Skip to content
Cloud Security DeskSearch
Menu

Evidence search

Search

Search titles, summaries, topics, providers, authors, and the full open-access corpus.

Results for “rate”

125 publications
Technical guideSource-based analysis

Check and stop anonymous access to Azure blobs

Understand account and container settings and prove both anonymous denial and intended app access.

Workload security · Azure · By Cloud Security Desk
Technical guideSource-based analysis

Restrict SSH and RDP access with an Azure network security group

Inspect effective rules, preserve the approved management path and test a fresh connection.

Workload security · Azure · By Cloud Security Desk
Technical guideSource-based analysis

Handle Azure OpenAI rate limits without retry storms

Separate deployment quota, short request bursts and bounded client retry behavior.

AI systems · Azure · By Cloud Security Desk
Technical guideSource-based analysis

Connect to Azure OpenAI without an API key

Prove Entra-based inference with a scoped runtime identity before disabling local authentication.

AI systems · Azure · By Cloud Security Desk
Technical guideSource-based analysis

Recover a deleted Azure blob with soft delete

Choose the right recovery action for a blob, version or container and verify restored bytes.

Resilience · Azure · By Cloud Security Desk
Technical guideSource-based analysis

Recover a deleted Azure Key Vault secret

Distinguish secret recovery from vault recovery and verify versioned application references.

Resilience · Azure · By Cloud Security Desk
Technical guideSource-based analysis

Design application authorization before writing Cedar policies

Define business actions, trustworthy entities and tenant boundaries before writing Cedar policies, then make the application responsible for enforcing the resulting decision.

Identity & access · AWS / Cedar · By Cloud Security Desk
Technical guideSource-based analysis

Keep Kubernetes audit records useful without logging secrets

Design a question-led Kubernetes audit policy with explicit body limits, rule precedence, lifecycle stages and provider-specific acceptance checks.

Detection & response · Kubernetes / AWS / Azure / Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Keep Terraform plans and state inside the change boundary

Protect Terraform plans and state as sensitive artifacts, and bind production approval to the specific plan, dependencies, workspace and apply identity that will be used.

Workload security · HashiCorp / AWS · By Cloud Security Desk
Technical guideSource-based analysis

Bind confidential GPU inference to a verified key release

Require composite evidence, owner policy and verified recipient binding before confidential inference receives protected key material.

AI systems · NVIDIA / Azure · By Cloud Security Desk
Technical guideSource-based analysis

Make PostgreSQL point in time recovery reproducible

Build a version-aware recovery chain from protected base backups and WAL through timeline selection, isolated replay and application acceptance.

Resilience · PostgreSQL · By Cloud Security Desk
Technical guideSource-based analysis

Choose who can share an inference prefix cache

Choose the principals allowed to share prefix state, then carry that decision through request routing, offload, transfer and restore.

AI systems · vLLM / NVIDIA · By Cloud Security Desk
Technical guideSource-based analysis

Set explicit trust boundaries for Entra partner access

Accepting another tenant’s authentication claims is a specific trust decision, not blanket approval of its users, devices or access to your applications.

Identity & access · Microsoft · By Cloud Security Desk
Technical guideSource-based analysis

Read VPC Flow Logs without overclaiming network evidence

Interpret aggregation, address translation, skipped records and delivery clocks before turning a VPC flow record into an incident conclusion.

Detection & response · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Separate webhook authenticity from permission to process it

Verify webhook authenticity at intake, then make durable acceptance, duplicate handling and permission to change business state separate decisions.

Workload security · Stripe / GitHub / IETF · By Cloud Security Desk
Research noteSource-based analysis

Embeddings still need a sensitive data boundary

Treat vector access as a derived-data release decision, with separate permissions for retrieval, debugging and bulk export.

AI systems · By Cloud Security Desk
Technical guideSource-based analysis

Plan Kubernetes drains around the disruption budget

Review selector scope, current status, unhealthy Pod handling and replacement capacity before treating a blocked drain as a reason to bypass availability controls.

Resilience · Kubernetes · By Cloud Security Desk
Technical guideSource-based analysis

Bind OAuth tokens to the client that presents them

DPoP can make possession of an access token insufficient for use, provided the issuer, client and resource server implement the same proof and key-binding contract.

Identity & access · IETF / Google · By Cloud Security Desk
Technical guideSource-based analysis

Catch late security events without replaying every alert

Separate event time, ingestion time and execution health so delayed records can be evaluated without turning every broader lookback into a replay.

Detection & response · Microsoft Sentinel / Microsoft Defender · By Cloud Security Desk
Technical guideSource-based analysis

Keep build credentials out of the image and its evidence

A temporary BuildKit secret mount controls credential delivery, not everything a build command can do with the credential or leave in its outputs.

Workload security · Docker / GitHub · By Cloud Security Desk
Technical guideSource-based analysis

Give persistent agent memory an admission boundary

Separate conversational candidates from admitted memory, preserve their permitted audience, and make derived summaries repairable.

AI systems · LangChain · By Cloud Security Desk
Technical guideSource-based analysis

Diagnose NAT gateway port exhaustion before adding capacity

Match allocation errors to destination tuples and gateway mode before changing connection pools, addresses or routes.

Resilience · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Keep S3 presigned access inside an explicit delegation window

Treat an S3 presigned URL as a reusable delegation whose usable lifetime depends on the signer, the request and the policies that still apply.

Identity & access · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Find the Purview audit history your investigation can still retrieve

Resolve Purview audit availability at the record level by separating actor eligibility, retention policy, collection status, investigator scope and export limits.

Detection & response · Microsoft Purview / Microsoft 365 · By Cloud Security Desk