A prompt injection can end with a stolen secret and a cloud breach. This talk traces one multi-layer attack across five signal domains in your AWS environment: L7/API traffic inspection, workload runtime, network flows, EKS audit logs, and CloudTrail. No single source tells the full story. We will look at where the industry, AWS included, is heading: correlating runtime signals with AI-assisted investigation to turn noise into a real assessment.