Visualização de leitura

Would a cloud environment that continuously generates realistic security activity be useful to you?

I'm exploring an idea and want to validate whether there's actually a need for it before building it further.

Imagine having a small Azure environment that behaves somewhat like a real organization:

  • Multiple identities with different roles
  • Normal day-to-day activity
  • Resource access and changes
  • Administrative activity
  • Deployments and configuration changes
  • Authentication activity
  • Background "noise"

And on top of that, specific security scenarios or attack activity is triggered at different times, hidden in the noise.

The goal would be to have an environment that is active and changing, rather than a static cloud-security lab where you perform one exercise and tear everything down.

Potential uses could include:

  • Detection engineering
  • Testing Sentinel/SIEM detections
  • KQL development
  • Threat hunting
  • SOC investigation practice
  • Cloud-security training
  • Testing security products
  • Practicing cloud incident response

I'm trying to figure out whether this is actually something people want.

If this existed, would you be interested in using it?

If yes:

What would you use it for?

And what would you expect it to do for you to consider it worth using?

If no:

What would you use instead, and why would this not be useful?

I'm not promoting a product or asking anyone to sign up for anything. I'm simply trying to determine whether this is a problem worth building a solution for.

submitted by /u/identity-stack
[link] [comments]

How do you create realistic activity in a cloud environment for cloud security learning?

I'm interested in how people actually create realistic cloud activity when learning and testing things like cloud detections, SIEM rules, incident investigations, or security tooling.

For example, if you wanted to test whether your security monitoring could detect something happening in Azure, how would you create the activity?

Would you:

  • Perform everything manually?
  • Use scripts/APIs?
  • Use attack simulation frameworks?
  • Use Terraform or another IaC approach?
  • Build dedicated test environments?
  • Replay existing telemetry?
  • Use intentionally vulnerable labs?
  • Something else?

What happens after the initial setup?

How do you keep the environment producing realistic activity rather than becoming a static environment that nobody touches?

What is the most annoying part of this process today?

I'm trying to understand the real-world workflow rather than looking for tool recommendations.

submitted by /u/identity-stack
[link] [comments]
❌