Evidence search
Search
Search titles, summaries, topics, providers, authors, and the full open-access corpus.
Results for “vm”
14 publicationsRemove public SSH access from an EC2 security group
Remove internet-wide EC2 SSH rules after testing Session Manager or restricted SSH. Check all groups, IPv6, fresh sessions, and recovery access.
Workload security · AWS · By Cloud Security DeskConnect to a Google Cloud VM with IAP and OS Login
Connect to a Linux VM through IAP and OS Login, check each permission and network layer, and remove old SSH paths with a tested recovery plan.
Identity & access · Google Cloud · By Cloud Security DeskTriage a Google Cloud Security Command Center finding
Review a Security Command Center finding, choose repair or a documented exception, and distinguish resource verification from muting and closure.
Detection & response · Google Cloud · By Cloud Security DeskRead an Azure Key Vault secret from a VM without a password
Set up one system-assigned VM identity and a vault-scoped secret permission.
Identity & access · Azure · By Cloud Security DeskFind why an Azure VM cannot reach a service
Use a specific source and destination with Network Watcher and separate network reachability from app health.
Detection & response · Azure · By Cloud Security DeskRestrict SSH and RDP access with an Azure network security group
Inspect effective rules, preserve the approved management path and test a fresh connection.
Workload security · Azure · By Cloud Security DeskRecover a deleted Azure Key Vault secret
Distinguish secret recovery from vault recovery and verify versioned application references.
Resilience · Azure · By Cloud Security DeskIsolate document parsing before RAG ingestion
Give document parsing a bounded worker, then admit its extracted content separately before embedding or indexing.
AI systems · Apache Tika / Kubernetes / gVisor · By Cloud Security DeskFinish S3 multipart uploads with verifiable object integrity
Keep an owned part manifest and verify the complete object result, because successful part transfers and an initial HTTP 200 are not sufficient completion evidence.
Workload security · AWS · By Cloud Security DeskWorkload federation across clouds needs separate trust decisions
Cross-cloud federation adds trust decisions, not a portable permission system. Map each credential and resource grant before moving a runtime workload.
Identity & access · AWS / Google Cloud / Microsoft Entra · By Cloud Security DeskChoosing isolation for a Kubernetes tenant
A namespace, a virtual control plane and a sandboxed runtime protect different boundaries. Start with tenant authority before choosing the cluster architecture.
Workload security · Kubernetes / gVisor / Kata Containers · By Cloud Security DeskMake secret rotation reach every running application
Secret managers, mounted files, application memory and connection pools can disagree about the active credential. Test each stage before calling rotation complete.
Workload security · Kubernetes / AWS / Azure / Google Cloud · By Cloud Security DeskShort SSH certificates still need explicit access boundaries
An SSH certificate supplies bounded identity claims. The issuer, server, client and incident operator still make separate access decisions.
Identity & access · OpenSSH · By Cloud Security DeskProve Azure Storage private access from DNS to authorization
Check the exact storage subresource, resolve its normal hostname from the application, and test public access and data permissions as separate boundaries.
Workload security · Azure · By Cloud Security Desk