Credential isolation and least privilege for AWS agents
Two problems come up every time you give an AI agent AWS access: the agent has exfiltratable credentials, and you have to guess what permissions it needs in the form...
Read →Notes on building security teams, automating compliance, and the architecture and organizational calls that decide whether a security program works.
After a round of improvements, I’ve tagged TrailTool 1.0. It’s backwards incompatible, but hopefully more stable.
Read more →Two problems come up every time you give an AI agent AWS access: the agent has exfiltratable credentials, and you have to guess what permissions it needs in the form...
Read →If you run local agents, you need to make tough choices between autonomy and safety. Setting dangerously-skip-permissions while sword fighting on desk chairs and letting the tokens burn bright is...
Read →Update: TrailTool 1.0 is out, with an identity-first session model and a lot more. See TrailTool 1.0: Identity-First Sessions for CloudTrail for what changed.
Read →Commercial GRC tools can cost $12K+/year and lock your compliance docs in proprietary systems. GraphGRC v2 gives you SOC 2 documentation in GitHub - pre-written controls, policies, and processes in...
Read →Dependabot throws security alerts but sometimes can't create pull requests. Here's a GitHub Action that automatically sends failed alerts to Copilot for resolution.
Read →Raccoons are both advanced and persistent threats. After one attacked my chihuahua Jolene, I declared war on my backyard invaders. Through ultrasonic deterrents, motion-activated sprinklers, and wacky inflatable air dancers,...
Read →Data retention covers two different problems - preservation (minimum time you must keep archival data) and deletion (maximum time you can keep personal data). They require opposite technical approaches -...
Read →Your new hire sits through generic security training, clicks through a 47-page policy, and gets random access over time. Three months later they ping for production access. The policies? Nobody's...
Read →Modern software companies use a lot of software services. Traditional security teams address third-party risk through certifications and questionnaires, but there's an opportunity to actually reduce risk by collaborating with...
Read →A framework for helping security engineers choose high-impact work using three criteria - business goals, implicit interest, and personal growth.
Read →Running EKS in FedRAMP environments requires careful implementation across multiple security domains
Read →Learn how software vendors can serve FedRAMP-authorized cloud service providers without going through the full authorization process.
Read →Learn how to leverage AWS Bedrock to create a FedRAMP-compliant AI assistant for your System Security Plan without exposing sensitive information.
Read →