詳細検索
Avatar

西田

Preventing Cloud Privilege Bloat: A JIT/PIM Design Guide for Azure, AWS, and GCP

Preventing Cloud Privilege Bloat: A JIT/PIM Design Guide for Azure, AWS, and GCP

Explains the design of using Azure's Entra PIM, AWS's IAM Identity Center, and GCP's conditional IAM to make cloud permissions "limited". This is a practical guide to how to prevent privilege bloat and attack surface expansion. |Colorkrew Security

What are typical patterns of AWS security breaches? CloudTrail× GuardDuty Practice Checklist

What are typical patterns of AWS security breaches? CloudTrail× GuardDuty Practice Checklist

Almost all breaches of AWS are access key leakage, excessive authority, IAM, and S3 misdisclosure. Continuous monitoring combined with CloudTrail and GuardDuty provides a checklist of practices to efficiently close common entry points. |Colorkrew Security

GCP Security Pitfalls: A Practical Checklist to Prevent with Service Accounts, IAM, and Audit Logs

GCP Security Pitfalls: A Practical Checklist to Prevent with Service Accounts, IAM, and Audit Logs

GCP security incidents are mainly caused by service account key leakage, IAM overprivileges, and lack of audit logs. Learn IAM design best practices and practical steps to enable Cloud Audit Logs in a checklist format. |Colorkrew Security

How does API key token leakage work? Practical Secrets Management from GitHub to CI/CD

How does API key token leakage work? Practical Secrets Management from GitHub to CI/CD

We will explain the four paths of Secrets leakage, such as API key miscommit to Git repositories and CI/CD log leaks, and the creation of a practical mechanism to protect them through three layers: prevention, detection, and rotation. |Colorkrew Security

The Complete Guide to API Security|5 Threats and Unbreakable Design After Authentication

The Complete Guide to API Security|5 Threats and Unbreakable Design After Authentication

"Safe because I authenticated with an API key" is a misconception. We will explain five threats that lurk after authentication, such as BOLA, insufficient rate limiting, input verification omissions, excessive information responses, and lack of audit logs, as well as implementation points for an unbreakable design. |Colorkrew Security

How to Use Microsoft Sentinel|What is Automation Design to Avoid Missing Critical Incidents?

How to Use Microsoft Sentinel|What is Automation Design to Avoid Missing Critical Incidents?

Experts will explain the setting conditions and "three principles" to ensure that serious incidents are not overlooked regarding automatic closing of alerts, which is an issue in SOC operations. The secrets of safe automation design, such as the importance of Severity limited and logging and weekly reviews to prevent accidents, are now available. Dramatically improve your own operations. |Colorkrew Security

3 KQL templates that can be used with Microsoft Sentinel! Tips for speeding up incident investigations

3 KQL templates that can be used with Microsoft Sentinel! Tips for speeding up incident investigations

A collection of KQL templates for combat that dramatically streamline investigations in Microsoft Sentinel and Defender. Active engineers publish queries that instantly identify suspicious behavior from three starting points: sign-in, terminal, and email. What are the tips for speeding up initial response by 10 times and standardizing security operations? |Colorkrew Security

Don't let Microsoft Sentinel end up being "just noisy." 3 tips to keep your operations from becoming a formality

Don't let Microsoft Sentinel end up being "just noisy." 3 tips to keep your operations from becoming a formality

Have you adopted Microsoft Sentinel but are tired of dealing with a high volume of alerts? A security engineer explains the key points of prioritizing rules, tuning to suit the environment, and notification design to avoid becoming a "noisy SIEM". Here are some practical improvement approaches that don't make operations a reality. |Colorkrew Security

What should Zero Trust do after all? Explanation of practical steps to start in the field

What should Zero Trust do after all? Explanation of practical steps to start in the field

What does Zero Trust do? From the essence of the concept to MFA, device management, and data protection, we will explain the practical points that can be started in the field|Colorkrew Security

Will AI replace SOC? What is the realistic future for corporate security operations?

Will AI replace SOC? What is the realistic future for corporate security operations?

Will AI replace SOC? In this article, we will sort out the areas of AI's strengths and weaknesses, explain the differences from the judgment work that SOCs are responsible for, and the areas that can be strengthened by using AI|Colorkrew Security

What is the problem of being able to analyze logs but not being able to judge? Essential Challenges of Enterprise SOCs

What is the problem of being able to analyze logs but not being able to judge? Essential Challenges of Enterprise SOCs

Logs can be analyzed, but they cannot determine whether they are a threat - a "decision-making barrier" that many companies face. Explanation of how to mature SOC through judgment criteria, risk assessment, and knowledge|Colorkrew Security

New design for log operations optimization with Microsoft Sentinel × Data Lake

New design for log operations optimization with Microsoft Sentinel × Data Lake

Microsoft Sentinel and Azure Data Lake Storage work together to optimize costs and provide analytics foundation flexibility. Explaining the latest design that separates real-time detection from long-term storage|Colorkrew Security