Runbook 03 — Enterprise Cloud Red Team Investigation & Reporting
Runbook Information
Section titled “Runbook Information”| Property | Value |
|---|---|
| Runbook Name | Enterprise Cloud Red Team Investigation & Reporting |
| Module | Module 08 — Cloud Red Team Operations |
| Runbook Number | Runbook 03 |
| Difficulty | Expert |
| Estimated Execution Time | Multi-day Investigation |
| Audience | Cloud Red Team Operators, Cloud Security Consultants, Security Architects, Incident Responders |
| Objective | Provide a repeatable methodology for investigating Cloud Red Team engagements, validating evidence, documenting attack paths, producing executive and technical reports, and managing engagement closure. |
Purpose
Section titled “Purpose”The technical execution of a Cloud Red Team engagement is only one part of a successful assessment.
The real value comes from transforming technical evidence into meaningful business insights that help an organization improve its cloud security posture.
Professional investigation and reporting should answer:
- What happened?
- How did it happen?
- Why did it happen?
- Which security controls worked?
- Which controls failed?
- What business assets were affected?
- How quickly was the activity detected?
- How effectively did the organization respond?
- What should be improved first?
This runbook provides the standard methodology used by GoHackersCloud consultants to investigate findings and produce customer-ready deliverables.
Investigation Lifecycle
Section titled “Investigation Lifecycle”Collect Evidence
↓
Validate Evidence
↓
Build Timeline
↓
Reconstruct Attack Path
↓
Analyze Security Controls
↓
Assess Business Impact
↓
Validate Detection & Response
↓
Assign Risk Ratings
↓
Develop Recommendations
↓
Prepare Executive Report
↓
Prepare Technical Report
↓
Conduct Executive Debrief
↓
Conduct Technical Debrief
↓
Track Remediation
↓
Close EngagementPhase 01 — Collect Evidence
Section titled “Phase 01 — Collect Evidence”Objective
Section titled “Objective”Gather all evidence produced during the engagement.
Evidence Sources
Section titled “Evidence Sources”- Operator activity logs
- CloudTrail logs
- Azure Activity Logs
- Google Cloud Audit Logs
- Kubernetes Audit Logs
- Identity logs
- SIEM alerts
- Cloud screenshots
- CLI output
- API responses
- Timeline records
- Purple Team notes
- Incident tickets
Evidence Handling Principles
Section titled “Evidence Handling Principles”Evidence should be:
- Accurate
- Complete
- Timestamped
- Traceable
- Securely stored
- Properly classified
- Easy to reproduce
Deliverables
Section titled “Deliverables”- Evidence Register
- Evidence Repository
- Chain of Custody Log
Phase 02 — Validate Evidence
Section titled “Phase 02 — Validate Evidence”Objective
Section titled “Objective”Ensure every finding is supported by reliable evidence.
Review
Section titled “Review”- Time synchronization
- User identities
- Resource names
- Account IDs
- Regions
- Cloud providers
- Event IDs
- Log integrity
- Screenshot relevance
Validation Checklist
Section titled “Validation Checklist”- Evidence matches activity
- Timestamps verified
- Scope confirmed
- Synthetic resources verified
- Logs preserved
- Sensitive data sanitized
Deliverables
Section titled “Deliverables”- Validated Evidence Register
Phase 03 — Build the Engagement Timeline
Section titled “Phase 03 — Build the Engagement Timeline”Objective
Section titled “Objective”Create a complete chronological record of the engagement.
Timeline Fields
Section titled “Timeline Fields”- Date
- Time (UTC)
- Operator
- Activity
- Identity
- Target Resource
- Result
- Evidence ID
- Detection Status
Example Timeline
Section titled “Example Timeline”| Time | Activity | Result |
|---|---|---|
| 09:00 | Initial Authentication | Successful |
| 09:15 | Role Assumption | Successful |
| 09:30 | Kubernetes Access | Successful |
| 09:45 | Secret Retrieval | Successful |
| 09:50 | SIEM Alert Generated | Yes |
| 10:05 | SOC Investigation | Started |
| 10:18 | Session Revoked | Completed |
Deliverables
Section titled “Deliverables”- Engagement Timeline
Phase 04 — Reconstruct the Attack Path
Section titled “Phase 04 — Reconstruct the Attack Path”Objective
Section titled “Objective”Build a complete attack path showing every transition.
Example
Section titled “Example”External Reconnaissance
↓
Developer Identity
↓
IAM Role
↓
CI/CD Pipeline
↓
Deployment Identity
↓
Kubernetes Cluster
↓
Service Account
↓
Secret Manager
↓
Synthetic Database
↓
SOC Detection
↓
ContainmentDocument
Section titled “Document”For each stage include:
- Identity
- Resource
- Permission
- Trust relationship
- Security control
- Detection status
- Business relevance
Deliverables
Section titled “Deliverables”- Enterprise Attack Path Diagram
Phase 05 — Analyze Security Controls
Section titled “Phase 05 — Analyze Security Controls”Objective
Section titled “Objective”Determine how security controls performed.
