An access key ends up in a public code repo.
The SIEM ingests CloudTrail on a 15-minute batch. By the time the correlation rule fires, an attacker has already listed every bucket, enumerated your IAM policies, and started staging data in a scratch account. Ninety percent of cloud breaches involve valid credentials — traditional log tools were not built for that speed or shape.
The risk of not knowing
If it is not surfaced today, it is exposed today. Attackers do not wait for your quarterly review — and neither do auditors.
The mechanism, not the marketing
- 1
Onam streams cloud audit logs — CloudTrail, VPC Flow, Azure Activity Log, GCP Cloud Audit, Kubernetes audit — in near real time, no external SIEM required.
- 2
L1 rule-based detection matches 200+ known-bad signatures aligned to MITRE ATT&CK for Cloud, covering credential abuse, persistence, exfiltration and defense evasion.
- 3
L2 behavioural analysis maintains 30-day per-entity baselines, so an identity behaving unlike itself (new region, new API, off-hours) fires an anomaly even without a rule.
- 4
L3 unsupervised ML surfaces novel techniques by clustering rare event sequences that never match known signatures — the class of threat traditional detection misses entirely.
- 5
Every alert is auto-enriched with posture, identity, and network context from the Onam graph and routed to Slack, PagerDuty, or email with response playbooks attached.
Specific outputs, measurable outcomes
CDR — Cloud Detection & Response in the real console.
Not a mockup — the actual Onam console on a live demo account, showing exactly what your team sees.
Questions we get a lot
Ready to see CDR — Cloud Detection & Response in your cloud?
Connect a read-only role in three minutes. Your first findings surface in under five.