Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Logs Don't Mean a Thing - Unraveling IaC-Managed Identity Ownership

fwd:cloudsec via YouTube

Overview

Coursera Spring Sale
40% Off Coursera Plus Annual!
Grab it
Explore the critical challenge of identifying identity ownership in modern Infrastructure-as-Code (IaC) environments through this 23-minute conference talk from fwd:cloudsec. Learn why traditional platform audit logs like CloudTrail and Entra ID audit logs are insufficient for determining who created or manages specific identities when IAM is managed through IaC frameworks. Discover innovative approaches to solving IaC-based ownership challenges by leveraging alternative data sources including IaC codebases and CI/CD logs. Understand how to implement static code analysis, heuristics, and large language models (LLMs) to unravel complex identity ownership patterns. Gain insights from security researchers Dan Abramov and Eliav Livneh, who share their practical experience in tackling Non-Human Identity (NHI) security challenges and developing solutions for proper identity management and incident response in cloud-native environments.

Syllabus

Logs don't mean a thing: Unraveling IaC-Managed Identity Ownership

Taught by

fwd:cloudsec

Reviews

Start your review of Logs Don't Mean a Thing - Unraveling IaC-Managed Identity Ownership

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.