Skip to content
Cloud Security DeskSearch
Menu

Evidence search

Search

Search titles, summaries, topics, providers, authors, and the full open-access corpus.

Results for “Azure”

34 publications
Technical guideSource-based analysis

Prove Azure Storage private access from DNS to authorization

Check the exact storage subresource, resolve its normal hostname from the application, and test public access and data permissions as separate boundaries.

Workload security · Azure · By Cloud Security Desk
Technical guideSource-based analysis

Build an Azure change record that survives the portal window

Activity Log records and resource logs answer different questions. Preserve the operation outcome, resource context and export scope needed for a later investigation.

Detection & response · Azure · By Cloud Security Desk
Research noteSource-based analysis

Stop retries from amplifying an outage

Count attempts across the complete request path, give retries a finite owner and budget, and define how repeated intent avoids duplicate side effects.

Resilience · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Keep encryption keys recoverable with the data they protect

Trace each encrypted recovery point to its required key, usable lifecycle state, and restore permissions before retiring cryptographic dependencies.

Resilience · AWS / Azure · By Cloud Security Desk
Research noteSource-based analysis

Define the expiry boundary for Entra privileged access

PIM records activation and expiry, but the protected application still determines when changed authority takes effect. Review both sides of that boundary.

Identity & access · Microsoft Entra · By Cloud Security Desk
Technical guideSource-based analysis

Keep private documents out of shared RAG answers

Authorize retrieved documents before they enter model context, preserve permissions on chunks, and make source access changes visible in the retrieval path.

AI systems · Azure · By Cloud Security Desk
Visual briefIllustrative analysis

Cloud logs that never reach the SIEM

A dashboard can be healthy while the evidence behind it is incomplete. Coverage needs to be tested from event creation to searchable record.

Detection & response · AWS / Azure / Google Cloud · By Umair Akbar and Ahmed Elshekh
Technical guideIllustrative analysis

What changes when static keys disappear

Workload identity removes a secret, but it also moves trust into issuers, claims, audiences, and runtime attachment points.

Identity & access · Workload security · AWS / Azure / Google Cloud · By Umair Akbar and Ahmed Elshekh
Research noteIllustrative analysis

Threat-model the system around the model

The model endpoint is one component. The consequential paths often run through retrieval stores, orchestration identities, evaluation data, and operator tools.

AI systems · AWS / Azure / Google Cloud · By Umair Akbar and Ahmed Elshekh
Technical guideIllustrative analysis

Recover the control plane before you need it

A recovery plan that depends on the compromised identity system is an aspiration. Build and test an independent administrative path.

Resilience · Identity & access · AWS / Azure / Google Cloud · By Umair Akbar and Ahmed Elshekh