AWS EC2 Forensic Investigation: Analyzing a RegreSSHion Compromise

When an AWS abuse report lands in your inbox about an EC2 instance running cryptocurrency mining malware, you know you’re in for an interesting investigation. This week, I conducted a complete forensic analysis of a compromised production server, and the findings highlight critical lessons about patch management, monitoring, and security hygiene. Initial Discovery The timeline started simple: AWS abuse report in December, 2025, about suspicious network activity. The client had already rebuilt a clean instance, but the compromised server remained running for forensic analysis. My task was to determine what happened, how it happened, and ensure the replacement was truly clean. ...

January 3, 2026 · 5 min · Me

Implementing Azure AD Privileged Identity Management (PIM)

Why Implement PIM? Privileged Identity Management (PIM) is one of the most effective security controls available in Azure AD. Traditional role assignments grant permanent, standing privileges that create significant security risks: Expanded Attack Surface: Compromised accounts with permanent privileges give attackers immediate access Compliance Gaps: Audit requirements often mandate Just-In-Time (JIT) access for privileged operations Privilege Creep: Over time, users accumulate unnecessary permanent role assignments PIM transforms these permanent assignments into time-bound, audited, and justified access - dramatically reducing your organization’s risk profile. ...

September 26, 2025 · 11 min · Me

Debugging SSL Certificate Automation with OpenSSL

Understanding SSL Certificate Renewal Verification When managing automated SSL certificate renewals, it’s crucial to verify that the automation is working correctly. This post walks through the process of checking certificate renewal status using OpenSSL. Checking Certificate Dates One of the most important aspects of SSL certificate management is ensuring timely renewals. Here’s how to check certificate expiration dates: openssl s_client -connect your-domain:443 -servername your-domain.com < /dev/null 2>/dev/null | openssl x509 -noout -dates ...

September 19, 2025 · 2 min · Me

Breaking the Docker Security Myth: CVE-2025-9074 and the Illusion of Container Isolation

The Wake-Up Call: CVE-2025-9074 A critical vulnerability recently discovered in Docker Desktop (CVE-2025-9074) serves as a sobering reminder that containers are not the security boundary many developers believe them to be. With a CVSS score of 9.3, this vulnerability allowed malicious containers to escape their supposed isolation and compromise the host system through a surprisingly simple attack vector. The Bottom Line Up Front: CVE-2025-9074 demonstrates that the widespread belief “Docker = isolated = secure” is not just wrong—it’s dangerously wrong. This misconception puts production Kubernetes environments at risk when teams fail to consider the underlying Linux kernel and operating system security implications. ...

September 13, 2025 · 8 min · Me

Implementing Azure Conditional Access Policies for Geographic Security

Understanding Geographic-Based Access Controls Geographic-based access controls are crucial for organizations looking to maintain compliance with international regulations or enhance security by removing some low hanging fruit. One specific use case is blocking access from OFAC sanctioned countries while allowing access from trusted locations. Implementation Steps 1. Create a Report-Only Policy First, create a policy in report-only mode to assess impact: Navigate to Azure Portal > Azure AD > Security > Conditional Access Create a new policy Configure the following settings: Users and groups: All users Cloud apps or actions: All cloud apps Conditions: Locations > Configure > Selected locations Access controls: Block access Enable policy: Report-only 2. Configure Location Conditions Create a list of blocked locations: ...

August 15, 2025 · 2 min · Me