Polling is the Vulnerability: A Case for Event-Driven Cloud Detection
Attackers don’t need zero-days in the cloud—they exploit detection delays. SIEM-based pipelines create blind spots through latency and complexity. This paper shows why the problem is architectural and presents OpenCDR, an event-driven system enabling near real-time response and eliminating detection gaps.
In modern cloud environments, attackers don’t need zero-days to evade detection—they exploit delays and blind spots in the detection pipeline itself (Practical AWS Antiforensics, VB 2025). Most cloud detection strategies rely on CloudTrail, GuardDuty, and centralized SIEM platforms, introducing multiple stages of ingestion, transformation, and correlation. These pipelines are inherently non-deterministic, often requiring minutes to detect and respond to high-severity events.
Based on practical experience gained while building and operating an open-source incident response framework (Dredge, Hack.lu 2024), as well as prior analysis of SIEM-centric detection failures in cloud environments, this talk argues that the problem is not a limitation of specific tools, but of architecture. Polling-based pipelines and stateless correlation models are fundamentally incompatible with event-driven cloud control planes. As a result, even well-instrumented environments can be bypassed by attackers operating within the detection delay window.
For example, disrupting or degrading a single component in the log ingestion path can silently create a detection gap, allowing an attacker to establish persistence or escalate privileges before any alert is generated. These failure modes are not edge cases—they are systemic properties of how most cloud detection systems are built today.
To explore this problem, we built OpenCDR, an open-source, event-driven detection and response system designed to test whether deterministic response can be achieved in practice. By eliminating polling stages, maintaining explicit detection state, and enforcing idempotency at the detection layer, the system enables consistent, near real-time response even under distributed event delivery and retry conditions.
The presentation analyzes the architectural tradeoffs and operational challenges encountered when moving from theory to production, including rule state management, response safety, rollback limitations, and scaling detection across heterogeneous event sources. Particular attention is given to failure modes observed in real-world environments, and how they impact detection reliability.
We conclude with a live attack scenario demonstrating how an adversary can exploit detection delays in traditional SIEM-based pipelines—and how an event-driven architecture reduces response time from minutes to seconds.
Former Police Officer from Argentina, now a Cloud Incident Responder and Security Engineer with over 10 years of IT experience. A Digital Nomad an international speaker, I've presented on Cloud Security and Incident Response at Ekoparty, FIRST, Virus Bulletin (three times), Hack.Lu, and various BSides events worldwide. I hold a Bachelor's degree in Information Security and an MBA (Master in Business Administration).