Cloud Detection and Response (CDR)
Cloud Detection and Response, or CDR, is a runtime-focused security capability that ingests telemetry from cloud control planes (CloudTrail, Azure Activity, GCP Audit Logs), workload runtime (often via eBPF or agents), identity behavior, and network flows to detect active threats such as compromised credentials, lateral movement, cryptomining, data exfiltration, and unauthorized API calls. Unlike posture management, CDR is reactive and behavior-based, designed to catch the techniques cataloged in MITRE ATT&CK for Cloud rather than configuration drift, and it is increasingly delivered as the runtime layer of a unified CNAPP — critical given that 80% of cloud breaches involve identity compromise that posture tools alone cannot stop.
Learn more: The Complete Cloud Detection and Response (CDR) guide