Cloud Detection & Response Connections Overview
What a CDR connection is
ARMO Cloud Detection & Response (CDR) watches your cloud provider's audit log for suspicious control-plane activity and turns matches into Runtime Incidents. The design is the same on every cloud:
- You host the collector. ARMO gives you a pre-filled deployment: a CloudFormation stack for AWS, an
az deploymentcommand for Azure, or a Terraform module for GCP. You run it once, in your own account, subscription, or project. - Detection runs in your environment. The collector reads the audit log where it already lands, evaluates ARMO's detection rules locally, and leaves the raw logs where they are.
- Only matched alerts leave. Each alert carries the single log record that triggered it and is pushed to ARMO over HTTPS using a per-connection access key. ARMO never reads from your cloud for CDR.
- Connection health comes from the collector. A connection is created Pending, flips to Connected when the collector first reports, and flips to Disconnected if ARMO hears nothing for 12 hours. A collector that resumes reporting reconnects on its own.
- Removal is two steps. Because ARMO has no access to your cloud, you delete the collector yourself (ARMO generates the commands where it can), then remove the connection in ARMO, which revokes the access key.
How CDR differs from Compliance (CSPM)
| Compliance (CSPM) | Cloud Detection & Response (CDR) | |
|---|---|---|
| Direction | ARMO pulls configuration from your cloud | Your collector pushes alerts to ARMO |
| Credential ARMO holds | Cross-account role (AWS), service principal (Azure), service-account key (GCP) | None. Only ARMO's own per-connection access key, stored on your side |
| What you deploy | A read-only role or identity | A running collector plus log plumbing |
| Data that leaves your cloud | Resource configuration | Matched alerts only |
The two features are independent and can be enabled on the same account.
Per-cloud comparison
| AWS | Azure | GCP | |
|---|---|---|---|
| Log source | CloudTrail (management events) in S3 | Activity Log (control plane) | Cloud Audit Logs, Admin Activity |
| Collector runtime | Lambda | Container Apps | Cloud Run (always on) |
| Log transport | S3 event notification | Event Hub via diagnostic setting | Log Router sink to Pub/Sub push |
| Deployment mechanism | CloudFormation quick-create link opened in the AWS console | Generated az deployment sub create command | Generated Terraform module or gcloud script |
| Scopes | Single Account, Entire Organization | Single Subscription, Whole Tenant | Single Project, Entire Organization |
| Org-wide coverage of new accounts | Via the organization trail | Azure Policy (DeployIfNotExists) at the Tenant Root Group | Organization-level sink including all child projects |
| Narrowing org scope | Exclude accounts in ARMO | Not yet (whole tenant only) | Exclude projects in ARMO |
| Who deploys | Someone able to create IAM roles and Lambda in the account | Owner or User Access Administrator on the subscription (Tenant Root Group for whole tenant) | Project Owner/Editor plus Service Account Admin and Logs Configuration Writer (organization-level for entire organization) |
| Connected trigger | First report from the collector | Single subscription: first collector heartbeat. Whole tenant: first subscription's Activity Log reaching the central collector | First heartbeat reporting real log traffic |
| Rule updates | Update the stack's image tag | Downloaded from ARMO automatically | Downloaded from ARMO automatically |
| Teardown help from ARMO | Delete the stack in CloudFormation | Generated cleanup command | Generated Terraform and gcloud teardown |
Things to know up front
- Cold start on Azure. Diagnostic settings can take up to about 90 minutes to deliver the first Activity Log events on a brand-new subscription. A long Pending immediately after onboarding is normal.
- Org-wide means org-wide. On Azure and GCP the org connection copies every subscription's or project's audit stream to your central collector. Excluding a project (GCP) stops its alerts, not its logs.
- Whole-tenant and whole-organization connections are one row. ARMO shows the tenant or organization as a single connection and does not list its subscriptions or projects underneath it.
- The deployment artifact contains a secret. Treat the quick-create link,
azcommand, or Terraform variables like a password.
Per-cloud guides
Updated about 6 hours ago
Did this page help you?
