Evidence search
Search
Search titles, summaries, topics, providers, authors, and the full open-access corpus.
Results for “admin”
77 publicationsRecovery objectives that match the cloud service
Define the business function, outage clock, recoverable data and dependency assumptions before choosing a cloud disaster-recovery architecture.
Resilience · AWS / Azure / Google Cloud / NIST · By Cloud Security DeskEntra emergency access that survives normal sign-in failure
A second administrator account does not prove an independent recovery path. Test the credential, workstation, policy and alert dependencies together.
Identity & access · Microsoft Entra · By Cloud Security DeskWhat cloud snapshots cannot preserve
Separate live execution, persisted disk and provider records before an authorized containment decision destroys evidence that a snapshot cannot recover.
Detection & response · AWS / NIST · By Cloud Security DeskMake secret rotation reach every running application
Secret managers, mounted files, application memory and connection pools can disagree about the active credential. Test each stage before calling rotation complete.
Workload security · Kubernetes / AWS / Azure / Google Cloud · By Cloud Security DeskRotate Entra application certificates with proof of adoption
A renewed certificate can exist in Key Vault while a running client still uses the old key. Define the evidence that makes application rotation complete.
Identity & access · Microsoft Entra / Azure Key Vault · By Cloud Security DeskTesting Sigma detections before a backend change
Keep rule structure, field transformations, query conversion and event matching as separate checks when changing a Sigma detection backend.
Detection & response · SigmaHQ · By Cloud Security DeskDesign an outbound fetch service that contains SSRF
A URL check is only the first decision. The fetch worker must contact the approved destination, recheck redirects and limit the authority of every request.
Workload security · OWASP / IANA · By Cloud Security DeskError budgets for controlled service degradation
Protect essential work under load while counting rejected and degraded requests against the service promise that users were actually given.
Resilience · Google / Envoy · By Cloud Security DeskShort SSH certificates still need explicit access boundaries
An SSH certificate supplies bounded identity claims. The issuer, server, client and incident operator still make separate access decisions.
Identity & access · OpenSSH · By Cloud Security DeskCloud incident severity needs a service impact model
Connect incident priority to service consequences, scope and time criticality while preserving evidence confidence and the authority to revise the decision.
Detection & response · NIST / FIRST · By Cloud Security DeskCertificate renewal under shorter validity limits
Use the public TLS issuance schedule to review authorization, renewal, deployment and independent verification of the certificate an endpoint actually serves.
Resilience · CA/Browser Forum / Let's Encrypt / AWS · By Cloud Security DeskMeasure SCIM offboarding at the application
A successful provisioning update proves a directory action, not the end of every application session. Define and test the application's offboarding contract.
Identity & access · SCIM / Microsoft Entra · By Cloud Security DeskCloud detection coverage after the ATT&CK data model change
Connect current ATT&CK strategies and analytics to available events, implemented rules and test evidence, while keeping taxonomy counts separate from protection.
Detection & response · MITRE · By Cloud Security DeskKeep database changes compatible with application rollback
Preserve an explicit relationship between old code and migrated state through additive changes, safe backfills, and a defined rollback window.
Resilience · Kubernetes / GitLab · By Cloud Security DeskMap every connection beyond the private AI endpoint
Trace inference, retrieval, tools, administration, and telemetry separately before describing an AI application as private.
AI systems · AWS · By Cloud Security DeskBuild an Azure change record that survives the portal window
Activity Log records and resource logs answer different questions. Preserve the operation outcome, resource context and export scope needed for a later investigation.
Detection & response · Azure · By Cloud Security DeskTrace Google service account impersonation across every hop
A short-lived token can carry a broad identity. Review who can mint it, which account it represents and whether the original caller remains visible.
Identity & access · Google Cloud · By Cloud Security DeskKeep encryption keys recoverable with the data they protect
Trace each encrypted recovery point to its required key, usable lifecycle state, and restore permissions before retiring cryptographic dependencies.
Resilience · AWS / Azure · By Cloud Security DeskFind the Google audit logs missing from your evidence window
Audit category, inherited configuration, destination and reader permissions all affect what an investigator can retrieve. Retention is only one part of the record.
Detection & response · Google Cloud · By Cloud Security DeskReview the authority behind every Entra app consent
The permission name is only part of the decision. Review the access mode, resource scope, consenting authority and people who can change the application.
Identity & access · Microsoft Entra · By Cloud Security DeskMake regional failover work without new infrastructure
Prepare capacity, dependencies, and the routing control path before an incident, then measure when clients reach an accepted recovery service.
Resilience · AWS · By Cloud Security DeskRequire EC2 IMDSv2 without breaking container credentials
Separate metadata token requirements from response hop limits, then verify both existing instances and future launches before declaring the migration complete.
Workload security · AWS · By Cloud Security DeskDefine the expiry boundary for Entra privileged access
PIM records activation and expiry, but the protected application still determines when changed authority takes effect. Review both sides of that boundary.
Identity & access · Microsoft Entra · By Cloud Security DeskKeep MCP tokens bound to the intended resource
Keep token audiences, user consent, and downstream tool authority separate when reviewing a protected HTTP MCP service.
AI systems · MCP · By Cloud Security Desk