Evidence search
Search
Search titles, summaries, topics, providers, authors, and the full open-access corpus.
Results for “admin”
77 publicationsRecover a deleted Azure blob with soft delete
Choose the right recovery action for a blob, version or container and verify restored bytes.
Resilience · Azure · By Cloud Security DeskRecover a deleted Azure Key Vault secret
Distinguish secret recovery from vault recovery and verify versioned application references.
Resilience · Azure · By Cloud Security DeskDesign application authorization before writing Cedar policies
Define business actions, trustworthy entities and tenant boundaries before writing Cedar policies, then make the application responsible for enforcing the resulting decision.
Identity & access · AWS / Cedar · By Cloud Security DeskKeep Kubernetes audit records useful without logging secrets
Design a question-led Kubernetes audit policy with explicit body limits, rule precedence, lifecycle stages and provider-specific acceptance checks.
Detection & response · Kubernetes / AWS / Azure / Google Cloud · By Cloud Security DeskKeep Terraform plans and state inside the change boundary
Protect Terraform plans and state as sensitive artifacts, and bind production approval to the specific plan, dependencies, workspace and apply identity that will be used.
Workload security · HashiCorp / AWS · By Cloud Security DeskMake PostgreSQL point in time recovery reproducible
Build a version-aware recovery chain from protected base backups and WAL through timeline selection, isolated replay and application acceptance.
Resilience · PostgreSQL · By Cloud Security DeskChoose who can share an inference prefix cache
Choose the principals allowed to share prefix state, then carry that decision through request routing, offload, transfer and restore.
AI systems · vLLM / NVIDIA · By Cloud Security DeskSet explicit trust boundaries for Entra partner access
Accepting another tenant’s authentication claims is a specific trust decision, not blanket approval of its users, devices or access to your applications.
Identity & access · Microsoft · By Cloud Security DeskEmbeddings still need a sensitive data boundary
Treat vector access as a derived-data release decision, with separate permissions for retrieval, debugging and bulk export.
AI systems · By Cloud Security DeskKeep build credentials out of the image and its evidence
A temporary BuildKit secret mount controls credential delivery, not everything a build command can do with the credential or leave in its outputs.
Workload security · Docker / GitHub · By Cloud Security DeskGive persistent agent memory an admission boundary
Separate conversational candidates from admitted memory, preserve their permitted audience, and make derived summaries repairable.
AI systems · LangChain · By Cloud Security DeskKeep S3 presigned access inside an explicit delegation window
Treat an S3 presigned URL as a reusable delegation whose usable lifetime depends on the signer, the request and the policies that still apply.
Identity & access · AWS · By Cloud Security DeskFind the Purview audit history your investigation can still retrieve
Resolve Purview audit availability at the record level by separating actor eligibility, retention policy, collection status, investigator scope and export limits.
Detection & response · Microsoft Purview / Microsoft 365 · By Cloud Security DeskDesign RDS IAM authentication around the connection pool
Generate IAM database tokens for the physical connections that need them, and keep token validity separate from the lifetime of an already-established SQL session.
Workload security · AWS · By Cloud Security DeskProve Identity Center permission changes reached every account
A permission-set change is complete only when the intended accounts, account-local policies, provisioning results and assignments have converged.
Identity & access · AWS · By Cloud Security DeskInvestigate denied access at an AWS VPC endpoint
Use CloudTrail network activity evidence to distinguish endpoint-policy violations from routing failures and downstream authorization problems.
Detection & response · AWS · By Cloud Security DeskRestrict device code sign-in without breaking approved clients
Restrict device-code authentication through an explicit client and resource policy, and test the tracked sessions that can outlive the initial browser approval.
Identity & access · Microsoft / IETF · By Cloud Security DeskKeep GitHub audit streaming continuous across maintenance
Plan audit-stream maintenance around native history, pause buffers, receiver acceptance and duplicate-aware evidence receipts.
Detection & response · GitHub / AWS · By Cloud Security DeskGive Kubernetes admission webhooks an explicit failure contract
Treat an admission webhook as a control-plane dependency with explicit behavior for denial, call failure, mutation and the changes needed to repair it.
Workload security · Kubernetes · By Cloud Security DeskFind the shared dependencies behind a cloud outage
Use the June 2025 Google Cloud and Cloudflare reports to review shared runtime, control, identity and recovery dependencies without turning one outage into a provider ranking.
Resilience · Google Cloud / Cloudflare / AWS · By Cloud Security DeskPasskey deployment needs a recovery design
A workforce passkey rollout needs a recovery contract before broad enforcement. Separate credential custody, enrollment evidence and application sessions.
Identity & access · NIST / FIDO Alliance / Microsoft Entra · By Cloud Security DeskWorkload federation across clouds needs separate trust decisions
Cross-cloud federation adds trust decisions, not a portable permission system. Map each credential and resource grant before moving a runtime workload.
Identity & access · AWS / Google Cloud / Microsoft Entra · By Cloud Security DeskA defensible cloud patch queue starts with exploitation evidence
Join exploitation evidence to affected assets, exposure, ownership and verified remediation without turning CVSS, EPSS or a catalog entry into a complete risk score.
Detection & response · CISA / NIST / FIRST · By Cloud Security DeskChoosing isolation for a Kubernetes tenant
A namespace, a virtual control plane and a sandboxed runtime protect different boundaries. Start with tenant authority before choosing the cluster architecture.
Workload security · Kubernetes / gVisor / Kata Containers · By Cloud Security Desk