How to Migrate an EC2 Fleet to IMDSv2 Without Breaking Applications
IMDSv2 protects instance credentials from SSRF attacks, but enforcing it across a large EC2 fleet can break older applications if done carelessly. Here is a...
Insights
Articles in How-To & Hardening.
IMDSv2 protects instance credentials from SSRF attacks, but enforcing it across a large EC2 fleet can break older applications if done carelessly. Here is a...
Use this checklist to make IMDSv2 mandatory across your AWS organization and keep it that way.
Entra ID offers two ways to enforce baseline identity security: Security Defaults (free, simple) and Conditional Access (requires Entra ID P1, flexible)....
Use this checklist to enable Security Defaults with minimal disruption, especially for smaller organizations.
Legacy (basic) authentication bypasses MFA. Even after Microsoft's retirement of basic authentication in Exchange Online, many organizations still find...
Use this checklist to find every remaining dependency on legacy authentication in Exchange Online and Microsoft 365.
Long-lived IAM user access keys are one of the most common causes of AWS breaches. IAM roles and IAM Identity Center provide short-lived credentials...
IMDSv2 protects EC2 instance credentials from server-side request forgery, the technique used in the Capital One breach. Combined with least-privilege...
AWS Control Tower sets up a governed multi-account environment with guard rails. Here is how to set it up and choose the right controls.
Control Tower offers hundreds of controls. Use this checklist to choose a practical starting set.
Exposed RDP and SSH ports are among the most attacked entry points in the cloud. Azure Bastion and just-in-time (JIT) VM access let administrators reach...
Help desk and support staff can reset passwords, change MFA methods and see user data. Here is how to scope those roles tightly in Microsoft 365 and Entra ID.
Entra ID includes two built-in defenses against password spraying: smart lockout and Identity Protection. Here is how to configure both.
A good Microsoft Sentinel deployment starts with planning workspaces, data sources and costs before turning anything on. Here is the sequence Microsoft's...
Data connectors determine both what Microsoft Sentinel can detect and what it costs. Use this checklist to prioritize them.
Account-level S3 Block Public Access protects every bucket in an account. With AWS Organizations, you can apply it everywhere and prevent anyone from...
Use this checklist to audit S3 public access across your AWS organization.
A multi-account AWS landing zone separates workloads, centralizes security tools and protects logs. Here is how to design one using AWS's own reference...
AWS Security Hub can produce hundreds of failed controls on day one. This checklist helps you triage them without drowning.
Emergency access accounts — often called break-glass accounts — let you regain administrative access to Entra ID and Microsoft 365 when normal sign-in...
When your identity provider or MFA service fails, every minute of confusion costs productivity. This runbook outlines what to do.
When you acquire a company, you acquire its cloud environments, identities and possibly its attackers. Here is how to run a cloud security due diligence...
Stolen tokens let attackers bypass passwords and MFA. Conditional Access session controls limit how long tokens stay useful and when users must...
Passwordless sign-in removes the most attacked credential and improves user experience. Here is a practical rollout plan using Windows Hello for Business,...