Posts
All the articles I've posted.
Selecting more than one tag in the sidebar shows only posts that have every selected tag.
- #Blockchain#Hoodi#Validator
Hoodi Validator Use Cases and Data Flows
How Hoodi execution, consensus, validation, signing, and observability components exchange data in a Kubernetes-based validator platform.
3 min read - #Private Repository#DevSecOps#Supply Chain Security
Private Repositories Security Review Process
A practical process for reviewing, approving, and continuously reassessing third-party artifacts before internal use.
4 min read - #Hoodi#Validator#AWS
Audit and Logging Architecture for Hoodi Node Validator
How the Hoodi validator platform collects, protects, archives, and investigates AWS, Kubernetes, Vault, and validator evidence.
19 min read - #Vault#Kubernetes#Hoodi
cert-manager and Vault: Roles, Scope, and Collaboration
How cert-manager, Vault, Kubernetes, and AWS KMS work together to protect Vault transport, workload identity, and validator secrets.
15 min read - #Hoodi#Validator#AWS
Hoodi Node Validator AWS Architecture Overview
An overview of the private AWS infrastructure supporting Hoodi execution and consensus workloads on Amazon EKS.
8 min read - #Vault#Identity Management#Kubernetes
Identity Management Using Vault
How Vault, Kubernetes, AWS, and GitHub divide responsibility for workload, operator, and release identities.
7 min read - #Kubernetes#EKS#Hoodi
Kubernetes Namespace Design for a Hoodi Validator
A security-focused guide to designing Kubernetes namespace boundaries for a Hoodi validator architecture.
6 min read - #Vault#Kubernetes#EKS
Vault Architecture on Kubernetes
A practical guide to Vault architecture, workload identity, secret delivery, PKI, and operations on Kubernetes.
8 min read - #Vault#Ethereum#Hoodi
Vault Secret Management for Hoodi Validator
How Vault Agent delivers validator secrets for Engine API authentication, TLS, signing, and slashing protection.
8 min read - #Ethereum#Hoodi#Validator
How a Hoodi Validator Works with Nethermind and Prysm
An explanation of how Nethermind, Prysm, a remote signer, and slashing protection work together in a Hoodi validator.
10 min read - #AWS#ECR#EKS
Private ECR Delivery Architecture for Private EKS
A defense-in-depth design for delivering approved private ECR artifacts to private EKS workloads.
Updated:15 min read - #AWS#EKS#Kubernetes
EKS Security Controls Implemented in the Cluster Design
A technical overview of EKS security controls implemented across the cluster design.
8 min read - #Ethereum#Hoodi#AWS
Private EKS Security Design Review
A confidentiality-focused security design review of a private EKS environment.
10 min read - #Azure#Backup#Recovery
Adding an Azure Recovery Vault Protected Items Check to Prowler
How Prowler identifies Azure Recovery Services Vaults with no protected backup items.
2 min read - #Azure#Backup#Recovery
Adding an Azure Recovery Vault Retention Check to Prowler
How Prowler identifies Recovery Services Vault backup policies with insufficient retention.
2 min read - #Azure#PostgreSQL#Prowler
Adding an Azure PostgreSQL High Availability Check to Prowler
How Prowler identifies Azure Database for PostgreSQL Flexible Servers without enabled high availability.
2 min read - #Azure#PostgreSQL#Prowler
Adding an Azure PostgreSQL Geo-Redundant Backup Check to Prowler
How Prowler verifies that Azure Database for PostgreSQL Flexible Server backups are geo-redundant.
1 min read - #Azure#NetworkSecurity#DDoS
Adding an Azure VNet DDoS Protection Check to Prowler
How Prowler verifies that Azure virtual networks use DDoS Network Protection.
2 min read - #Azure#NetworkSecurity#NSG
Adding an Azure Subnet NSG Check to Prowler
How Prowler detects Azure virtual-network subnets that lack Network Security Group protection.
2 min read - #Azure#MySQL#Prowler
Adding an Azure MySQL High Availability Check to Prowler
How Prowler identifies Azure Database for MySQL Flexible Servers without failover-ready high availability.
2 min read - #Azure#MySQL#Prowler
Adding an Azure MySQL Geo-Redundant Backup Check to Prowler
How Prowler verifies that Azure Database for MySQL Flexible Server backups can survive a regional outage.
2 min read - #Azure#EntraID#Identity
Adding an Azure Entra Recent Sign-In Check to Prowler
How Prowler identifies enabled Microsoft Entra accounts that have not signed in within 90 days.
2 min read - #Azure#EntraID#Identity
Adding an Azure Entra Strong Authentication Check to Prowler
How Prowler verifies that Microsoft Entra tenants enable strong authentication methods and MFA registration enforcement.
