PRACTICE COLLECTION
Cloud & identity investigations
Identity and cloud configuration shape who can act and what they can access. Work through these already-published fictional scenarios to practice separating suspicious signals from confirmed impact.
Choose a case
Identity & Access · 4 min
The Impossible Travel Alert
One account, two logins, two distant locations.
Open investigation →Identity & Access · 4 minThe Suspicious OAuth App
A user granted a third-party app access to their account.
Open investigation →Identity & Access · 4 minA Reporting Add-On Wants Full Mailbox Access
A consent event appears for an app nobody in IT recognises.
Open investigation →Cloud Security · 4 minThe Bucket Went Public at 14:06
A configuration change exposed a storage container. Now what does that actually mean?
Open investigation →Identity & Access · 4 minDormant Service Account Wakes Up
Silent for 180 days, then authenticating every four minutes.
Open investigation →Cloud Security · 4 minA Public Function Returns Customer Records
A serverless endpoint works without authentication—and accepts any customer identifier.
Open investigation →Build context first
More cloud and identity cases are planned. This collection links only to investigations available today.