Zero Trust Microservices: East-West Detection
Zero trust microservices detection. Find east-west movement via new service-pair edges, workload identity drift, and Kafka abuse, with SPL and KQL analytics.
Topic hub
Adversary techniques broken down for the defender: how an attack actually works, what it leaves behind, and the detections and hardening that neutralize it. Lab-only, authorization-only, mapped to MITRE ATT&CK.
5 articles
Zero trust microservices detection. Find east-west movement via new service-pair edges, workload identity drift, and Kafka abuse, with SPL and KQL analytics.
Supply chain attack detection in CI/CD. Build-time egress, dependency drift, and artifact provenance, with Sigma and SPL analytics plus hermetic-build hardening.
Linux privilege escalation detection for defenders — auditd rules for sudo, SUID and GTFOBins abuse, a CVE-2025-32463 sudo chroot case study, and hardening.
Broken access control testing for defenders — detect IDOR and BOLA from authorization-failure telemetry with Sigma and SPL rules, plus deny-by-default hardening.
How Kerberoasting abuses service tickets to crack service-account passwords offline — and the Sigma detection and hardening that shut it down. Lab-only.