Cloud Detection & Response Connections Overview

What a CDR connection is

ARMO Cloud Detection & Response (CDR) watches your cloud provider's audit log for suspicious control-plane activity and turns matches into Runtime Incidents. The design is the same on every cloud:

  1. You host the collector. ARMO gives you a pre-filled deployment: a CloudFormation stack for AWS, an az deployment command for Azure, or a Terraform module for GCP. You run it once, in your own account, subscription, or project.
  2. Detection runs in your environment. The collector reads the audit log where it already lands, evaluates ARMO's detection rules locally, and leaves the raw logs where they are.
  3. Only matched alerts leave. Each alert carries the single log record that triggered it and is pushed to ARMO over HTTPS using a per-connection access key. ARMO never reads from your cloud for CDR.
  4. Connection health comes from the collector. A connection is created Pending, flips to Connected when the collector first reports, and flips to Disconnected if ARMO hears nothing for 12 hours. A collector that resumes reporting reconnects on its own.
  5. Removal is two steps. Because ARMO has no access to your cloud, you delete the collector yourself (ARMO generates the commands where it can), then remove the connection in ARMO, which revokes the access key.

How CDR differs from Compliance (CSPM)

Compliance (CSPM)Cloud Detection & Response (CDR)
DirectionARMO pulls configuration from your cloudYour collector pushes alerts to ARMO
Credential ARMO holdsCross-account role (AWS), service principal (Azure), service-account key (GCP)None. Only ARMO's own per-connection access key, stored on your side
What you deployA read-only role or identityA running collector plus log plumbing
Data that leaves your cloudResource configurationMatched alerts only

The two features are independent and can be enabled on the same account.

Per-cloud comparison

AWSAzureGCP
Log sourceCloudTrail (management events) in S3Activity Log (control plane)Cloud Audit Logs, Admin Activity
Collector runtimeLambdaContainer AppsCloud Run (always on)
Log transportS3 event notificationEvent Hub via diagnostic settingLog Router sink to Pub/Sub push
Deployment mechanismCloudFormation quick-create link opened in the AWS consoleGenerated az deployment sub create commandGenerated Terraform module or gcloud script
ScopesSingle Account, Entire OrganizationSingle Subscription, Whole TenantSingle Project, Entire Organization
Org-wide coverage of new accountsVia the organization trailAzure Policy (DeployIfNotExists) at the Tenant Root GroupOrganization-level sink including all child projects
Narrowing org scopeExclude accounts in ARMONot yet (whole tenant only)Exclude projects in ARMO
Who deploysSomeone able to create IAM roles and Lambda in the accountOwner or User Access Administrator on the subscription (Tenant Root Group for whole tenant)Project Owner/Editor plus Service Account Admin and Logs Configuration Writer (organization-level for entire organization)
Connected triggerFirst report from the collectorSingle subscription: first collector heartbeat. Whole tenant: first subscription's Activity Log reaching the central collectorFirst heartbeat reporting real log traffic
Rule updatesUpdate the stack's image tagDownloaded from ARMO automaticallyDownloaded from ARMO automatically
Teardown help from ARMODelete the stack in CloudFormationGenerated cleanup commandGenerated Terraform and gcloud teardown

Things to know up front

  • Cold start on Azure. Diagnostic settings can take up to about 90 minutes to deliver the first Activity Log events on a brand-new subscription. A long Pending immediately after onboarding is normal.
  • Org-wide means org-wide. On Azure and GCP the org connection copies every subscription's or project's audit stream to your central collector. Excluding a project (GCP) stops its alerts, not its logs.
  • Whole-tenant and whole-organization connections are one row. ARMO shows the tenant or organization as a single connection and does not list its subscriptions or projects underneath it.
  • The deployment artifact contains a secret. Treat the quick-create link, az command, or Terraform variables like a password.

Per-cloud guides


Did this page help you?