Coverage may include control planes, identities, workloads, containers, orchestration, networks, storage, data access, and software-as-a-service applications, but implementations vary widely.
CDR correlates administrative API calls, authentication events, configuration changes, runtime activity, network observations, and provider alerts. Analysts use cloud-resource relationships and identity context to reconstruct events and select responses such as revoking a session, disabling a key, restricting a workload, preserving evidence, or rebuilding a resource.
Key points
Detection coverageMap cloud attack techniques to available events, assets, identities, accounts, and services. Validate that logging is enabled, timely, correctly parsed, retained, and protected.
InvestigationPreserve provider and workload evidence, correlate identities with ephemeral resources, distinguish automation from misuse, and determine affected data and dependencies.
Controlled responsePre-authorize low-risk actions where appropriate, require approval for disruptive changes, use least-privileged response identities, and test containment, rollback, recovery, and provider escalation.
Important limitationCDR has no standardized minimum coverage and cannot detect what services, identities, workloads, or events do not expose. Missing logs, short-lived resources, encrypted activity, outages, weak detections, and unsafe automation can cause misses or harm; an alert is evidence, not proof of compromise.