Blog

    AWS Security & Cloud Insights

    Practical guides, best practices, and expert insights on AWS security, cloud architecture, and compliance from our team of experienced consultants.

    90 articles published

    AWS Security14 min read

    The Agent's AWS Footprint

    Part 15 of 16 in the AWS Security Agent: From Zero to Hero series. What AWS Security Agent leaves behind in your own account. CloudTrail events, Secrets Manager entries, and VPC Flow Logs, with the commands to audit and observe every run yourself.

    AWS Security AgentCloudTrailSecrets Manager
    Read
    AWS Security7 min read

    Attacking the Agent Itself

    Part 14 of 16 in the AWS Security Agent: From Zero to Hero series. What AWS itself documents about AWS Security Agent as its own attack surface: the guardrails it publishes, how it limits its own blast radius, and how domain ownership and data handling are enforced. Sourced entirely from AWS's public documentation, not hands-on testing.

    AWS Security AgentPenetration TestingAI Agents
    Read
    AWS Security13 min read

    We Tried to Trick the Agent

    Part 13 of 16 in the AWS Security Agent: From Zero to Hero series. Adversarial evasion experiments against AWS Security Agent: code obfuscation, prompt injection in design documents and pull requests, fake sanitizers, and misleading comments. Almost every obfuscated vulnerability was still detected (18 of 19), and every injection attempt in these runs was ignored.

    AWS Security AgentPrompt InjectionCode Review
    Read
    AWS Security12 min read

    What It Catches and What It Misses

    Part 12 of 16 in the AWS Security Agent: From Zero to Hero series. An honest, data-driven account of where AWS Security Agent falls short, with a practical fix for each weakness, plus why results vary from run to run and why a single run undercounts.

    AWS Security AgentPenetration TestingAI Agents
    Read
    AWS Security10 min read

    How We Measured Detection Rate

    Part 11 of 16 in the AWS Security Agent: From Zero to Hero series. The full measurement methodology behind this series. A purpose-built application with 39 intentional vulnerabilities, a JSON answer key, false-positive controls, and a scoring scheme you can reproduce.

    AWS Security AgentPenetration TestingMethodology
    Read
    AWS Security12 min read

    Inside the Engine: What the Logs Reveal

    Part 10 of 16 in the AWS Security Agent: From Zero to Hero series. A data-driven walk through the CloudWatch logs of two real penetration tests: the 14 tools the agent uses, the thousands of reasoning blocks and tool calls, and how the observed behavior maps onto AWS's published multi-agent stages.

    AWS Security AgentPenetration TestingAI Agents
    Read
    AWS Security8 min read

    Advanced Pentesting: VPC and Cross-Account

    Part 9 of 16 in the AWS Security Agent: From Zero to Hero series. Testing private applications inside a VPC with the agent's ENI model, the network constraints that actually matter, and cross-account shared VPC pentesting via AWS Resource Access Manager added in February 2026.

    AWS Security AgentPenetration TestingVPC
    Read
    AWS Security13 min read

    Pentesting With Credentials

    Part 8 of 16 in the AWS Security Agent: From Zero to Hero series. I ran the same pentest twice against the same application. The only change was providing a username and password. Findings went from 5 to 13, a 160 percent increase, including two critical JWT bypasses and a privilege escalation.

    AWS Security AgentPenetration TestingJWT
    Read

    Page 1 of 10

    All Articles

    Need Expert AWS Security Help?

    Our team of AWS-certified consultants can help you implement the security best practices discussed in our articles.