OPERATIONAL PLAYBOOK · IR-03

Cloud identity compromise

Contain compromised human and workload identities, find delegated access and persistence, and validate every downstream action.

SEVERITY / CRITICALFIRST ACTION / REVOKE ACTIVE SESSIONS AND TOKENSFORMAT / PRINT-READY

Recognize and declare

Treat these signals as an incident when they cross an authorization, confidentiality, integrity, availability, or safety boundary.

  • Unexpected token use, role assumption, consent, key creation, or MFA change
  • Activity from unfamiliar networks, devices, agents, or geographies
  • Security controls, logging, policies, or recovery methods are changed

Preserve the evidence

Collect authoritative records before destructive cleanup whenever operationally safe. Record source, collector, UTC time, integrity hash, access, and retention decision.

  • Authentication, token issuance, federation, MFA, conditional-access, and device logs
  • Cloud control-plane, API, resource, network, and data-access audit logs
  • Role, policy, group, application, service-principal, key, and secret changes
  • Session identifiers, token IDs, actors, IPs, user agents, resources, and UTC timestamps

IR-03 · FIRST 15 MINUTES

Reduce immediate uncertainty

  1. Revoke sessions and tokens; disable the identity when active misuse outweighs availability impact.
  2. Preserve identity and cloud audit data, configuration, policy versions, and affected-resource state.
  3. Block known attacker infrastructure and require trusted administrative paths.
  4. Inventory roles, delegated credentials, applications, keys, secrets, and reachable tenants or accounts.
  5. Identify destructive, persistence, data-access, and security-control changes.

Contain → eradicate → recover

PHASE / 01

Contain

  • Remove high-risk role assignments and temporary credentials while maintaining break-glass access.
  • Disable unauthorized applications, federation paths, API keys, automation, and recovery methods.
  • Apply scoped deny controls to affected resources, regions, services, or data planes.
PHASE / 02

Eradicate

  • Remove backdoor identities, policies, keys, functions, automation, and cross-account trust.
  • Rotate secrets from a clean control plane and update every dependent workload.
  • Restore logging and security controls from reviewed configuration-as-code.
PHASE / 03

Recover

  • Re-enable identities with phishing-resistant MFA and reduced privilege.
  • Validate resource integrity, data access, billing, deployments, and security telemetry.
  • Monitor affected identities and equivalent indicators across all tenants and accounts.

Decision gates

Record the owner, evidence, uncertainty, operational impact, and rollback condition at every transition.

Containment gate

Attacker sessions and delegated paths are invalid, with trusted administration preserved.

Eradication gate

All persistence, policy, key, application, and federation changes are reconciled.

Recovery gate

Resource owners approve integrity, privilege, telemetry, and staged restoration.

Rollback safeguard: define the last known-good state, measurable failure signals, accountable decision owner, and fastest safe return path before restoring service.

AUTHORSHIP & REVIEW

How to trust and adapt this guide

Author & accountable editor
Leandro Rocha
Version
1.0
Published / reviewed
18 August 2026
Review status
Maintainer-reviewed; independent peer review is not claimed.

Reference basis

  • NIST SP 800-61 Rev. 3
  • Cloud-provider identity and audit guidance
  • MITRE ATT&CK Cloud techniques

Assumptions

  • The organization has authorized incident leadership, protected communications, and access to relevant telemetry.
  • Actions are adapted to business impact, legal obligations, architecture, and available evidence before execution.

Limitations

  • This field guide is not a substitute for organization-specific legal, privacy, safety, regulatory, or business-continuity advice.
  • Vendor interfaces and log availability vary by product, plan, region, configuration, and retention period.