Eight chapters covering cloud security from the shared responsibility model through applied detection engineering: Azure AD/Entra ID and AWS IAM attack techniques, the telemetry sources that actually catch them, cloud-native threat hunting methodology, detection queries in KQL/SPL/Sigma, real-world threat actor campaigns, and the Zero Trust/CIEM/CSPM controls that reduce how often any of this becomes an active incident. Built for SOC analysts and detection engineers extending coverage beyond the endpoint.
No chapters match “”.
The shared responsibility model across IaaS/PaaS/SaaS, why the cloud attack surface has no fixed perimeter, and why identity becomes the control plane everything else depends on.
Password spray and legacy auth bypass, consent phishing and OAuth abuse, adversary-in-the-middle token theft, and conditional access bypass techniques.
IAM enumeration with a compromised key, S3 misconfiguration patterns, IAM privilege escalation paths, and the CloudTrail events that expose them.
CloudTrail management vs. data events, Entra sign-in and audit logs, VPC/NSG flow logs and DNS logging, and building a minimum viable logging baseline.
Adapting ABLE hypothesis generation to identity, control-plane, and network layers, and pivoting on identity when the infrastructure itself is ephemeral.
KQL against Entra sign-in and audit logs, Sigma rules for CloudTrail, SPL for Splunk-ingested CloudTrail, and tuning cloud detections against automation noise.
Scattered Spider's help-desk social engineering, Nobelium's federated trust abuse, and how ransomware operators target cloud backups for extortion leverage.
Zero Trust as continuous verification, CIEM for right-sizing entitlements, CSPM for catching configuration drift, and the hardening baseline that ties the module together.
WHAT YOU SHOULD KNOW
WHAT YOU WILL KNOW AFTER
H3AD-SEC tools that pair directly with this module's content.
ATT&CK-driven hypothesis platform. Build cloud-specific hunt hypotheses across identity, control-plane, and network layers using the ABLE framework covered in Chapter 5.
Detection rule library across KQL, Sigma, and XQL. Pull ready-made detection logic for the Entra and CloudTrail scenarios covered in Chapter 6.
Visual pivot graph for investigations. Map identity, resource, and API-caller relationships when the underlying cloud infrastructure is too ephemeral to examine directly.
Multi-source IOC analysis across VirusTotal, Shodan, OTX, and AbuseIPDB. Useful for scoring external infrastructure surfaced during cloud egress and exfiltration hunts.