logo

Shrinking the haystack: The six phases of cloud threat detection

ID: e32e28d2-a892-5760-9ad9-555296a86d0e

STIX ID: report--e32e28d2-a892-5760-9ad9-555296a86d0e

Feed Name: Red Canary

Date Published: 2025-01-08

Date Updated: 2026-04-29

Author: Brian Davis

...
...

This article explains how to detect threats in the cloud control plane (e.g., API abuse, unauthorized access, data exfiltration) by implementing a scalable six-phase pipeline: Ingest, Standardize, Combine, Detect, Suppress, and Respond. It details strategies for cost-effective telemetry ingestion and filtering, normalizing disparate logs (e.g., adopting OCSF), correlating events to build stateful context around principals and resources, and applying analytics to identify behavior patterns indicative of malicious activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.