Recognize and declare
Treat these signals as an incident when they cross an authorization, confidentiality, integrity, availability, or safety boundary.
- Unexpected token use, role assumption, consent, key creation, or MFA change
- Activity from unfamiliar networks, devices, agents, or geographies
- Security controls, logging, policies, or recovery methods are changed
Preserve the evidence
Collect authoritative records before destructive cleanup whenever operationally safe. Record source, collector, UTC time, integrity hash, access, and retention decision.
- Authentication, token issuance, federation, MFA, conditional-access, and device logs
- Cloud control-plane, API, resource, network, and data-access audit logs
- Role, policy, group, application, service-principal, key, and secret changes
- Session identifiers, token IDs, actors, IPs, user agents, resources, and UTC timestamps
IR-03 · FIRST 15 MINUTES
Reduce immediate uncertainty
- Revoke sessions and tokens; disable the identity when active misuse outweighs availability impact.
- Preserve identity and cloud audit data, configuration, policy versions, and affected-resource state.
- Block known attacker infrastructure and require trusted administrative paths.
- Inventory roles, delegated credentials, applications, keys, secrets, and reachable tenants or accounts.
- Identify destructive, persistence, data-access, and security-control changes.
Contain → eradicate → recover
PHASE / 01Contain
- Remove high-risk role assignments and temporary credentials while maintaining break-glass access.
- Disable unauthorized applications, federation paths, API keys, automation, and recovery methods.
- Apply scoped deny controls to affected resources, regions, services, or data planes.
PHASE / 02Eradicate
- Remove backdoor identities, policies, keys, functions, automation, and cross-account trust.
- Rotate secrets from a clean control plane and update every dependent workload.
- Restore logging and security controls from reviewed configuration-as-code.
PHASE / 03Recover
- Re-enable identities with phishing-resistant MFA and reduced privilege.
- Validate resource integrity, data access, billing, deployments, and security telemetry.
- Monitor affected identities and equivalent indicators across all tenants and accounts.
Decision gates
Record the owner, evidence, uncertainty, operational impact, and rollback condition at every transition.
Containment gate
Attacker sessions and delegated paths are invalid, with trusted administration preserved.
Eradication gate
All persistence, policy, key, application, and federation changes are reconciled.
Recovery gate
Resource owners approve integrity, privilege, telemetry, and staged restoration.
Rollback safeguard: define the last known-good state, measurable failure signals, accountable decision owner, and fastest safe return path before restoring service.
AUTHORSHIP & REVIEW
How to trust and adapt this guide
- Author & accountable editor
- Leandro Rocha
- Version
- 1.0
- Published / reviewed
- 18 August 2026
- Review status
- Maintainer-reviewed; independent peer review is not claimed.
Reference basis
- NIST SP 800-61 Rev. 3
- Cloud-provider identity and audit guidance
- MITRE ATT&CK Cloud techniques
Assumptions
- The organization has authorized incident leadership, protected communications, and access to relevant telemetry.
- Actions are adapted to business impact, legal obligations, architecture, and available evidence before execution.
Limitations
- This field guide is not a substitute for organization-specific legal, privacy, safety, regulatory, or business-continuity advice.
- Vendor interfaces and log availability vary by product, plan, region, configuration, and retention period.