2 min read - #Azure#EntraID#Identity
Adding an Azure Entra App Credential Expiry Check to Prowler
How Prowler identifies expired, soon-to-expire, and non-expiring credentials on Microsoft Entra app registrations.
2 min read - #Azure#MicrosoftDefender#Prowler
Adding an Azure Defender CSPM Check to Prowler
How Prowler verifies that Microsoft Defender Cloud Security Posture Management is enabled for an Azure subscription.
2 min read - #Azure#Databricks#Prowler
Adding an Azure Databricks No Public IP Check to Prowler
How Prowler verifies that Azure Databricks classic-compute workspaces use secure cluster connectivity.
2 min read - #Azure#Databricks#Prowler
Adding an Azure Databricks Public Network Access Check to Prowler
How Prowler identifies Azure Databricks workspaces that remain accessible through public network endpoints.
2 min read - #Azure#CosmosDB#Prowler
Adding an Azure Cosmos DB Public Network Access Check to Prowler
How Prowler identifies Cosmos DB accounts that remain reachable through public network endpoints.
2 min read - #Azure#CosmosDB#Prowler
Adding an Azure Cosmos DB Minimum TLS Check to Prowler
How Prowler identifies Cosmos DB accounts that still permit legacy TLS protocols for client connections.
2 min read - #Azure#CosmosDB#Prowler
Adding an Azure Cosmos DB Continuous Backup Check to Prowler
How Prowler identifies Cosmos DB accounts that lack continuous backup and point-in-time restore capability.
2 min read - #Azure#CosmosDB#Prowler
Adding an Azure Cosmos DB Automatic Failover Check to Prowler
How Prowler identifies Cosmos DB accounts that require manual intervention during a regional outage.
2 min read - #Azure#AKS#Kubernetes
Adding an Azure AKS Local Accounts Check to Prowler
How Prowler identifies AKS clusters that still allow local Kubernetes accounts to bypass Microsoft Entra ID authentication.
3 min read - #Azure#AKS#Kubernetes
Adding an Azure AKS Monitor Check to Prowler
How Prowler identifies AKS clusters without Azure Monitor managed Prometheus metrics enabled.
3 min read - #Azure#AKS#Kubernetes
Adding an Azure AKS Defender Check to Prowler
How Prowler identifies AKS clusters without Microsoft Defender for Containers security monitoring enabled.
3 min read - #Azure#AKS#Kubernetes
Adding an Azure AKS Auto-Upgrade Check to Prowler
How Prowler identifies AKS clusters without an automatic Kubernetes upgrade channel and helps prevent version drift.
3 min read - #GCP#Prowler#Contribution
Adding a GCP Secret Manager Rotation Check to Prowler
How Prowler verifies that Secret Manager secrets have automatic rotation configured within policy and have not missed their next rotation date.
3 min read - #GCP#Prowler#Contribution
Adding a GCP Secret Manager Public Access Check to Prowler
How Prowler identifies Secret Manager secrets whose IAM policies grant access to everyone or to every Google-authenticated user.
3 min read - #GCP#Prowler#Contribution
Adding a GCP Cloud SQL High Availability Check to Prowler
How Prowler identifies Cloud SQL primary instances that lack regional high availability and automatic zonal failover.
3 min read - #GCP#Prowler#Contribution
Adding a GCP Cloud SQL CMEK Check to Prowler
How Prowler identifies Cloud SQL instances that use Google-managed encryption keys instead of customer-managed keys in Cloud KMS.
4 min read - #GCP#Prowler#Contribution
Adding a GCP Cloud Functions Public Access Check to Prowler
How Prowler detects Cloud Functions that IAM policies make invokable by anyone on the internet or by any Google-authenticated user.
3 min read - #GCP#Prowler#Contribution
Adding a GCP Cloud Functions VPC Check to Prowler
How Prowler's new Cloud Functions VPC connector check helps find missing private-network boundaries in GCP serverless workloads.
3 min read - #Contribution#Supply Chain Security#NIST SP 800-204
Private Registries and Package Mirrors: What I Contributed to the SEAL Security Frameworks
A new SEAL Security Frameworks page on internal package registries - what mirroring defends against, how routing blocks dependency confusion, and why the registry becomes a trust component in its own right.
11 min read - #Contribution#CI/CD Security#Supply Chain Security
Policy as Code Through the CI/CD Pipeline: What I Contributed to the SEAL Security Frameworks
A four-page section on policy as code across the CI/CD pipeline, mapped to NIST SP 800-204D, merged into the SEAL Security Frameworks.
11 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (10) - Regulatory Overlays
Applying PIPA/ISMS-P and customer contractual obligations on top of the EKS SaaS baseline, and why tenant deletion is a control-plane workflow, not a single DynamoDB delete.
