❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMicrosoftSentinel

How do you create realistic activity in a cloud environment for cloud security learning?

5 September 2026 at 01:25

I'm interested in how people actually create realistic cloud activity when learning and testing things like cloud detections, SIEM rules, incident investigations, or security tooling.

For example, if you wanted to test whether your security monitoring could detect something happening in Azure, how would you create the activity?

Would you:

  • Perform everything manually?
  • Use scripts/APIs?
  • Use attack simulation frameworks?
  • Use Terraform or another IaC approach?
  • Build dedicated test environments?
  • Replay existing telemetry?
  • Use intentionally vulnerable labs?
  • Something else?

What happens after the initial setup?

How do you keep the environment producing realistic activity rather than becoming a static environment that nobody touches?

What is the most annoying part of this process today?

I'm trying to understand the real-world workflow rather than looking for tool recommendations.

submitted by /u/identity-stack
[link] [comments]
❌
❌