Skip to content
Cloud Security DeskSearch
Menu

Evidence search

Search

Search titles, summaries, topics, providers, authors, and the full open-access corpus.

Results for “role”

84 publications
Technical guideSource-based analysis

Entra emergency access that survives normal sign-in failure

A second administrator account does not prove an independent recovery path. Test the credential, workstation, policy and alert dependencies together.

Identity & access · Microsoft Entra · By Cloud Security Desk
Technical guideSource-based analysis

What cloud snapshots cannot preserve

Separate live execution, persisted disk and provider records before an authorized containment decision destroys evidence that a snapshot cannot recover.

Detection & response · AWS / NIST · By Cloud Security Desk
Technical guideSource-based analysis

Make secret rotation reach every running application

Secret managers, mounted files, application memory and connection pools can disagree about the active credential. Test each stage before calling rotation complete.

Workload security · Kubernetes / AWS / Azure / Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Testing Sigma detections before a backend change

Keep rule structure, field transformations, query conversion and event matching as separate checks when changing a Sigma detection backend.

Detection & response · SigmaHQ · By Cloud Security Desk
Technical guideSource-based analysis

Design an outbound fetch service that contains SSRF

A URL check is only the first decision. The fetch worker must contact the approved destination, recheck redirects and limit the authority of every request.

Workload security · OWASP / IANA · By Cloud Security Desk
Technical guideSource-based analysis

Error budgets for controlled service degradation

Protect essential work under load while counting rejected and degraded requests against the service promise that users were actually given.

Resilience · Google / Envoy · By Cloud Security Desk
Technical guideSource-based analysis

Short SSH certificates still need explicit access boundaries

An SSH certificate supplies bounded identity claims. The issuer, server, client and incident operator still make separate access decisions.

Identity & access · OpenSSH · By Cloud Security Desk
Technical guideSource-based analysis

Cloud incident severity needs a service impact model

Connect incident priority to service consequences, scope and time criticality while preserving evidence confidence and the authority to revise the decision.

Detection & response · NIST / FIRST · By Cloud Security Desk
Technical guideSource-based analysis

Certificate renewal under shorter validity limits

Use the public TLS issuance schedule to review authorization, renewal, deployment and independent verification of the certificate an endpoint actually serves.

Resilience · CA/Browser Forum / Let's Encrypt / AWS · By Cloud Security Desk
Technical guideSource-based analysis

The telemetry collector is part of the evidence boundary

Review sender identity, tenant routing, processing and export as separate trust boundaries before treating collected telemetry as dependable evidence.

Detection & response · OpenTelemetry · By Cloud Security Desk
Technical guideSource-based analysis

Prepare cloud workloads for hybrid post-quantum TLS

Hybrid support in a library is not proof that every TLS hop uses it. Verify negotiation, compatibility and fallback while keeping certificate authentication separate.

Workload security · IETF / NIST / OpenSSL / Cloudflare · By Cloud Security Desk
Technical guideSource-based analysis

Know when AWS KMS encryption needs an envelope

KMS Encrypt has small plaintext limits. Follow the data key and encrypted-message format when an application needs to protect larger payloads.

Workload security · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Model output needs its own trust boundary

A model can produce valid JSON containing an unauthorized identifier, an unsafe link or text that a renderer interprets as code. The application consuming that output owns the next trust decision.

AI systems · OpenAI · By Cloud Security Desk
Technical guideSource-based analysis

Map every connection beyond the private AI endpoint

Trace inference, retrieval, tools, administration, and telemetry separately before describing an AI application as private.

AI systems · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Prove Azure Storage private access from DNS to authorization

Check the exact storage subresource, resolve its normal hostname from the application, and test public access and data permissions as separate boundaries.

Workload security · Azure · By Cloud Security Desk
Technical guideSource-based analysis

Build an Azure change record that survives the portal window

Activity Log records and resource logs answer different questions. Preserve the operation outcome, resource context and export scope needed for a later investigation.

Detection & response · Azure · By Cloud Security Desk
Technical guideSource-based analysis

Trace Google service account impersonation across every hop

A short-lived token can carry a broad identity. Review who can mint it, which account it represents and whether the original caller remains visible.

Identity & access · Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Keep sensitive prompts out of routine telemetry

Collect diagnostic metadata for a defined purpose and treat prompts, retrieved documents, tool arguments, and responses as a separate content-capture decision.

AI systems · AWS · By Cloud Security Desk
Research noteSource-based analysis

Place AWS guardrails on the principal and the resource

SCPs and RCPs constrain different sides of a request. A useful review records both the applicable guardrails and the policies that actually grant access.

Identity & access · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Keep encryption keys recoverable with the data they protect

Trace each encrypted recovery point to its required key, usable lifecycle state, and restore permissions before retiring cryptographic dependencies.

Resilience · AWS / Azure · By Cloud Security Desk
Technical guideSource-based analysis

Put enforceable boundaries around agent tool calls

Treat model proposals as requests for authority, then check the operation, resource, recipient, and approval at the point where a tool can create a side effect.

AI systems · AWS · By Cloud Security Desk
Research noteSource-based analysis

Find the Google audit logs missing from your evidence window

Audit category, inherited configuration, destination and reader permissions all affect what an investigator can retrieve. Retention is only one part of the record.

Detection & response · Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Review the authority behind every Entra app consent

The permission name is only part of the decision. Review the access mode, resource scope, consenting authority and people who can change the application.

Identity & access · Microsoft Entra · By Cloud Security Desk
Technical guideSource-based analysis

Make regional failover work without new infrastructure

Prepare capacity, dependencies, and the routing control path before an incident, then measure when clients reach an accepted recovery service.

Resilience · AWS · By Cloud Security Desk