CLOUD SECURITY · OLLANDI DIP

Monitor cloud control planes, identities, resources, posture, and exposure as one changing security state.

Specialized cloud security that contributes live evidence and domain actions to Ollandi’s cross-domain defense loop.

Compare all DIPs

From domain telemetry to a decision operators can use.

01 · MONITORS
  • Administrative and control-plane activity
  • IAM and resource-policy changes
  • Configuration, posture, and public exposure
  • Workload, data-service, and regional dependencies
02 · DETECTS
  • Privilege escalation and credential misuse
  • Risky configuration drift
  • Unexpected public or cross-account access
  • Low-noise attack sequences using legitimate APIs
03 · EXPLAINS
  • Who or what initiated the change
  • Which resources and services are reachable
  • Whether activity matches approved work
  • The likely threat, affected scope, and remaining uncertainty
04 · ENABLES RESPONSE
  • Revoke or revalidate sessions
  • Temporarily suspend new privilege
  • Block unsafe access paths
  • Escalate higher-impact remediation for approval
COVERAGE

The context this DIP brings into Ollandi.

The DIP normalizes domain evidence with source and time preserved. Ollandi then relates it to other DIPs, service dependencies, policy, authority, and historical state.

  • Cloud audit logs
  • IAM policies and deltas
  • Configuration snapshots
  • CI/CD and change records
  • Workload and dependency metadata
  • Security and compliance policy
CLOUD DIPRegional exposure plane
WEST 01
WEST 02
NORTH 01
EAST 01
SOUTH 01
EDGE
CONTROL PLANE
Public path changed
Connected to shared infrastructure context

See how the Cloud DIP moves from signal to verified outcome.

01Observe

A service account gains privilege outside an approved change window.

02Interpret

Secrets enumeration follows. Ollandi tests a deployment error, configuration drift, and credential compromise as competing explanations.

03Contain

A reversible privilege suspension and session revocation are checked against policy, service dependency, and blast radius.

04Verify

Anomalous calls stop; the before-and-after state and decision evidence are preserved.

The DIP supplies depth. Ollandi supplies the shared state, threat reasoning, action validation, and evidence.

Domain stateCross-domain hypothesisPolicy-checked actionVerified evidence
See the complete Ollandi lifecycle