3 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (9) - CI/CD Verification
Gating EKS SaaS deployments on requirement IDs, from rendering Helm and Kustomize manifests to running tenant-boundary tests across Cognito pools.
3 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (8) - Evidence and Review
Why an EKS SaaS requirement is a criterion rather than proof, and how the plugin ties NetworkPolicy, IRSA, and tenant-context requirements to evidence-based status.
2 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (7) - Refresh and Lifecycle
Refreshing the EKS SaaS security contract as ingress, cluster topology, and IAM bindings change, without losing prior approvals, evidence, or requirement history.
3 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (6) - Authoring, Validation, and Publication
Writing atomic, verifiable EKS SaaS requirements for tenant identity, network isolation, IRSA, and the provisioning pipeline, validated by code before publication.
5 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (5) - Responsibility and Prioritization
Splitting EKS SaaS work across AWS, the platform team, product teams, and the SaaS operator, and why IRSA and shared controllers need more than one owner.
6 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (4) - Blast Radius
Calculating blast radius across the AWS EKS SaaS reference architecture, from a contained siloed order table to a provisioning pipeline that can reach the whole account.
5 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (3) - Threat Analysis
A ten-threat model across the AWS EKS SaaS reference architecture's shared control plane, tenant namespaces, ingress routing, and IAM Roles for Service Accounts.
8 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (2) - CIA Impact and Baseline
Calculating CIA impact for the AWS EKS SaaS reference architecture, where pooled and siloed DynamoDB models and a shared control plane both feed the result.
7 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (1) - Service Analysis
Building a confirmed service profile for AWS's EKS SaaS reference architecture, where namespace-per-tenant isolation and a shared control plane change what counts as a boundary.
6 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS ECS SaaS (10) - Regulatory Overlays
Applying PIPA/ISMS-P and customer contractual obligations on top of the ECS SaaS baseline, and why tenant deletion and cross-border data flow stay explicit review items.
5 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS ECS SaaS (9) - CI/CD Verification
Five deterministic gates that connect ECS SaaS requirements to CI/CD, from validating the requirement contract to tenant-boundary tests and image provenance.
6 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS ECS SaaS (8) - Evidence and Review
Why an ECS SaaS requirement is a criterion rather than proof, and how the plugin ties tenant-isolation, IAM, and audit requirements to evidence-based status.
5 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS ECS SaaS (7) - Refresh and Lifecycle
Refreshing the ECS SaaS security contract as isolation tiers, tenant data, and integrations change, without losing approvals, evidence, or requirement history.
5 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS ECS SaaS (6) - Authoring, Validation, and Publication
Turning the ECS SaaS work queue into atomic, verifiable requirements, validated by code and published as a versioned security contract.
6 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS ECS SaaS (5) - Responsibility and Prioritization
Turning the ECS SaaS baseline, threats, and blast-radius results into an owned, prioritized work queue, with the control plane and tenant isolation tier driving priority.
6 min read - #Security Design#Security Requirements#Plugin
Security Requirements Plugin - Kubernetes Analysis Added
Turning Kubernetes manifests into a security graph so RBAC, NetworkPolicy, service mesh, and cloud IAM relationships feed blast-radius and requirements analysis.
9 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS ECS SaaS (4) - Blast Radius
Calculating blast radius for the AWS ECS SaaS reference architecture, tracing which tenants, data, and control-plane components a threat path could reach.
5 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS ECS SaaS (3) - Threat Analysis
A STRIDE threat model across nine trust boundaries of the AWS ECS SaaS reference architecture, from tenant claim spoofing to a deployment role that can reach every tenant.
8 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS ECS SaaS (2) - CIA Impact and Baseline
Calculating confidentiality, integrity, and availability impact for the AWS ECS SaaS reference architecture, and why holding customer data pulls in a privacy baseline and a regulatory overlay.
7 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS ECS SaaS (1) - Service Analysis
Building a confirmed service profile for AWS's ECS SaaS reference architecture, before any control, threat, or blast-radius calculation.
9 min read - #Security Design#Security Requirements#Plugin
Security Requirements Plugin: New Feature - Blast Radius
How the security-requirements plugin's blast-radius stage scopes each threat across tenant, data, runtime, control, and recovery dimensions to prioritize requirements and review work.
3 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS Serverless Movie Voting App (9) - CI/CD Verification
Turning each requirement's verification metadata into a dispatchable CI/CD check, from IAM policy inspection to sentinel-based log scanning.
5 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS Serverless Movie Voting App (8) - Regulatory Overlays
Applying ISMS-P and GDPR overlays on top of the NIST baseline once the movie service adds accounts, an analytics provider, and Korean and EU users.
5 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS Serverless Movie Voting App (7) - Evidence and Review
Why a written security requirement is a criterion, not proof, and how the security-requirements plugin ties each requirement to evidence-based status.
