Research catalogue
Publications
6 open-access demonstration publications for people responsible for cloud control evidence.
From the desk
6 publicationsThe permission path you didn’t review
Cross-account trust rarely fails at the obvious policy. The risk lives in the path between identities, conditions, and inherited access.
Identity & access · AWS · By Umair Akbar and Ahmed ElshekhCloud logs that never reach the SIEM
A dashboard can be healthy while the evidence behind it is incomplete. Coverage needs to be tested from event creation to searchable record.
Detection & response · AWS / Azure / Google Cloud · By Umair Akbar and Ahmed ElshekhWhat changes when static keys disappear
Workload identity removes a secret, but it also moves trust into issuers, claims, audiences, and runtime attachment points.
Identity & access · Workload security · AWS / Azure / Google Cloud · By Umair Akbar and Ahmed ElshekhFive Kubernetes events your cloud trail will not explain
Cloud control-plane logs tell you who changed the cluster. They do not fully explain what happened inside it.
Detection & response · Workload security · Kubernetes · By Umair Akbar and Ahmed ElshekhThreat-model the system around the model
The model endpoint is one component. The consequential paths often run through retrieval stores, orchestration identities, evaluation data, and operator tools.
AI systems · AWS / Azure / Google Cloud · By Umair Akbar and Ahmed ElshekhRecover the control plane before you need it
A recovery plan that depends on the compromised identity system is an aspiration. Build and test an independent administrative path.
Resilience · Identity & access · AWS / Azure / Google Cloud · By Umair Akbar and Ahmed Elshekh