Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Detection & Response

Articles in Detection & Response.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
AWSDetection & Response

Detecting Cryptojacking in Cloud: CloudTrail, GuardDuty and Athena Queries

Cryptojacking — using stolen cloud resources to mine cryptocurrency — is one of the most common outcomes of a cloud compromise. It is also one of the most...

Multi-CloudDetection & Response

Patch Verification Queries for CPU Vulnerabilities Across Azure and AWS VMs

Hardware vulnerabilities like Meltdown and Spectre are hard to detect being exploited. The practical detection task is making sure every system actually...

AWSDetection & Response

Detecting Leaked AWS Access Keys: CloudTrail, GuardDuty and Athena Queries

Leaked AWS access keys are often used within minutes of exposure. Detecting misuse quickly limits how much an attacker can do.

AWSDetection & Response

Detecting S3 Misconfiguration: CloudTrail, GuardDuty and Athena Queries

Most S3 misconfigurations begin with a configuration change. Monitoring those changes in near real time catches exposures within minutes rather than months.

Multi-CloudDetection & Response

Detecting Unpatched Web Application Exploitation: Sentinel and GuardDuty Detections

Exploitation of public-facing web applications is one of the most common ways attackers get in. Detecting exploitation attempts — and especially successful...

Microsoft 365Detection & Response

Detecting Compromised Admin Account: Defender XDR and Sentinel Hunting Queries

Compromised administrator accounts give attackers control of an entire Microsoft 365 tenant. Detecting unusual admin behavior early is one of the...

AWSDetection & Response

Detecting S3 Bucket Policy Misconfiguration: CloudTrail, GuardDuty and Athena Queries

Overly broad bucket policies are a frequent root cause of S3 exposures. Detecting policy changes that widen access — and catching risky policies already in...

AzureDetection & Response

Detecting Credential Theft Lateral Movement: Defender for Cloud and Sentinel KQL

NotPetya combined credential theft with legitimate admin tools to move across networks. Detecting that pattern early is one of the most effective ways to...

AWSDetection & Response

Detecting Public S3 Bucket Access: CloudTrail, GuardDuty and Athena Queries

The best time to catch a public S3 bucket is the moment it becomes public. Detection rules on configuration changes close the window between a mistake and...

AzureDetection & Response

Detecting SMBv1 Exploitation: Defender for Cloud and Sentinel KQL

WannaCry and its successors exploited SMB flaws to spread across networks. Even with SMBv1 removed, detecting suspicious SMB activity is a valuable early...

Multi-CloudDetection & Response

Detecting Leaked Session Tokens: Sentinel and GuardDuty Detections

When a provider leaks session tokens, the question is whether anyone used them. Detection focuses on sessions that look valid but behave differently from...

Entra ID & IdentityDetection & Response

Detecting Credential Stuffing Attacks: Entra Sign-In Logs and Sentinel KQL

Credential stuffing uses username and password pairs leaked from other breaches to try to sign in to your Microsoft 365 tenant. Detection is about spotting...

Multi-CloudDetection & Response

Detecting DNS DDoS Attacks: Sentinel and GuardDuty Detections

DDoS attacks against DNS and web front ends are noisy, which makes them easy to notice and hard to diagnose quickly. The goal of detection is speed: confirm...

← NewerPage 4 of 4
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.