Evaluate
Section titled “Evaluate”- Identity security
- MFA
- IAM policies
- RBAC
- Conditional Access
- Logging
- Monitoring
- Network segmentation
- Secrets management
- Kubernetes security
- CI/CD security
Classification
Section titled “Classification”| Status | Meaning |
|---|---|
| Effective | Successfully prevented or detected activity |
| Partial | Reduced risk but did not fully prevent activity |
| Ineffective | Failed to prevent or detect |
| Not Tested | Outside engagement scope |
Deliverables
Section titled “Deliverables”- Security Control Assessment
Phase 06 — Assess Business Impact
Section titled “Phase 06 — Assess Business Impact”Objective
Section titled “Objective”Translate technical findings into business language.
Review
Section titled “Review”- Critical applications
- Sensitive information
- Customer services
- Regulatory exposure
- Financial impact
- Operational disruption
- Reputation impact
Business Impact Matrix
Section titled “Business Impact Matrix”| Finding | Technical Impact | Business Impact |
|---|---|---|
| Excessive IAM Permissions | Privilege Escalation | Unauthorized cloud administration |
| Shared Service Account | Secret Access | Sensitive application exposure |
| Weak CI/CD Controls | Deployment Abuse | Unauthorized application deployment |
| Missing Detection | Delayed Response | Increased attacker dwell time |
Deliverables
Section titled “Deliverables”- Business Impact Assessment
Phase 07 — Validate Detection & Response
Section titled “Phase 07 — Validate Detection & Response”Objective
Section titled “Objective”Measure defensive effectiveness.
Review
Section titled “Review”- Logging coverage
- Alert generation
- SIEM correlation
- Analyst investigation
- Escalation
- Containment
- Recovery
Detection Metrics
Section titled “Detection Metrics”- Time to Log
- Time to Alert
- Time to Investigate
- Time to Escalate
- Time to Contain
- Time to Recover
Deliverables
Section titled “Deliverables”- Detection Assessment
- SOC Performance Report
Phase 08 — Assign Risk Ratings
Section titled “Phase 08 — Assign Risk Ratings”Objective
Section titled “Objective”Prioritize findings.
Severity Levels
Section titled “Severity Levels”| Rating | Description |
|---|---|
| Critical | Immediate business risk |
| High | Significant security weakness |
| Medium | Moderate risk requiring remediation |
| Low | Limited exposure |
| Informational | Security improvement opportunity |
Risk Factors
Section titled “Risk Factors”Evaluate:
- Likelihood
- Business impact
- Exploitability
- Existing controls
- Detection capability
- Exposure
Deliverables
Section titled “Deliverables”- Risk Register
Phase 09 — Develop Recommendations
Section titled “Phase 09 — Develop Recommendations”Objective
Section titled “Objective”Provide practical remediation guidance.
Recommendation Categories
Section titled “Recommendation Categories”Immediate
Section titled “Immediate”- Remove excessive permissions
- Rotate secrets
- Revoke sessions
- Remove temporary roles
Short-Term
Section titled “Short-Term”- Improve IAM
- Harden Kubernetes RBAC
- Strengthen CI/CD controls
- Improve logging
Long-Term
Section titled “Long-Term”- Zero Trust implementation
- Identity governance
- Continuous Purple Team exercises
- Cloud detection engineering
Deliverables
Section titled “Deliverables”- Prioritized Remediation Roadmap
Phase 10 — Prepare the Executive Report
Section titled “Phase 10 — Prepare the Executive Report”Audience
Section titled “Audience”- CIO
- CISO
- Executive Leadership
- Board Members
- Risk Committee
Report Structure
Section titled “Report Structure”- Executive Summary
- Business Objectives
- Scope
- Overall Security Posture
- Attack Path Summary
- Business Impact
- Security Strengths
- Key Risks
- Detection Performance
- Recommendations
- Roadmap
Executive Report Principles
Section titled “Executive Report Principles”- Focus on business outcomes.
- Avoid unnecessary technical detail.
- Highlight strategic risks.
- Present measurable improvements.
- Support findings with evidence.
Deliverables
Section titled “Deliverables”- Executive Report
- Executive Presentation
Phase 11 — Prepare the Technical Report
Section titled “Phase 11 — Prepare the Technical Report”Audience
Section titled “Audience”- Cloud Engineers
- Security Engineers
- SOC
- DevSecOps
- Platform Teams
Technical Report Structure
Section titled “Technical Report Structure”- Scope
- Methodology
- Environment
- Timeline
- Attack Path
- Findings
- Evidence
- Detection Results
- ATT&CK Mapping
- Risk Register
- Recommendations
- Cleanup Verification
Deliverables
Section titled “Deliverables”- Technical Report
Phase 12 — Executive Debrief
Section titled “Phase 12 — Executive Debrief”Objective
Section titled “Objective”Present findings to leadership.
