<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Ofir</title>
    <description>The latest articles on DEV Community by Ofir (@ofirbe).</description>
    <link>https://dev.to/ofirbe</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4132169%2F1ee721c2-0da7-4b58-a35c-d2805aec2343.png</url>
      <title>DEV Community: Ofir</title>
      <link>https://dev.to/ofirbe</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/ofirbe"/>
    <language>en</language>
    <item>
      <title>Building Kultarr: Making AWS Security Investigations Less Painful</title>
      <dc:creator>Ofir</dc:creator>
      <pubDate>Thu, 08 Oct 2026 05:23:23 +0000</pubDate>
      <link>https://dev.to/ofirbe/building-kultarr-making-aws-security-investigations-less-painful-4b3b</link>
      <guid>https://dev.to/ofirbe/building-kultarr-making-aws-security-investigations-less-painful-4b3b</guid>
      <description>&lt;p&gt;I've been building Kultarr. Here's where it's at.&lt;/p&gt;

&lt;p&gt;I've spent a lot of time working with AWS, and one thing that always frustrated me was how much digging it takes to understand a security change.&lt;/p&gt;

&lt;p&gt;You see something unusual, open CloudTrail, check IAM permissions, jump between services, and try to piece everything together.&lt;/p&gt;

&lt;p&gt;That's one of the reasons I started building Kultarr.&lt;/p&gt;

&lt;p&gt;The goal is to make AWS security investigations easier. Not just show another alert, but help explain who changed something, what happened, what it affected, and what can be done about it.&lt;/p&gt;

&lt;p&gt;It's still in development, and there's a lot left to build and improve.&lt;/p&gt;

&lt;p&gt;But I finally got the website to a point where I'm happy to share it.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://kultarr.io" rel="noopener noreferrer"&gt;https://kultarr.io&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I'm curious to hear what you think, especially if you work with AWS.&lt;/p&gt;

&lt;p&gt;What's something you wish AWS &lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ffbwsxbelznydurcr3zc7.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ffbwsxbelznydurcr3zc7.png" alt=" " width="800" height="415"&gt;&lt;/a&gt;made easier to investigate?&lt;/p&gt;

</description>
      <category>aws</category>
      <category>buildinpublic</category>
      <category>security</category>
      <category>showdev</category>
    </item>
    <item>
      <title>I’m building Kultarr to make AWS investigations less painful</title>
      <dc:creator>Ofir</dc:creator>
      <pubDate>Sun, 27 Sep 2026 15:15:46 +0000</pubDate>
      <link>https://dev.to/ofirbe/im-building-kultarr-to-make-aws-investigations-less-painful-4lb9</link>
      <guid>https://dev.to/ofirbe/im-building-kultarr-to-make-aws-investigations-less-painful-4lb9</guid>
      <description>&lt;p&gt;I’ve spent a lot of time working with AWS environments, and one thing that keeps coming up is how annoying it can be to understand what actually happened after something changes.&lt;/p&gt;

&lt;p&gt;You notice a security group is suddenly open, an IAM policy was changed, a new access key appeared, or something in the environment just doesn’t look right. AWS has the information, but finding the answer usually means opening CloudTrail, checking IAM, jumping back to the resource, looking at permissions, timestamps, and trying to connect everything yourself.&lt;/p&gt;

&lt;p&gt;That’s why I started building Kultarr.&lt;/p&gt;

&lt;p&gt;The idea is pretty simple: when something changes in AWS, I want to make it easier to understand the full story behind it. What changed, who made the change, what permissions were used, which resource was affected, and what it looked like before.&lt;/p&gt;

&lt;p&gt;I’m not trying to replace AWS tools. I actually want to use the data AWS already gives us and make the investigation around it much easier to follow.&lt;/p&gt;

&lt;p&gt;Kultarr is still being built and there’s a lot I want to improve, but the direction is becoming much clearer.&lt;/p&gt;

&lt;p&gt;I’d really like to hear from people who work with AWS regularly: when something unexpected happens in an account, what usually wastes the most time during the investigation?&lt;/p&gt;

