CIS AWS Monitoring: The 15 CloudTrail Alarms Nobody Has
CIS AWS Foundations v7.0.0 asks for 15 CloudTrail monitoring alarms. The full list with control IDs, which five to build first, and why scanners skip them.
Expert perspectives on cloud security, compliance, and threat intelligence. Practical guidance for security leaders navigating an evolving landscape.
Cloud Security
CIS AWS Foundations v7.0.0 asks for 15 CloudTrail monitoring alarms. The full list with control IDs, which five to build first, and why scanners skip them.
Threat Intelligence
Malicious inbox rules are how attackers hide after MFA is bypassed. Here are the 6 auto-forwarding patterns that signal a compromised Microsoft 365 mailbox.
Cloud Security
Non-interactive sign-ins are logins performed on your behalf by an app or a token, and Entra ID hides them on a separate tab most people never open. That is exactly where a stolen session token reuses your identity after MFA is already satisfied.
Best Practices
How often to scan your cloud environment: identity daily, configuration and exposure weekly, compliance monthly, plus re-scans after every change event.
Cloud Security
Microsoft 365 Copilot did not create your oversharing problem. It inherited a decade of it and gave every employee a conversational way to surface it in seconds. Here is why Copilot exposes latent access risk, and how to govern it before rollout.
Cloud Security
Every external collaboration invites another guest into your tenant, and almost none of them ever leave. After auditing hundreds of Microsoft Entra ID tenants, guest sprawl is one of the most consistent and most ignored exposures we find.
Cloud Security
Storage accounts are where the data actually lives, which makes them the first thing attackers go after. After auditing hundreds of Azure subscriptions, the same six exposure patterns keep showing up.
Cloud Security
Key Vault is supposed to be the safe place for your secrets. After auditing hundreds of Azure subscriptions, the same misconfigurations keep showing up.
Cloud Security
Power Apps and Power Automate let anyone in your tenant build apps that touch sensitive data. Here is how citizen development becomes the new shadow IT.
Cloud Security
Break glass accounts are your last way back into a locked-out Microsoft 365 tenant. Most are misconfigured in ways that turn the insurance policy into the breach itself.
Cloud Security
Every Microsoft 365 tenant has hundreds of service principals with quiet, excessive permissions. Here is how to find them and clean up.
Cloud Security
After auditing hundreds of Microsoft 365 tenants, the same Conditional Access misconfigurations show up over and over. Here are the seven that matter.
Page 2 of 5