OCI Threat Hunting & Incident Response | Log Queries+Compromised Credential Playbook | Project 10/10
SecureTechWithJKA
0:00 / 0:00
OCI Threat Hunting & Incident Response | Log Queries+Compromised Credential Playbook | Project 10/10
9 просмотров · 2 недели назад
SecureTechWithJKA
44 подписчика
9 просмотров · 2 недели назад
The alarm fired at 02:37 AM.
oci-sec-alarm-iam-policy-change.
A successful policy modification by john.smith.
Source IP: 198.51.100.47.
Not a corporate IP.
This is what the full incident response looks like —
from the first alert email to the evidence bucket with
a 7-year retention lock.
This is Project 10 and the final video of my OCI Security
Engineering series. 10 projects. One coherent security
architecture. Every layer you built in P1–P9 contributed
a log, an alarm, or a control that makes this response
possible.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🔐 WHAT WE BUILD
━━━━━━━━━━━━━━━━━━━━━━━━━━━━
✅ 5 saved Log Explorer threat hunting queries:
Q1 — Privilege Escalation Detection
Q2 — External API Access — High Volume
Q3 — Mass Resource Deletion
Q4 — Network Rejection Spike (port scan / lateral movement)
Q5 — Vault Key Operations Outside Business Hours
✅ 5-phase IR playbook — Detect · Contain · Investigate ·
Preserve Evidence · Recover & Harden
✅ Live walkthrough of the compromised credential scenario
✅ Evidence preservation — retention lock + incident bucket
✅ Hardening actions after every incident
━━━━━━━━━━━━━━━━━━━━━━━━━━━━
💡 WHY ALL FIVE QUERIES TOGETHER?
━━━━━━━━━━━━━━━━━━━━━━━━━━━━
No single query tells the full story.
Q1 fires when the attacker escalates privilege.
Q2 confirms they are operating from an external IP.
Q3 catches if they start destroying resources.
Q4 shows if a compromised instance is scanning the network.
Q5 reveals if they are trying to hold your data hostage.
An attacker who fires Q1 and Q2 simultaneously is in
your tenancy and has elevated access. Q1, Q2, and Q5
together is an active ransomware attempt.
The queries are designed to cross-reference — not run in isolation.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━
⏱️ TIMESTAMPS
━━━━━━━━━━━━━━━━━━━━━━━━━━━━
— The alarm fires — scenario setup
— Why Log Analytics and what it covers across the stack
— Log Analytics free tier limitation and CLI workaround
— Q1 Privilege Escalation — query walkthrough and what each clause does
— Q2 External API Access — tuning the NOT clause for your CIDRs
— Q3 Mass Resource Deletion — runaway Terraform vs insider attack
— Q4 Network Rejection Spike — port scan vs lateral movement patterns
— Q5 Key Operations outside hours — the data hostage signal
— IR Playbook overview — all 5 phases on one view
— Phase 1 DETECT — running queries against the live scenario
— Phase 2 CONTAIN — deactivate, delete keys, revert policy
— Phase 3 INVESTIGATE — full audit trail export
— Phase 4 PRESERVE EVIDENCE — retention lock and incident bucket
— Phase 5 RECOVER — closing the vector, reactivating with controls
— Hardening checklist after every incident
— Series complete — what all 10 projects built together
━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🏁 SERIES COMPLETE — WHAT YOU BUILT ACROSS ALL 10 PROJECTS
━━━━━━━━━━━━━━━━━━━━━━━━━━━━
P1 Secure Landing Zone — compartments, IAM, audit pipeline
P2 Hub-and-Spoke Network Security — VCN, DRG, NSGs, WAF
P3 IAM Federation & Dynamic Groups — SAML, credential-free Vault
P4 Vault & Data Encryption — CMK, secrets, auto-rotation
P5 Cloud Guard & Security Posture — CSPM, Security Zones, scanning
P6 Centralised Security Operations — logs, SIEM export, alarms
P7 Identity Domains & Privileged Access — MFA, session policies, certification
P8 Zero Trust Packet Routing — ZPR, attribute-based network enforcement
P9 Data Classification & Protection — Data Safe, ADB, retention lock
P10 Threat Hunting & Incident Response — queries, IR playbook ← YOU ARE HERE
━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🌐 MULTI-CLOUD SECURITY JOURNEY
━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Part of my hands-on multi-cloud security engineering series:
☁️ Oracle Cloud (OCI) Security — 10 Projects ✅ COMPLETE
☁️ Microsoft & Azure Security
☁️ AWS Security
☁️ GCP Security
☁️ SAP BTP Security
━━━━━━━━━━━━━━━━━━━━━━━━━━━━
📌 RESOURCES
━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🔗 LinkedIn: / johnkayode-abusi
📋 OCI Log Analytics docs:
https://docs.oracle.com/en-us/iaas/lo...
━━━━━━━━━━━━━━━━━━━━━━━━━━━━
👤 ABOUT ME
━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Product Security Leader with 17+ years securing cloud-native
and hybrid environments across IAM, AppSec, DevSecOps,
AI/LLM security, and multi-cloud architecture.
CCSP · CKS · CKA · CEH · Microsoft Cybersecurity Architect Expert ·
AWS Certified · GCP Certified · OCI Certified ·
SAP BTP Security Certified · APIsec Certified Practitioner
━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🔔 Series complete — if this helped, like and subscribe.
Drop a comment with what security project you are
building next.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━
#ThreatHunting #IncidentResponse #LogAnalytics #SIEM #SOC #CloudSecurity #SecurityOperations #IRPlaybook #EvidencePreservation #OracleCloudInfrastructure
#MultiCloudSecurity #DevSecOps #SecureTechWithJKA