Enter your keyword

← All Projects  ›  Cloud IR Playbooks & SIEM Detection Engineering
Project 05 - Detection Engineering

Cloud IR Playbooks & SIEM Detection Engineering

Microsoft Sentinel · AWS · MITRE ATT&CK

18 custom KQL detection rules mapped to MITRE ATT&CK for Cloud - reducing MTTD by 65% and automating 40% of alert responses via SOAR.

65% MTTD reduction18 KQL rules40% automationMITRE mapped4 IR playbooksNIST SP 800-61 Rev 3
65%
MTTD reduction
18
Custom KQL rules
40%
Alert automation
4
IR scenarios covered
The Challenge
Problem Statement

A regulated financial institution on AWS lacked cloud-native incident response capability. AWS and Azure telemetry was not feeding into any SIEM, detection relied on default GuardDuty rules not tuned to the specific threat model, and there were no documented response procedures for cloud attack scenarios. Mean time to detect for cloud incidents was measured in days rather than hours, and responders had no playbooks to guide containment and investigation.

The Approach
How I Solved It

I started with the threat model - identifying the most likely attack paths for a financial institution on AWS and mapping them to MITRE ATT&CK for Cloud (IaaS). I built custom KQL detection rules in Microsoft Sentinel for each high-priority technique: IAM credential compromise, S3 data exfiltration, EC2 cryptomining, GuardDuty/CloudTrail disablement, federated session hijacking, and ransomware indicators. For each detection, I built a corresponding SOAR automation in Logic Apps for deterministic response actions. I also developed four cloud IR playbooks aligned to NIST SP 800-61 Rev 3, and a full Cloud IR Plan documenting the IRT structure, six-phase lifecycle with formal decision gates, and regulatory notification obligations.

Frameworks & Standards
NIST SP 800-61 Rev 3
MITRE ATT&CK for Cloud
NIST CSF DE/RS/RC
FFIEC Incident Response Guidance
Tools & Platforms
Microsoft Sentinel · KQL · Azure Logic Apps · AWS GuardDuty · CloudTrail · Security Hub · AWS Lambda
Category
SIEM · Detection Engineering · Incident Response
What Was Delivered
Outcomes & Results
65% reduction in mean time to detect across cloud incident categories
18 custom KQL detection rules deployed in Microsoft Sentinel - all mapped to MITRE ATT&CK for Cloud
40% of alert responses automated via SOAR Logic Apps - reducing analyst workload for high-confidence detections
Four cloud IR playbooks built covering S3 exfiltration, EC2 cryptomining, IAM credential compromise, and ransomware
Cloud IR Plan documented aligned to NIST SP 800-61 Rev 3 (April 2025) with IRT structure and phase exit decision gates
MITRE ATT&CK Navigator layer published showing detection coverage - available on GitHub
Key Lesson
Default SIEM rules are not a detection strategy - they are a starting point calibrated for the average environment. The 65% MTTD reduction came from building context-aware detections for the specific attack patterns most likely against our environment, not from buying more tools. Detection coverage maps built against MITRE ATT&CK are more useful than rule counts.
// Evidence artifact - downloadable
Documented. Verifiable. Downloadable.
This project has a corresponding evidence artifact available in the Evidence Vault.
Download: Cloud IR Playbook