Direct answer
Contain the identity and preserve the control-plane evidence first. Revoke sessions and exposed keys, protect privileged accounts, preserve cloud audit and identity logs, review IAM and resource changes, identify data or service impact, rotate secrets, remove persistence, and restore only the permissions and resources that are known to be authorised.
When to activate this playbook
Unexpected console or API activity from a cloud identity.
New keys, roles, policies, users, service principals or federation changes.
Unusual resource creation, deletion, snapshot, export or data-access activity.
Security alerts indicate privilege escalation, anomalous access or persistence.
First 15 minutes
Open an incident and identify the cloud account, tenant, project, subscription or organisation involved.
Preserve cloud control-plane, identity and relevant workload logs.
Revoke exposed sessions, tokens and keys and protect high-privilege identities.
Apply an approved containment measure to stop ongoing destructive or exfiltration activity.
First hour
Review IAM changes, access keys, service principals, federation, policies and privileged-role assignments.
Identify resources created, changed, deleted, snapshotted, exported or accessed by the compromised identity.
Search for persistence through new identities, keys, automation, scheduled tasks or deployment changes.
Determine whether customer, regulated or confidential data was accessed or exposed.
First day
Remove unauthorised identities, policies, keys, resources and persistence mechanisms.
Rotate affected secrets and restore least-privilege access from an approved baseline.
Validate resource integrity, logging and detection coverage before returning to normal operation.
Document cost, service, data, security and governance consequences and follow-up actions.
Evidence to preserve
EvidenceCloud control-plane and identity audit logs.
EvidenceIAM users, roles, policies, keys, federation and service-principal history.
EvidenceResource configuration, deployment and infrastructure-as-code history.
EvidenceStorage, database, network and workload access logs relevant to the incident.
EvidenceBilling or resource-creation evidence where attacker activity changed cost or capacity.
Key decision points
Was a privileged identity compromised?
Were new persistent cloud identities or keys created?
Was sensitive data accessed, copied or exported?
Are affected resources trustworthy enough to recover or should they be rebuilt?
Communication discipline
Coordinate cloud platform, identity, security, engineering and legal/privacy owners.
Use the cloud provider’s approved support and incident channels where appropriate.
Separate confirmed access from inferred data exposure when reporting impact.
Where Cybatar fits
Cloud-log and event-source context linked to incidents and assets.
Incident, evidence, threat and exposure records in one response timeline.
Remediation tasks, exceptions and governance reporting.
Connector-health evidence to distinguish configured sources from active telemetry.
Claim boundary
Cybatar can coordinate cloud-security events and response evidence, but it does not guarantee cloud-provider session revocation, complete log availability, automatic secret rotation or full cloud-native remediation. Those actions depend on provider capabilities, permissions and deployment configuration.
Related evidence and guidance
Cloud logs connector patternhttps://cybatar.co/connectors/cloud-logs
Integration-health evidencehttps://cybatar.co/developers/integration-health
Security Operations capabilityhttps://cybatar.co/platform/security-operations
Recommendation guidehttps://cybatar.co/recommendation-guide
Incident Response Checklisthttps://cybatar.co/incident-response-checklist
Evidence Preservation Checklisthttps://cybatar.co/incident-evidence-preservation-checklist