acceptance checks.

Technical guide · September 2, 2026 · Source-based analysis

Read VPC Flow Logs without overclaiming network evidence

Interpret aggregation, address translation, skipped records and delivery clocks before turning a VPC flow record into an incident conclusion.

Technical guide · September 2, 2026 · Source-based analysis

Catch late security events without replaying every alert

Separate event time, ingestion time and execution health so delayed records can be evaluated without turning every broader lookback into a replay.

Technical guide · September 2, 2026 · Source-based analysis

Find the Purview audit history your investigation can still retrieve

Resolve Purview audit availability at the record level by separating actor eligibility, retention policy, collection status, investigator scope and export limits.

Technical guide · September 2, 2026 · Source-based analysis

Investigate denied access at an AWS VPC endpoint

Use CloudTrail network activity evidence to distinguish endpoint-policy violations from routing failures and downstream authorization problems.

Technical guide · September 2, 2026 · Source-based analysis

Keep GitHub audit streaming continuous across maintenance

Plan audit-stream maintenance around native history, pause buffers, receiver acceptance and duplicate-aware evidence receipts.

Technical guide · August 28, 2026 · Source-based analysis

A defensible cloud patch queue starts with exploitation evidence

Join exploitation evidence to affected assets, exposure, ownership and verified remediation without turning CVSS, EPSS or a catalog entry into a complete risk score.

Technical guide · August 28, 2026 · Source-based analysis

What cloud snapshots cannot preserve

Separate live execution, persisted disk and provider records before an authorized containment decision destroys evidence that a snapshot cannot recover.

Technical guide · August 28, 2026 · Source-based analysis

Testing Sigma detections before a backend change

Keep rule structure, field transformations, query conversion and event matching as separate checks when changing a Sigma detection backend.

Technical guide · August 28, 2026 · Source-based analysis

Cloud incident severity needs a service impact model

Connect incident priority to service consequences, scope and time criticality while preserving evidence confidence and the authority to revise the decision.

Technical guide · August 28, 2026 · Source-based analysis

The telemetry collector is part of the evidence boundary

Review sender identity, tenant routing, processing and export as separate trust boundaries before treating collected telemetry as dependable evidence.

Technical guide · August 28, 2026 · Source-based analysis

Cloud detection coverage after the ATT&CK data model change

Connect current ATT&CK strategies and analytics to available events, implemented rules and test evidence, while keeping taxonomy counts separate from protection.

Technical guide · Published August 28, 2026 · Source-based analysisSeries August 2, 2026

Build an Azure change record that survives the portal window

Activity Log records and resource logs answer different questions. Preserve the operation outcome, resource context and export scope needed for a later investigation.

Technical guide · Published August 28, 2026 · Source-based analysisSeries June 23, 2026

Measure GuardDuty runtime coverage from the resource outward

An enabled protection plan does not describe the health of every workload. Review supported resources, agents, connectivity and the denominator behind coverage.

Research note · Published August 28, 2026 · Source-based analysisSeries May 14, 2026

Find the Google audit logs missing from your evidence window

Audit category, inherited configuration, destination and reader permissions all affect what an investigator can retrieve. Retention is only one part of the record.

Technical guide · Published August 28, 2026 · Source-based analysisSeries April 4, 2026

Investigate an Entra application through grants and sign-ins

A successful service-principal sign-in is one event in a larger sequence. Connect it to credential changes, permission grants and the resource involved.

Technical guide · Published August 28, 2026 · Source-based analysisSeries February 23, 2026

Verify the CloudTrail files behind an incident timeline

Digest delivery and successful validation are different evidence states. Preserve the files, metadata and validation result needed to distinguish them.

Technical guide · Published August 28, 2026 · Source-based analysisSeries January 14, 2026

Choose the S3 object events your investigation will need

CloudTrail event history is not an object-access ledger. Build selectors around the questions an investigation must answer, then test the exclusions.

Questions answered

  1. What does Cloud Security Desk cover under Detection & response?

    Practical analysis of cloud telemetry, detection coverage, investigation quality, and recovery readiness.

    Supporting context

    A detection is only as complete as its evidence path.

  2. Why does the detection & response topic matter to cloud security?

    A detection is only as complete as its evidence path. This topic applies that principle to practical control evidence and review decisions.

  3. Which control questions belong to Detection & response?

    Research belongs here when its central evidence, failure mode, or operational decision falls within the detection & response boundary described on this page.

  4. How many detection & response publications are available?

    This page currently lists 26 publications assigned to Detection & response.

  5. How should readers use the Detection & response research?

    Start with the publication closest to the control, platform, or evidence gap under review, then follow its findings, limitations, numbered sources, related work, and downloadable material.

  6. Can detection & response overlap other research topics?

    Yes. A publication can appear under several topics when one evidence path crosses multiple control boundaries; each publication page identifies its complete scope.

    Supporting context