Security Operations
Find out what happens in your cloud
Cantina investigates cloud alerts, checks which data was accessed, and closes the exposure.
Understand who accessed exposed cloud data
A public storage bucket may contain sensitive records. Cantina examines the bucket and its access logs to determine whether someone read those records, where the requests came from, and what else was affected. It then closes the exposure.
Trace the activity and close the exposed resource
- 01
Inspect the resource
Start with the cloud security alert and check what is exposed.
- 02
Read the access logs
Establish which requests reached the resource and what data they accessed.
- 03
Assess the scope
Check the data involved and how far the incident extends.
- 04
Close the exposure
Correct the affected resource's configuration.
Access log
- 14:02:11 203.0.113.24 GET exports/pii-2026.csv read
- 14:02:11 203.0.113.24 GET exports/manifest.json read
- 09:41:52 10.0.4.7 LIST exports/ list
-
Alert triaged
public bucket · GCP SCC
-
Access confirmed
2 objects read externally
-
Scope assessed
1,204 records · 1 external IP
-
Exposure closed
public access removed
Investigate cloud threats with evidence of access and impact
-
Cloud alert investigation
Investigate findings such as a public bucket flagged by GCP Security Command Center.
-
Evidence of access
Use logs to distinguish possible exposure from recorded access.
-
Sensitive-data checks
Identify the records involved so the team can assess the incident.
-
Configuration changes
Remove the public exposure found during the investigation.
What security teams say about Cantina
Cantina is the first platform we have used that carries the work through from finding an issue to driving the fix, and it lets my team operate like one far larger than it is. We keep finding new uses for it across our security program.
Matt Mock
Chief Information Security Officer
See how Cantina investigates a cloud exposure
See how Cantina checks the access logs and closes the bucket's exposure.