Cloud security,
explained plainly.
The concepts the platform is built on, posture, reachability, blast radius, identity risk and vulnerability prioritisation , written out properly, without the acronym soup.
Who can walk into your AWS account from outside?
OIDC, SAML and cross-account trust let outsiders assume roles in your AWS account. How to find each one, plus a free open source CLI that audits them.
What is an attack path in cloud security?
An attack path is the chain of real hops from an exposed entry point to a sensitive target in your cloud. What the hops are and how tools detect them.
CVSS, EPSS and KEV: three scores, three different questions
CVSS measures how bad a flaw is, EPSS how likely it is to be exploited, and KEV whether it already has been. How to combine all three in one patch queue.
CIEM: the over-permissioned identity problem
CIEM finds cloud identities holding more access than they use, and the permission chains that lead to admin. How it works, and how it differs from IAM.
Blast radius: measuring what falls with a single asset
Blast radius is what an attacker can reach after taking one cloud resource. How it is computed, how it differs from attack paths, and where it misleads.
Why a CVSS score cannot prioritise your cloud risk
CVSS rates a flaw before anyone has seen your account. Attack paths rank risk by what an attacker can reach. Where each fits, with a side-by-side table.
What is Cloud Security Posture Management?
CSPM checks cloud configuration against a secure baseline using read-only APIs. What it covers, what it misses, and how it differs from CWPP and CNAPP.