Cloud Security

Cloud Infrastructure
Security & Compliance

3
Cloud Platforms
AWS
GuardDuty & Hub
Azure
Defender & Sentinel
GCP
SCC & Chronicle
CSPM
Posture Mgmt
CRITPublic S3 bucket exposes PII — misconfiguration #1 cloud risk| HIGHAWS keys in GitHub repo → IAM enumeration → privilege escalation| CRITAzure AD Global Admin via PIM abuse → tenant takeover| HIGHGCP service account key leaked → project-wide access| MEDIMDSv1 enabled → SSRF → EC2 instance credentials stolen| CRITCryptojacking via compromised Lambda function → $50K bill| HIGHOverprivileged IAM role → lateral movement across accounts| MEDCloudTrail disabled → attacker activity undetected for 47 days| CRITPublic S3 bucket exposes PII — misconfiguration #1 cloud risk| HIGHAWS keys in GitHub repo → IAM enumeration → privilege escalation| CRITAzure AD Global Admin via PIM abuse → tenant takeover| HIGHGCP service account key leaked → project-wide access| MEDIMDSv1 enabled → SSRF → EC2 instance credentials stolen| CRITCryptojacking via compromised Lambda function → $50K bill| HIGHOverprivileged IAM role → lateral movement across accounts| MEDCloudTrail disabled → attacker activity undetected for 47 days|
Security Domains
01
🔐
IAM & Identity
Least privilege, privilege escalation paths, IAM policy analyser
02
AWS Security
GuardDuty, Security Hub, misconfiguration checker, attack paths
03
Azure Security
Defender for Cloud, Sentinel KQL, Entra ID, PIM abuse
04
GCP Security
SCC, Chronicle, IAM, VPC Service Controls, org policy
05
📋
Posture & Compliance
CSPM, CWPP, shared responsibility, logging, CIS benchmarks
🔐

IAM & Identity Security

Least privilege, privilege escalation paths, cross-account access, federation

Interactive📋

IAM Policy Analyser

Check your IAM configuration against least-privilege best practices across AWS, Azure, GCP.

Interactive📈

Privilege Escalation Paths

Select your current IAM permissions and find potential escalation paths to admin.

Reference📖

IAM Best Practices

Least privilege, MFA enforcement, role-based access, JIT access, service account hygiene.

AWS Security

Amazon Web Services security services, misconfigurations, attack techniques, and detections

Interactive⚠️

AWS Misconfiguration Checker

Select your AWS services and get a targeted misconfiguration checklist.

Reference🔨

AWS Attack Techniques

IAM abuse, SSRF→IMDS, S3 exfil, Lambda backdoor, CloudTrail evasion.

Reference

AWS Security Services

GuardDuty, Security Hub, Inspector, Macie, Config, CloudTrail — full reference.

AWS Security Services Map
Threat Detection
GuardDuty
ML-based threat detection — IAM anomalies, crypto mining, C2 traffic
Posture
Security Hub
Centralised findings from GuardDuty, Inspector, Macie, Config
Vulnerability
Inspector
EC2, Lambda, ECR vulnerability scanning — CVE detection
Data Security
Macie
S3 PII discovery — detects exposed sensitive data automatically
Compliance
Config
Resource configuration history and compliance rules
Audit
CloudTrail
API call logging — who did what, when, from where
Identity
IAM Access Analyzer
Finds resources shared externally — S3, KMS, Lambda, roles
Network
Network Firewall
Stateful managed firewall for VPC — IDS/IPS rules
WAF/DDoS
Shield + WAF
DDoS protection + web application firewall with managed rules
Secrets
Secrets Manager
Automatic rotation of DB credentials, API keys, OAuth tokens

Azure Security

Microsoft Azure security services, Entra ID, Defender for Cloud, Sentinel KQL detections

Reference

Azure Security Services

Defender for Cloud, Sentinel, Entra ID, Key Vault, DDoS Protection — full reference.

Reference🔍

Sentinel KQL Detections

Ready-to-use KQL queries for IAM abuse, impossible travel, privilege escalation, data exfil.

