Skip to main content

Overview of Cloud Resource Claim

An overview of Active Defense Cloud Resource Claim in the watchTowr Platform.

Cloud Resource Claim is a mitigation available through Active Defense that helps reduce takeover risk when your environment still references a cloud resource that is no longer assigned or controlled by your organization.

When a finding is eligible for Cloud Resource Claim, you will see the Active Defense option available on the finding details page, alongside existing actions such as retesting.

Cloud Resource Claim is available only for selected findings where a configuration in your environment (for example, a DNS record or application setting) still references a cloud resource, such as a storage bucket, that is no longer assigned to any account.

There is no bulk apply. Each claim is reviewed and applied on a per-finding basis, given the ownership and cost implications involved.

Cloud Resource Claim is most valuable when:

  • A finding identifies a cloud resource referenced by your environment that has been deleted or is no longer assigned.

  • A third party could otherwise claim that resource and use it to serve malicious content, redirect traffic, or exploit trust associated with your organization.

  • You want to close the exposure immediately, ahead of updating or removing the underlying reference that points to it.

Cloud Resource Claim requires a supported cloud integration to be configured for your organization before this mitigation becomes available on a finding.

Prerequisites:

  • A configured cloud integration with permissions sufficient to claim the resource type identified in the finding.

  • Authority within your organization to take ownership of the cloud resource, including any associated cost, ownership, or operational responsibilities.

  • A process for monitoring newly claimed resources, in case they need to be decommissioned or reassigned later.

  • Personnel available to review the resource name, region, and destination account before confirming the claim.

Active Defense mitigation measures, including Cloud Resource Claim, are provided on a best-effort basis.

You are responsible for reviewing, testing, and validating any mitigation before deployment to ensure it is most appropriate for your environment.

Workflow Overview

  1. Detection: A finding identifies a cloud resource referenced by your environment that is no longer assigned. The finding appears as normal, with full technical detail and evidence.

  2. Active Defense Available: If a supported cloud integration is configured, the Finding Details page will show the Active Defense option for Cloud Resource Claim.

  3. Review the Mitigation: Opening Active Defense will show the identified resource and the integration(s) available to complete the claim. You can select the appropriate integration, or where only one is configured, the platform may identify it for you automatically.

How to manually deploy the Cloud Resource Claim mitigation from a finding in the watchTowr Platform:

  1. Navigate to the finding where the Cloud Resource Claim mitigation is available. Within the finding's Action Panel, select Active Defense.

  2. The mitigation wizard will open, showing specific mitigation guidance.

  3. Select your configured integration from the available connections.

  4. Select the region and click Continue.

    1. If you do not have permission to continue, you'll see the following error message:

    2. If the cloud resource has already been claimed, you'll see the following error message:

  5. Before confirming the claim, review:

    • The resource name.

    • The region.

    • The destination account the resource will be claimed into.

  6. Validate the mitigation once resource has been claimed, use the platform's retesting workflow on the original finding to confirm the exposure has been resolved.

Applying the claim will register the resource within a customer-controlled cloud account. watchTowr does not claim or hold the resource on your behalf.

Claiming a cloud resource may create cost, ownership, or operational requirements that remain your organization's responsibility going forward.

watchTowr provides:

  • Identification of the exposed, unassigned cloud resource.

  • The mechanism to claim it via your configured integration.

Your organization is responsible for:

  • Final approval of the claim.

  • Ongoing ownership, cost, and management of the claimed resource.

  • Monitoring for any operational impact after the claim is made.

If you need assistance, don't hesitate to contact the watchTowr team. Our knowledgeable team is ready to help you navigate the watchTowr Platform and address any questions or concerns.

Did this answer your question?