Explains the design of using Azure's Entra PIM, AWS's IAM Identity Center, and GCP's conditional IAM to make cloud permissions "limited". This is a practical guide to how to prevent privilege bloat and attack surface expansion. |Colorkrew Security
Almost all breaches of AWS are access key leakage, excessive authority, IAM, and S3 misdisclosure. Continuous monitoring combined with CloudTrail and GuardDuty provides a checklist of practices to efficiently close common entry points. |Colorkrew Security
GCP security incidents are mainly caused by service account key leakage, IAM overprivileges, and lack of audit logs. Learn IAM design best practices and practical steps to enable Cloud Audit Logs in a checklist format. |Colorkrew Security
We will explain the four paths of Secrets leakage, such as API key miscommit to Git repositories and CI/CD log leaks, and the creation of a practical mechanism to protect them through three layers: prevention, detection, and rotation. |Colorkrew Security
"Safe because I authenticated with an API key" is a misconception. We will explain five threats that lurk after authentication, such as BOLA, insufficient rate limiting, input verification omissions, excessive information responses, and lack of audit logs, as well as implementation points for an unbreakable design. |Colorkrew Security
Experts will explain the setting conditions and "three principles" to ensure that serious incidents are not overlooked regarding automatic closing of alerts, which is an issue in SOC operations. The secrets of safe automation design, such as the importance of Severity limited and logging and weekly reviews to prevent accidents, are now available. Dramatically improve your own operations. |Colorkrew Security
A collection of KQL templates for combat that dramatically streamline investigations in Microsoft Sentinel and Defender. Active engineers publish queries that instantly identify suspicious behavior from three starting points: sign-in, terminal, and email. What are the tips for speeding up initial response by 10 times and standardizing security operations? |Colorkrew Security
Have you adopted Microsoft Sentinel but are tired of dealing with a high volume of alerts? A security engineer explains the key points of prioritizing rules, tuning to suit the environment, and notification design to avoid becoming a "noisy SIEM". Here are some practical improvement approaches that don't make operations a reality. |Colorkrew Security
What does Zero Trust do? From the essence of the concept to MFA, device management, and data protection, we will explain the practical points that can be started in the field|Colorkrew Security
Will AI replace SOC? In this article, we will sort out the areas of AI's strengths and weaknesses, explain the differences from the judgment work that SOCs are responsible for, and the areas that can be strengthened by using AI|Colorkrew Security
Logs can be analyzed, but they cannot determine whether they are a threat - a "decision-making barrier" that many companies face. Explanation of how to mature SOC through judgment criteria, risk assessment, and knowledge|Colorkrew Security
Microsoft Sentinel and Azure Data Lake Storage work together to optimize costs and provide analytics foundation flexibility. Explaining the latest design that separates real-time detection from long-term storage|Colorkrew Security