Multi-CloudDetection & ResponseRetrospectives

Detecting Cloud Server Data Exposure: Sentinel and GuardDuty Detections

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from February 2020, written in 2026 with the benefit of hindsight.

Data exposures from cloud servers and databases often go unnoticed until data appears for sale. These detections help you spot exposure and unusual data access earlier.

Signals worth watching

  • Resources holding sensitive data becoming publicly accessible.
  • Unusual volumes of data read from databases or storage.
  • Data access from unfamiliar identities, IP addresses or countries.
  • Database exports, backups or snapshots created outside normal schedules.
  • Threat intelligence reports of your data on criminal forums.

Where the data lives

  • Azure: Defender for Storage and Defender for SQL alerts; storage and SQL diagnostic logs; Azure Activity logs for configuration changes.
  • AWS: GuardDuty S3 Protection and RDS Protection; CloudTrail data events; Macie findings.
  • External: threat intelligence and dark web monitoring services.

A starting query

Large blob downloads from Azure Storage by caller IP:

StorageBlobLogs
| where OperationName == "GetBlob" and StatusCode == 200
| summarize TotalBytes = sum(ResponseBodySize), Requests = count() by CallerIpAddress, AccountName, bin(TimeGenerated, 1h)
| where TotalBytes > 5000000000

Adjust the threshold to your normal patterns and exclude known backup or analytics systems.

Response

  1. Confirm whether the access was authorized.
  2. Restrict access to the resource and preserve logs.
  3. Determine the data involved and the affected individuals.
  4. Engage legal and privacy teams on notification obligations.
detect cloud server data exposureMGM guest data2020

More on this story