Research topic
Detection & response
A detection is only as complete as its evidence path.
Practical analysis of cloud telemetry, detection coverage, investigation quality, and recovery readiness.
View every topicFrom the desk
26 publicationsChoose and verify CloudWatch Logs retention
Choose CloudWatch Logs retention from supported values, verify the saved setting, and account for delayed deletion, archives, and log-group ownership.
Make CloudWatch alarms handle missing data correctly
Choose how CloudWatch alarms treat missing data, understand evaluation surprises, test notifications, and preserve useful alarm evidence.
Get an alert when Google Cloud project access changes
Build a Google Cloud log-based alert for project IAM changes, verify the filter and notification channel, and understand incident limits.
Triage a Google Cloud Security Command Center finding
Review a Security Command Center finding, choose repair or a documented exception, and distinguish resource verification from muting and closure.
Get an Azure alert when a role assignment changes
Detect successful RBAC changes and test alert delivery without expanding a production role.
Find why an Azure VM cannot reach a service
Use a specific source and destination with Network Watcher and separate network reachability from app health.
Keep Kubernetes audit records useful without logging secrets
Design a question-led Kubernetes audit policy with explicit body limits, rule precedence, lifecycle stages and provider-specific acceptance checks.
Read VPC Flow Logs without overclaiming network evidence
Interpret aggregation, address translation, skipped records and delivery clocks before turning a VPC flow record into an incident conclusion.
Catch late security events without replaying every alert
Separate event time, ingestion time and execution health so delayed records can be evaluated without turning every broader lookback into a replay.
Find the Purview audit history your investigation can still retrieve
Resolve Purview audit availability at the record level by separating actor eligibility, retention policy, collection status, investigator scope and export limits.
Investigate denied access at an AWS VPC endpoint
Use CloudTrail network activity evidence to distinguish endpoint-policy violations from routing failures and downstream authorization problems.
Keep GitHub audit streaming continuous across maintenance
Plan audit-stream maintenance around native history, pause buffers, receiver acceptance and duplicate-aware evidence receipts.
A defensible cloud patch queue starts with exploitation evidence
Join exploitation evidence to affected assets, exposure, ownership and verified remediation without turning CVSS, EPSS or a catalog entry into a complete risk score.
What cloud snapshots cannot preserve
Separate live execution, persisted disk and provider records before an authorized containment decision destroys evidence that a snapshot cannot recover.
Testing Sigma detections before a backend change
Keep rule structure, field transformations, query conversion and event matching as separate checks when changing a Sigma detection backend.
Cloud incident severity needs a service impact model
Connect incident priority to service consequences, scope and time criticality while preserving evidence confidence and the authority to revise the decision.
The telemetry collector is part of the evidence boundary
Review sender identity, tenant routing, processing and export as separate trust boundaries before treating collected telemetry as dependable evidence.
Cloud detection coverage after the ATT&CK data model change
Connect current ATT&CK strategies and analytics to available events, implemented rules and test evidence, while keeping taxonomy counts separate from protection.
Build an Azure change record that survives the portal window
Activity Log records and resource logs answer different questions. Preserve the operation outcome, resource context and export scope needed for a later investigation.
Measure GuardDuty runtime coverage from the resource outward
An enabled protection plan does not describe the health of every workload. Review supported resources, agents, connectivity and the denominator behind coverage.
Find the Google audit logs missing from your evidence window
Audit category, inherited configuration, destination and reader permissions all affect what an investigator can retrieve. Retention is only one part of the record.
Investigate an Entra application through grants and sign-ins
A successful service-principal sign-in is one event in a larger sequence. Connect it to credential changes, permission grants and the resource involved.
Verify the CloudTrail files behind an incident timeline
Digest delivery and successful validation are different evidence states. Preserve the files, metadata and validation result needed to distinguish them.
Choose the S3 object events your investigation will need
CloudTrail event history is not an object-access ledger. Build selectors around the questions an investigation must answer, then test the exclusions.
Questions answered
What does Cloud Security Desk cover under Detection & response?
Practical analysis of cloud telemetry, detection coverage, investigation quality, and recovery readiness.
Supporting context
A detection is only as complete as its evidence path.
Why does the detection & response topic matter to cloud security?
A detection is only as complete as its evidence path. This topic applies that principle to practical control evidence and review decisions.
Which control questions belong to Detection & response?
Research belongs here when its central evidence, failure mode, or operational decision falls within the detection & response boundary described on this page.
How many detection & response publications are available?
This page currently lists 26 publications assigned to Detection & response.
How should readers use the Detection & response research?
Start with the publication closest to the control, platform, or evidence gap under review, then follow its findings, limitations, numbered sources, related work, and downloadable material.
Can detection & response overlap other research topics?
Yes. A publication can appear under several topics when one evidence path crosses multiple control boundaries; each publication page identifies its complete scope.
Supporting context