5 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS Serverless Movie Voting App (6) - Refresh and Lifecycle
How the security-requirements plugin re-derives a security contract as a service changes, without losing prior approvals, exceptions, or audit history.
8 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS Serverless Movie Voting App (5) - Requirement Authoring and Validation
Turning a prioritized work list into stable, atomic, verifiable security requirements, then linting and merging them into a publishable contract.
8 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS Serverless Movie Voting App (4) - Responsibility and Prioritization
Assigning AWS/team/org responsibility for the selected controls and crossing them with the eight movie-service threats to produce a prioritized work list.
11 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS Serverless Movie Voting App (3) - Threat Analysis
Applying STRIDE at each trust boundary of the AWS serverless movie-rating sample, turning eight threats into eight testable security requirements.
8 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS Serverless Movie Voting App (2) - CIA Impact and Baseline
How the security-requirements plugin turns a confirmed service profile into a CIA impact rating, a NIST 800-53B baseline, and an ASVS level.
15 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS Serverless Movie Voting App (1) - Service Analysis
How the security-requirements plugin builds a confirmed service profile from an AWS serverless movie-rating sample, before any control or threat is derived.
13 min read - #AI#AI Supply Chain#Supply Chain Security
The AI Software Supply Chain Is Under Attack
A field guide to AI-era supply chain attacks - the objects at risk, how to screen them, and why AI coding raises the stakes.
11 min read - #Security Design#Security Requirements#Compliance
Security Requirements Plugin: First Security Activity
Claude plugin that derives security requirements from service descriptions and reviews security design.
10 min read - #NIST SP 800-204D#CI/CD#CI/CD Security
Securing Workflows in CD Pipelines
Supply chain security measures also apply to controls during the CD process.
4 min read - #NIST SP 800-204D#CI/CD#CI/CD Security
Securing Workflows in CI Pipelines - Secure Code Commits
Appropriate forms of testing should be performed before code commits
2 min read - #NIST SP 800-204D#CI/CD#CI/CD Security
Securing Workflows in CI Pipelines - Integrity of Evidence Generation During Software Updates
How to ensure the integrity of evidence generation during software updates
6 min read - #NIST SP 800-204D#CI/CD#CI/CD Security
Securing Workflows in CI Pipelines - Secure Pull-Push Operations on Repositories
Deep dive into secure Pull-Push Operations on Repositories referring to NIST SP 800-204D
6 min read - #NIST SP 800-204D#CI/CD#CI/CD Security
Securing Workflows in CI Pipelines - Secure Build
Introduce the requirements for secure build and associated tools to secure your build stage in CI/CD pipeline.
19 min read - #NIST#NIST SP 800-218#NIST SP 800-204D
Relationship Between NIST SP 800-218 and SP 800-204D
Review the relationship between NISTP SP 800-218 and SP 800-204D. Walk through how the SSDF specifically focuses on cloud-native application CI/CD pipelines
11 min read - #SSDF#NIST#NIST SP 800-218
NIST SP 800-218(SSDF)
Secure Software Development Framework enhanced by Software Supply Chain Attack.
22 min read - #Detection#SOC#Detection as Code
Palantir ADS
Palantir's methodology to enhance its detection engineering
4 min read - #CACAO Playbook#OASIS#SOC
CACAO Playbook
Standarize and represent incident response workflow as JSON
11 min read - #Incident Response#Vulnerability Response#Playbook
CISA Incident & Vulnerability Response Playbooks
Incident and Vulnerability Response Playbook Standard
15 min read - #Microservices#NIST#NIST SP 800-204
NIST SP 800-204 Series
The NIST Special Publication Series for Securing Microservices.
5 min read - #DevSecOps#DoD
DoD DevSecOps Strategy and Implementation Docs
DevSecOps documents structure of U.S Department of Defense.
5 min read - #NIST#OSCAL#CNCF
NIST OSCAL and associated projects
An introduction to NIST OSCAL and its associated CNCF projects for compliance as code.
5 min read - #AI#DoDD 3000.09#SOC
DoD Directive-3000.09
Why did I choose DoDD 3000.09 for UAV AI SCO.
4 min read - #F3EAD#Red Team#AI
The F3EAD Targeting Cycle Implementation to UAV AI Red Team
Why did I implemented F3EAD,U.S military target process,to UAV AI Red team for Hackathon
2 min read - #NIST SP 800-37(RMF)#NIST SP 800-39#NIST SP 800-30
How NIST's Risk Publications Connect
The connections and relationships between NIST Risk related publications
2 min read - #threat-modeling#STRIDE
Threat Modeling - STRIDE
Conducting STRIDE threat modeling in detail
4 min read - #meta
Hello, World
How this blog is built, and how posts are grouped with tags.
1 min read