Plerion

131 posts

Plerion banner
Plerion

Plerion

@PlerionHQ

Simplify cloud security

Australia Katılım Ekim 2021
17 Takip Edilen142 Takipçiler
Plerion
Plerion@PlerionHQ·
Managing network access in AWS used to mean babysitting endless lists of VPC IDs. Painful. Easy to screw up. Now AWS has 3 new condition keys that scale: 🔑 aws:VpceAccount → restrict to accounts 🔑 aws:VpceOrgPaths → restrict to OUs 🔑 aws:VpceOrgID → restrict to your org
English
1
1
2
95
Plerion
Plerion@PlerionHQ·
Diversity is the enemy of security! No, I’m not sledging DEI. I’m saying that doing things in a million different ways - in the name of speed, innovation, or employee satisfaction - has a hidden cost. A cost most people don’t notice, because they aren’t the ones who feel it.
English
1
0
0
61
Plerion retweetledi
AWS Startups
AWS Startups@AWSstartups·
Meet Pleri, the newest member of your security team. Created by @PlerionHQ & powered by #AWS services, the #AI teammate acts like a seasoned security engineer, proactively protecting systems at scale. Ready to build your own? Plerion explains how: go.aws/46zxkqu
English
2
4
8
2.4K
Plerion
Plerion@PlerionHQ·
If you're struggling with vulnerability management in the cloud, I'd recommend having a look at Plerion's cloud security platform. We find and prioritize vulnerabilities in cloud containers, images, and code. plerion.com/use-cases/find…
English
0
0
0
39
Plerion
Plerion@PlerionHQ·
So if you've already got a vulnerability SLA in place, or are thinking of implementing one, build systems to do these 4 things: 1. Attribution 2. Notification 3. Escalation 4. Accountability It's still going to be hard, but at least you'll have a chance.
English
1
0
0
35
Plerion
Plerion@PlerionHQ·
Vulnerability fix SLAs are common but having systems to support them is not. That's why they fail! A vulnerability fix SLA is great because it sets the standard and expectations for everyone on how quickly each type of security issues needs to be fix.
English
1
0
0
56
Plerion
Plerion@PlerionHQ·
Every security capability needs a coverage metric. If you don't pair security goals with coverage goals, you're just pretending to do security.
English
0
0
1
69
Plerion
Plerion@PlerionHQ·
Just dropped a 🔥 conversation with a non-technical CISO. I learned so much from this guy! You don't have to be technical to be a CISO but if you make silly metrics your goal, you'll get silly results. Tag your favourite CISO.
English
1
1
4
259
Plerion retweetledi
Daniel Grzelak
Daniel Grzelak@dagrz·
My favourite part about hacking AWS and blogging about it is the good folks at AWS valiantly trying to change my clickbait titles. I just think "How to get rekt using AWS Neptune" is way more interesting than "Best practices for using AWS Neptune". plerion.com/blog/how-to-ge…
English
2
5
34
3.6K
Plerion retweetledi
Daniel Grzelak
Daniel Grzelak@dagrz·
Bad prioritization kills security teams. So I did some experiments to see if AI could help. If you think about it, prioritization is just sorting. So why not use sorting algorithms to prioritize? The LLM can be the comparison function. plerion.com/blog/automatic…
English
1
2
14
665
Plerion retweetledi
Daniel Grzelak
Daniel Grzelak@dagrz·
I wrote some code and a guide to figure out who has access to your AWS production, through transitive trusts. It's always scary to figure this out but well worth it. plerion.com/blog/root-in-p…
English
0
5
14
1.1K
Plerion
Plerion@PlerionHQ·
So, when you finally realize it’s your job to ask “Do you own that?” — don’t be sad. Instead, find ways to systematically identify these assets and keep their metadata up to date, so you can automate this in the future.
English
0
0
0
18
Plerion
Plerion@PlerionHQ·
And you won’t be able to fix it — whether it’s an S3 bucket or an RDS database — unless you know who owns it. Typically, only they understand how to solve the problem without breaking the business.
English
1
0
0
19
Plerion
Plerion@PlerionHQ·
No one will tell you this, but one of the dumbest — and most valuable — things you’ll do as a cloud security engineer is ask people, “Do you own this?”
English
1
0
0
35