# Cloud Defense — Reference Index Defensive counterpart to the offensive [`cloud-containers`](../../cloud-containers/reference/INDEX.md) scenarios. Two files, both organised by the same four attacker stages (lateral movement -> privilege escalation -> exfiltration -> evasion): | File | Job | |---|---| | [detection-signals.md](detection-signals.md) | The control-plane log event to alert on for each attacker stage, plus the logging prerequisites that make it visible | | [hardening-controls.md](hardening-controls.md) | The single preventive control that removes each technique | Read both top to bottom alongside the matching offensive scenario for the cloud in scope.