Welcome. This site is a working notebook for cloud security engineering: the patterns, tradeoffs, detections, and operational lessons that are useful when securing real cloud environments.
Start Here
- Domain 1: Detection
- Domain 2: Incident Response
- Domain 3: Infrastructure Security
- Domain 4: Identity and Access Management
- Domain 5: Data Protection
- Domain 6: Security Foundations and Governance
- AWS Core Services
- AWS Networking
- Network Concepts
- Microservices Security
Writing Queue
- AWS IAM policy review checklist
- Azure Entra ID conditional access patterns
- CloudTrail detection ideas that are actually worth alerting on
- Terraform module security review notes
- Incident response notes for exposed cloud credentials