The AWS evidence requests that show up in real ISO 27001 audits — log retention proofs, access control evidence, past investigation examples, and DR tests. Written from actual audit prep, not a vendor checklist.
Permission boundaries let you scope individual IAM identities in ways SCPs can't. Here's the developer sandbox pattern I deploy — with real policy code, the ceiling-vs-grant mental model, and the traps most teams fall into.
Security Hub now has an MCP server for Claude Desktop. Query your exposure findings in natural language, visualize attack paths, and prioritize fixes — here's how to set it up and what it's actually useful for.
Standard GuardDuty watches network traffic. Runtime Monitoring deploys an agent that sees process execution, file access, and privilege escalation inside EC2, EKS, and ECS — here's how to enable it without blowing up your bill.
Secrets Manager now publishes secret change events to EventBridge automatically — no CloudTrail workarounds needed. Here's how to set up alerts for rotation failures, stale secrets, and unexpected changes.
GuardDuty detects threats. Security Hub aggregates findings and checks compliance. Here's how they differ, where they overlap, and how to run them together without paying twice for the same data.
A real spearphishing incident I handled from ticket to remediation. Full attack chain reconstruction, forensic analysis, IOC extraction, and the mistakes that cost us days.
Practical guide to analyzing AWS CloudTrail logs — Athena queries for tracing non-compliant resources, finding who opened SSH to the world, and building your investigation workflow.
Practical AWS Service Control Policies for real organizations. Includes must-have SCPs, break-glass patterns, and lessons from managing 25 accounts across 6 OUs.
Handle real AWS security incidents step by step. Covers compromised keys, public S3 buckets, cryptomining, privilege escalation, and automated containment.
The same 5 AWS misconfigurations show up in every audit I run. Here's what they are, why teams keep making them, and how to fix each one with Console and Terraform.
The baseline I verify on every AWS security engagement — 10 checks with CLI commands covering IAM, S3, logging, and network hardening. Takes 30 minutes, catches 80% of what goes wrong.
Most EKS clusters run with default RBAC, no network policies, and pods with root. Here's the 10-item hardening checklist — IRSA, pod security standards, network policies, secrets encryption, and node lockdown with YAML you can apply today.
Step-by-step guidance on meeting CIS Benchmarks for EC2 in AWS. Learn how to map controls, audit compliance, and automate remediation using AWS services and open-source tools.
Most EKS clusters ship with control plane logging off and no runtime detection. Here's the step-by-step: audit logs, Falco, GuardDuty for containers, and the gaps teams miss.
How to prepare for eJPTv2 when your background is cloud security, not pentesting. Study plan, resource ranking, lab strategy, and what to focus on from a defender's perspective.
One hunter reported 220 IDOR finds in a single year. Here's how insecure direct object references show up in Lambda, API Gateway, and DynamoDB — with prevention code.
Enable GuardDuty, filter noisy findings by severity, and wire EventBridge alerts to Slack or your SIEM — with Terraform and Console steps. Includes which finding types actually need your attention.
How to detect IAM privilege escalation in AWS using CloudTrail events, EventBridge rules, and real-world API patterns. Includes alerting setup and Terraform.
Build a CIS-compliant Amazon Linux 2 AMI using EC2 Image Builder. Covers IMDSv2 enforcement, auditd, CloudWatch logging, and automated security hardening.
Audit and tighten IAM permissions using Access Analyzer, CloudTrail, and service last-accessed data. Step-by-step workflows for enforcing least privilege.
Step-by-step SSM Session Manager setup — IAM role, AmazonSSMManagedInstanceCore policy, instance profile, and session logging. No SSH keys, no bastion hosts, no port 22.
Harden EC2 instances with IAM least privilege, OS lockdown, encryption, logging, and CIS benchmark checks. Practical guide with console and Terraform examples.
Free toolkit with an IR playbook template, Terraform-deployed notification pipeline, Lambda functions for SES and Slack alerts, and a forensic tool matrix — everything you need to respond to AWS security incidents.
Build real AWS threat detection with GuardDuty, CloudTrail, EventBridge, and Wazuh — without Splunk or Datadog. Practical architectures that cost under $50/month.
Kill long-term AWS access keys for good. A step-by-step playbook using IAM roles and STS to lock down access in under a day — with the mistakes to skip.
Most small teams write an IR plan and never test it. Here's the framework for cloud-native AWS incident response — from preparation and forensics to tabletop exercises that expose the gaps.
Generate least-privilege IAM policies automatically from CloudTrail activity using Access Analyzer, then deploy them with Terraform. Step-by-step with code examples.
Step-by-step root account detection with EventBridge, SNS, and Slack alerts — CLI commands and Terraform included. Plus what to do when the alert fires.
I’m Javier Pulido , a Cloud Security Engineer specialized in AWS. Over the past several years I’ve built and secured multi-account AWS environments with infrastructure-as-code, identity federation, and continuous monitoring — the same patterns I write about here. What I Help Teams With Beyond writing, I take on selected consulting engagements. If your team is dealing with any of these,…
AWS security consultant based in Sevilla, Spain. Cloud security audits, GuardDuty and Security Hub deployment, IAM hardening, incident response, and ISO 27001 preparation. Remote engagements across Europe.