- Administrative and control-plane activity
- IAM and resource-policy changes
- Configuration, posture, and public exposure
- Workload, data-service, and regional dependencies
CLOUD SECURITY · OLLANDI DIP
Monitor cloud control planes, identities, resources, posture, and exposure as one changing security state.
Specialized cloud security that contributes live evidence and domain actions to Ollandi’s cross-domain defense loop.
WHAT THE CLOUD DIP DOES
From domain telemetry to a decision operators can use.
- Privilege escalation and credential misuse
- Risky configuration drift
- Unexpected public or cross-account access
- Low-noise attack sequences using legitimate APIs
- Who or what initiated the change
- Which resources and services are reachable
- Whether activity matches approved work
- The likely threat, affected scope, and remaining uncertainty
- Revoke or revalidate sessions
- Temporarily suspend new privilege
- Block unsafe access paths
- Escalate higher-impact remediation for approval
COVERAGE
The context this DIP brings into Ollandi.
The DIP normalizes domain evidence with source and time preserved. Ollandi then relates it to other DIPs, service dependencies, policy, authority, and historical state.
- Cloud audit logs
- IAM policies and deltas
- Configuration snapshots
- CI/CD and change records
- Workload and dependency metadata
- Security and compliance policy
WEST 01
WEST 02
NORTH 01
EAST 01
SOUTH 01
EDGE
CONTROL PLANE
Public path changed
Public path changed
ONE INCIDENT · COMPLETE LOOP
See how the Cloud DIP moves from signal to verified outcome.
A service account gains privilege outside an approved change window.
Secrets enumeration follows. Ollandi tests a deployment error, configuration drift, and credential compromise as competing explanations.
A reversible privilege suspension and session revocation are checked against policy, service dependency, and blast radius.
Anomalous calls stop; the before-and-after state and decision evidence are preserved.
PART OF OLLANDI - NOT ANOTHER SILO
The DIP supplies depth. Ollandi supplies the shared state, threat reasoning, action validation, and evidence.
Domain state→Cross-domain hypothesis→Policy-checked action→Verified evidence
See the complete Ollandi lifecycle