# What is Cloud Detection and Response (CDR)?

> Cloud detection and response (CDR) is a non-standard industry label for capabilities and practices that use cloud-specific telemetry to detect suspicious activity, investigate its scope, and take or guide response actions.

- Canonical URL: https://yellowcube.eu/glossary/cloud-detection-and-response/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Coverage may include control planes, identities, workloads, containers, orchestration, networks, storage, data access, and software-as-a-service applications, but implementations vary widely.

CDR correlates administrative API calls, authentication events, configuration changes, runtime activity, network observations, and provider alerts. Analysts use cloud-resource relationships and identity context to reconstruct events and select responses such as revoking a session, disabling a key, restricting a workload, preserving evidence, or rebuilding a resource.

### Key points

- **Detection coverage:** Map cloud attack techniques to available events, assets, identities, accounts, and services. Validate that logging is enabled, timely, correctly parsed, retained, and protected.
- **Investigation:** Preserve provider and workload evidence, correlate identities with ephemeral resources, distinguish automation from misuse, and determine affected data and dependencies.
- **Controlled response:** Pre-authorize low-risk actions where appropriate, require approval for disruptive changes, use least-privileged response identities, and test containment, rollback, recovery, and provider escalation.
- **Important limitation:** CDR has no standardized minimum coverage and cannot detect what services, identities, workloads, or events do not expose. Missing logs, short-lived resources, encrypted activity, outages, weak detections, and unsafe automation can cause misses or harm; an alert is evidence, not proof of compromise.

### Related terms

[Cloud security](<https://yellowcube.eu/glossary/cloud-security/>) · [Security telemetry](<https://yellowcube.eu/glossary/security-telemetry/>) · [Incident response (IR)](<https://yellowcube.eu/glossary/incident-response/>) · [Extended detection and response (XDR)](<https://yellowcube.eu/glossary/extended-detection-and-response/>) · [Cloud workload protection platform (CWPP)](<https://yellowcube.eu/glossary/cloud-workload-protection-platform/>)

### Sources

[NIST SP 800-61 Rev. 3: Incident Response Recommendations](https://csrc.nist.gov/pubs/sp/800/61/r3/final) · [MITRE ATT&CK: Cloud platforms in the Enterprise matrix](https://attack.mitre.org/matrices/enterprise/cloud/) · [Cloud Security Alliance: The Challenges of Cloud Detection and Response](https://cloudsecurityalliance.org/blog/2023/03/13/the-challenges-of-cloud-detection-and-response)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