Interactive⚠️

Azure Misconfiguration Checker

Select Azure services and get targeted hardening checklist.

Azure Security Services Map
CSPM + CWPP
Defender for Cloud
Unified CSPM and workload protection across Azure, AWS, GCP
SIEM/SOAR
Microsoft Sentinel
Cloud-native SIEM with built-in SOAR and UEBA capabilities
Identity
Entra ID (AAD)
Identity platform — SSO, MFA, Conditional Access, PIM
Privileged Access
PIM
Just-in-time privileged access with approval workflows
Secrets
Key Vault
Secrets, keys, and certificate management with HSM backing
Network
Azure Firewall
Managed stateful firewall with threat intelligence filtering
WAF/DDoS
DDoS Protection
Standard tier — adaptive tuning, attack analytics, SLA
Endpoint
Defender for Endpoint
EDR for Windows/Linux/macOS — integrates with Sentinel

GCP Security

Google Cloud Platform security services, IAM, VPC Service Controls, Chronicle SIEM

Reference

GCP Security Services

Security Command Center, Chronicle, Cloud Armor, Secret Manager, VPC Service Controls.

Reference🔐

GCP IAM & Attack Paths

Service account abuse, workload identity, org policy bypass, privilege escalation.

GCP Security Services Map
CSPM
Security Command Center
Asset inventory, vulnerability findings, threat detection across GCP
SIEM
Chronicle
Petabyte-scale security analytics — YARA-L detection rules
WAF/DDoS
Cloud Armor
DDoS protection and WAF with adaptive protection ML
Secrets
Secret Manager
Versioned secrets with IAM-based access and audit logging
Data Exfil
VPC Service Controls
Perimeter around GCP APIs — prevents data exfiltration
Audit
Cloud Audit Logs
Admin activity, data access, system events — 400-day retention
Network
Cloud IDS
Network-based threat detection powered by Palo Alto Networks
Identity
Workload Identity
Keyless auth for GKE workloads — eliminates service account keys
📋

Posture & Compliance

CSPM, CWPP, shared responsibility model, logging strategy, CIS benchmarks

Reference🤝

Shared Responsibility Model

IaaS vs PaaS vs SaaS — what you own vs what the provider owns across AWS, Azure, GCP.

Reference📋

CSPM & CWPP Reference

Wiz, Prisma Cloud, Orca, Defender for Cloud — capabilities comparison.

Reference📊

Cloud Logging Strategy

Essential logs per platform, retention, SIEM ingestion, cost optimisation.

Interactive

CIS Benchmark Checker

Select your cloud platform and get the top CIS benchmark controls to verify.

Cloud Security Platform — Specialist Modules
🇮🇳 IN Regulatory

India Cloud Data Localisation

RBI, SEBI, DPDP, IRDAI, MeitY requirements — interactive compliance checker, regulator tabs, and gap assessment tool.

RBI SEBI DPDP 2023 IRDAI MeitY
🏦 Banks & NBFCs

RBI Cloud Guidelines

Practical checklist for banks & NBFCs — data residency, IAM, network security, DR, audit logging, and vendor risk controls mapped to RBI circulars.

IT Framework DCRSS 6hr SAR
🤝 Interactive

Shared Responsibility Matrix

Interactive IaaS/PaaS/SaaS × AWS/Azure/GCP matrix — who owns what, customer responsibility drill-down, and common misconceptions.

IaaS PaaS SaaS AWS·Azure·GCP
🏗️ Shift Left

Terraform / IaC Security

Top misconfigurations with secure HCL patterns, tfsec & Checkov rule IDs, CI/CD security gate pipeline, and interactive scanner simulation.

tfsec Checkov CI/CD Gate KICS
🔴 Detection

Native Detection Reference

GuardDuty, Defender for Cloud, GCP SCC — finding types, MITRE ATT&CK mapping, KQL queries, IOCs, and response playbooks in one reference.

GuardDuty Defender GCP SCC MITRE ATT&CK
☁️

Tool