Defend the cloud
The platform decides how bad any bug can get. I keep AWS small, private and watched.
- Cloud postureMulti-account AWS audits with Prowler and Wiz, ranked by real risk.
- Private networkingVPC and Transit Gateway designs with nothing public by accident.
- Identity and accessIAM and SSO reviews that remove standing admin access.
- Containers and EKSTrivy image scans and kube-bench CIS checks before release.
- Detection engineeringWazuh SIEM, file integrity monitoring and Tines automation.
- Policy as codeCloud and host compliance rules in Rego and OVAL.
