Securing Service Principals
How Entra ID App Registrations / Enterprise Applications are comonly misconfigured and can be used by attackers to elevate privileges, access sensitive information and move laterally across Azure tenancies.
How Entra ID App Registrations / Enterprise Applications are comonly misconfigured and can be used by attackers to elevate privileges, access sensitive information and move laterally across Azure tenancies.
Snotra now supports kubernetes!
Exploiting overly permissive VPC endpoints to exfiltrate data from private AWS subnets
Simple method to define and build security testing containers in Podman
Attacking AWS Accounts from a black box perspective
Using Snotra to Check For Sensitive Tags
Making Sense of Logging in Azure with Azure Monitor, Diagnostic Settings and Activity Log Alerts
AWS and overly permissive GitHub OIDC cross-account role trust policies
Blog post about Kubernetes Security Fundementals
Blog post about Cloud Configuration Reviews