CDR — Cloud Detection & Response

Is an attacker operating inside your cloud environment right now?

By the time a SIEM fires an alert, the attacker has already moved. CDR closes the gap.

Onam CDR runs continuous three-tier behavioral analysis over your cloud audit logs — detecting everything from known attack patterns to novel techniques no signature has seen, and correlating every finding with your posture and identity graph for instant context.

10,000+
security rules
7
cloud providers
< 5 min
to first finding
100%
agentless
Why this matters

An access key ends up in a public code repo.

The SIEM ingests CloudTrail on a 15-minute batch. By the time the correlation rule fires, an attacker has already listed every bucket, enumerated your IAM policies, and started staging data in a scratch account. Ninety percent of cloud breaches involve valid credentials — traditional log tools were not built for that speed or shape.

The risk of not knowing

If it is not surfaced today, it is exposed today. Attackers do not wait for your quarterly review — and neither do auditors.

Real-time detection, not periodic audits
How does it actually work?

The mechanism, not the marketing

  1. 1

    Onam streams cloud audit logs — CloudTrail, VPC Flow, Azure Activity Log, GCP Cloud Audit, Kubernetes audit — in near real time, no external SIEM required.

  2. 2

    L1 rule-based detection matches 200+ known-bad signatures aligned to MITRE ATT&CK for Cloud, covering credential abuse, persistence, exfiltration and defense evasion.

  3. 3

    L2 behavioural analysis maintains 30-day per-entity baselines, so an identity behaving unlike itself (new region, new API, off-hours) fires an anomaly even without a rule.

  4. 4

    L3 unsupervised ML surfaces novel techniques by clustering rare event sequences that never match known signatures — the class of threat traditional detection misses entirely.

  5. 5

    Every alert is auto-enriched with posture, identity, and network context from the Onam graph and routed to Slack, PagerDuty, or email with response playbooks attached.

What do you actually get?

Specific outputs, measurable outcomes

L1 rule-based detection
200+ known-bad signatures across CloudTrail, VPC Flow, and K8s audit logs
L2 statistical behavioral baselines
per-entity anomaly detection over 30-day windows
L3 ML anomaly detection
novel threats with no prior signature
MITRE ATT&CK for Cloud mapping
Posture + identity enrichment on every alert
Incident correlation into unified incidents
Real-time alerting
Slack, PagerDuty, email with full context
Response playbooks
quarantine, revoke, block
See it live

CDR — Cloud Detection & Response in the real console.

Not a mockup — the actual Onam console on a live demo account, showing exactly what your team sees.

CDR — Detection & Response
Configure Rules
2.3M
Events / Hour
4
Active Alerts
847
CloudTrail Events
12
Blocked IPs
Loading live data…
Detections correlated in real time
2.3M events/hour distilled into 4 active alerts, mapped to MITRE ATT&CK
Clip length
11s
Data
Demo account
FAQ

Questions we get a lot

AWS CloudTrail (management and data events), VPC Flow Logs, GuardDuty findings, Azure Activity Log and Entra ID sign-in logs, GCP Cloud Audit Logs, Kubernetes audit logs, and container runtime events. All ingested via read-only integrations.
Ready to see it live

Ready to see CDR — Cloud Detection & Response in your cloud?

Connect a read-only role in three minutes. Your first findings surface in under five.