Discuss
Section titled “Discuss”- Overall objective
- Business impact
- Attack path
- Security strengths
- Priority risks
- Investment priorities
- Remediation roadmap
Expected Outcome
Section titled “Expected Outcome”Leadership understands:
- Business exposure
- Risk priorities
- Required investment
- Next steps
Phase 13 — Technical Debrief
Section titled “Phase 13 — Technical Debrief”Objective
Section titled “Objective”Review technical findings.
Participants
Section titled “Participants”- Cloud Security
- DevSecOps
- Platform Teams
- SOC
- Incident Response
- IAM Team
Discuss
Section titled “Discuss”- Attack path
- Detection gaps
- Identity weaknesses
- Kubernetes findings
- Cloud logging
- Recommendations
- Retesting
Deliverables
Section titled “Deliverables”- Technical Debrief Notes
Phase 14 — Track Remediation
Section titled “Phase 14 — Track Remediation”Objective
Section titled “Objective”Monitor remediation progress.
Record
Section titled “Record”- Finding
- Owner
- Priority
- Due date
- Status
- Validation
- Retest results
Example
Section titled “Example”| Finding | Owner | Status |
|---|---|---|
| IAM Permissions | IAM Team | In Progress |
| Kubernetes RBAC | Platform Team | Planned |
| SIEM Detection | SOC | Complete |
Deliverables
Section titled “Deliverables”- Remediation Tracker
Phase 15 — Retesting
Section titled “Phase 15 — Retesting”Objective
Section titled “Objective”Verify remediation effectiveness.
Validate
Section titled “Validate”- IAM improvements
- Detection improvements
- Kubernetes hardening
- Segmentation
- CI/CD security
- Secret management
Deliverables
Section titled “Deliverables”- Retest Report
Phase 16 — Engagement Closure
Section titled “Phase 16 — Engagement Closure”Verify
Section titled “Verify”- Temporary identities removed
- Temporary resources deleted
- Test secrets rotated
- Sessions revoked
- Evidence archived
- Reports delivered
- Customer acceptance received
Deliverables
Section titled “Deliverables”- Cleanup Verification Report
- Engagement Closure Report
Standard Deliverables Checklist
Section titled “Standard Deliverables Checklist”Investigation
Section titled “Investigation”- Evidence Register
- Engagement Timeline
- Attack Path Diagram
- Security Control Assessment
- Business Impact Assessment
- Risk Register
- ATT&CK Mapping
Reporting
Section titled “Reporting”- Executive Report
- Executive Presentation
- Technical Report
- Technical Debrief
Remediation
Section titled “Remediation”- Roadmap
- Remediation Tracker
- Retest Report
Closure
Section titled “Closure”- Cleanup Verification
- Engagement Closure Report
Investigation Decision Gates
Section titled “Investigation Decision Gates”| Phase | Decision |
|---|---|
| Evidence Collection | Evidence complete and validated |
| Timeline | Chronology verified |
| Attack Path | Supported by evidence |
| Risk Assessment | Business impact confirmed |
| Executive Report | Reviewed and approved |
| Technical Report | Technical validation complete |
| Remediation | Owners assigned |
| Closure | Cleanup verified and accepted |
Engagement Success Criteria
Section titled “Engagement Success Criteria”The investigation is successful when:
- Every finding is supported by evidence.
- Attack paths are clearly documented.
- Business impact is accurately described.
- Detection effectiveness is measured.
- Risks are prioritized.
- Recommendations are actionable.
- Executive and technical reports are delivered.
- Remediation ownership is established.
- Retesting is planned.
- Engagement is formally closed.
Consultant Best Practices
Section titled “Consultant Best Practices”Professional Cloud Red Team consultants should:
- Preserve evidence throughout the engagement.
- Maintain an accurate investigation timeline.
- Separate confirmed findings from assumptions.
- Recognize security controls that performed well.
- Use business language for executive audiences.
- Support every conclusion with evidence.
- Prioritize recommendations by business risk.
- Track remediation through completion.
- Verify remediation with retesting.
- Conduct formal executive and technical debriefs.
- Maintain confidentiality and secure handling of sensitive information.
Common Reporting Mistakes
Section titled “Common Reporting Mistakes”Avoid:
- Unsupported conclusions.
- Missing evidence.
- Overstating business impact.
- Ignoring successful security controls.
- Excessive technical jargon in executive reports.
- Missing remediation ownership.
- No remediation validation.
- Incomplete engagement closure.
Runbook Summary
Section titled “Runbook Summary”This runbook provides the complete investigation and reporting methodology for enterprise Cloud Red Team engagements.
By following this structured process, consultants can consistently transform technical assessment activities into actionable business intelligence, executive decision support, and measurable security improvements.
The methodology ensures that every engagement is evidence-driven, professionally documented, aligned with enterprise consulting standards, and focused on helping organizations strengthen their cloud security posture through clear findings, prioritized remediation, validated improvements, and successful engagement closure.