Cloud security

What is Cloud detection and response (CDR)?

Definition

Detecting and responding to active threats in cloud environments, using cloud audit logs, identity activity and workload telemetry.

How it works

CSPM finds misconfigurations; CDR finds attackers. It watches sources such as Azure activity logs, AWS CloudTrail and Google Cloud audit logs for suspicious behaviour like unusual API calls, privilege escalation or new access keys.

Response actions in the cloud often focus on identity: disabling keys, revoking sessions and removing permissions.

Key points

  • Focuses on active threats, not configuration
  • Uses cloud audit and identity logs
  • Response centres on identities and keys
  • Complements CSPM

Common questions

Is CDR part of MDR?

It can be. Pulse monitors Azure, AWS and GCP alongside endpoints, identity and email.

Which logs matter most?

Control plane audit logs and identity sign-in logs are the starting point.

Talk to someone who does this every day

Questions about CDR? Our team will give you a straight answer.

Contact us