AWS CloudTrail Log Analysis: How to Find Who Did What (And When)

How to actually use CloudTrail logs day-to-day — tracing non-compliant resources to their source, querying with Athena, and setting up alerts before things go wrong.

July 13, 2026 · 9 min · 1767 words · Javier Pulido

AWS SCPs That Actually Work: Practical Guide for Real Teams

SCPs every AWS org should deploy on day one — plus the break-glass pattern, limit gotchas, and why you shouldn’t use SCPs to fix human behavior.

July 8, 2026 · 9 min · 1711 words · Javier Pulido

AmazonSSMManagedInstanceCore: Full Policy Breakdown

Full breakdown of every permission in the AmazonSSMManagedInstanceCore IAM policy, plus a least-privilege custom alternative for production EC2 instances.

July 7, 2026 · 8 min · 1496 words · Javier Pulido

AWS Incident Response: 5 Scenarios & How to Contain Them

Five real-world AWS incident response scenarios with detection signals, containment steps, CLI commands, and automation examples. Practical guide for security teams.

July 7, 2026 · 7 min · 1475 words · Javier Pulido

EKS Security Best Practices: RBAC, Pod Security & IRSA Hardening (2026)

10 actionable EKS security best practices covering IRSA, RBAC, network policies, pod security standards, image scanning, secrets encryption, and node hardening.

July 7, 2026 · 7 min · 1438 words · Javier Pulido

Meeting CIS Benchmarks for EC2: A Practical Guide

How to map, audit, and automate CIS Benchmark compliance for EC2 instances using AWS Config, Security Hub, SSM, and open-source scanners.

September 25, 2025 · 3 min · 506 words · Javier Pulido

EKS Security Monitoring: Audit Logs, Falco Runtime Detection & GuardDuty

Practical EKS security checklist — control plane audit logs, Falco runtime detection, GuardDuty for containers, and the monitoring gaps most teams miss.

September 17, 2025 · 6 min · 1150 words · Javier Pulido

EC2 Hardening Guide: Secure AWS Instances Step by Step

This guide delves into the technical aspects of hardening EC2 instances, covering topics from instance selection to monitoring and automation, aligning with AWS’s security recommendations.

May 29, 2025 · 2 min · 391 words · Javier Pulido

AWS Incident Response Guide: The Framework for Cloud-Native IR (2026)

The full framework for AWS incident response — why cloud IR is fundamentally different, how to build maturity progressively, and how to actually test your plan with tabletop exercises.

May 4, 2025 · 17 min · 3477 words · Javier Pulido

How I Passed the AWS Certified Security – Specialty (SCS-C02) Exam in 2025

My real-world journey passing the AWS Certified Security – Specialty (SCS-C02) exam. Study strategies, mistakes, resources, and tips for future candidates.

April 28, 2025 · 3 min · 622 words · Javier Pulido

Automate IAM Least Privilege with Access Analyzer & Terraform

Automate least-privilege IAM roles using Access Analyzer policy generation, CloudTrail-based scoping, and Terraform integration.

April 21, 2025 · 4 min · 799 words · Javier Pulido