&lt;p&gt;&lt;a href="https://kultarr.io" rel="noopener noreferrer"&gt;https://kultarr.io&lt;/a&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>aws</category>
    </item>
    <item>
      <title>AWS access keys are easy to forget. I built a view to make them obvious.</title>
      <dc:creator>Ofir</dc:creator>
      <pubDate>Thu, 24 Sep 2026 13:31:03 +0000</pubDate>
      <link>https://dev.to/ofirbe/aws-access-keys-are-easy-to-forget-i-built-a-view-to-make-them-obvious-3o49</link>
      <guid>https://dev.to/ofirbe/aws-access-keys-are-easy-to-forget-i-built-a-view-to-make-them-obvious-3o49</guid>
      <description>&lt;p&gt;AWS access keys are really easy to create and really easy to forget about. A developer creates one for a script, a CI job uses another, someone leaves the company, a workload changes, and six months later the key is still active.&lt;/p&gt;

&lt;p&gt;While building Kultarr, I wanted one place where I could quickly see which keys are active, which ones are older than 90 days, which have never been used, which belong to privileged identities, and whether a root account still has an access key.&lt;/p&gt;

&lt;p&gt;So I built this view.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fd18vsyc1n1ix3q5rt1hd.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fd18vsyc1n1ix3q5rt1hd.png" alt=" " width="800" height="488"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The main thing I wanted to avoid was another security dashboard that just throws numbers at you. A 300 day old read only key and a 300 day old administrator key are not the same problem, so the view also adds context around privilege, usage, age and status.&lt;/p&gt;

&lt;p&gt;The idea is pretty simple: open one page and immediately understand what actually deserves attention.&lt;/p&gt;

&lt;p&gt;Kultarr is still early and I’m building it around real AWS problems I’ve run into rather than trying to pack it with random features.&lt;/p&gt;

&lt;p&gt;Curious how other teams handle this today. Do you rotate access keys automatically, use AWS Config/Security Hub, internal scripts, or still review them manually?&lt;/p&gt;

&lt;p&gt;&lt;a href="https://kultarr.io" rel="noopener noreferrer"&gt;https://kultarr.io&lt;/a&gt;&lt;/p&gt;

</description>
      <category>aws</category>
      <category>cloud</category>
      <category>devops</category>
      <category>security</category>
    </item>
    <item>
      <title>Terraform drift is easy to detect. Understanding it is the hard part.</title>
      <dc:creator>Ofir</dc:creator>
      <pubDate>Mon, 21 Sep 2026 17:04:38 +0000</pubDate>
      <link>https://dev.to/ofirbe/terraform-drift-is-easy-to-detect-understanding-it-is-the-hard-part-2f3g</link>
      <guid>https://dev.to/ofirbe/terraform-drift-is-easy-to-detect-understanding-it-is-the-hard-part-2f3g</guid>
      <description>&lt;p&gt;Terraform can tell you that something changed, but that usually isn’t the full story. What I actually want to know is who changed it, whether it was changed manually in AWS, when it happened, which .tf file owns that resource, and whether there was a commit or pull request connected to it. That’s one of the things we’re working on in Kultarr: connecting the live AWS resource back to Terraform and GitHub, so you can see the AWS resource, the Terraform resource, the file, the repo, the commit, the pull request and the CloudTrail activity around the change. If AWS and Terraform no longer match, the useful part isn’t only knowing that drift exists, it’s understanding how it happened.&lt;/p&gt;

&lt;p&gt;kultarr.io&lt;/p&gt;

</description>
      <category>aws</category>
      <category>devops</category>
      <category>infrastructure</category>
      <category>terraform</category>
    </item>
    <item>
      <title>AWS tells you something changed. Figuring out what actually happened is another story.</title>
      <dc:creator>Ofir</dc:creator>
      <pubDate>Fri, 18 Sep 2026 23:08:30 +0000</pubDate>
      <link>https://dev.to/ofirbe/aws-tells-you-something-changed-figuring-out-what-actually-happened-is-another-story-2hd7</link>
      <guid>https://dev.to/ofirbe/aws-tells-you-something-changed-figuring-out-what-actually-happened-is-another-story-2hd7</guid>
      <description>&lt;p&gt;I kept running into the same problem with AWS. The alert usually isn’t the hard part. The investigation is.&lt;/p&gt;

&lt;p&gt;An IAM policy changes, a security group gets opened, or a role suddenly has permissions it didn’t have before. AWS gives you the event, but then you still need to figure out the story behind it. You check CloudTrail to see who made the change, IAM to understand the permissions, Terraform to see what should have been there, and GitHub to check whether it came from a normal deployment.&lt;/p&gt;

&lt;p&gt;That context switching is what started bothering me. One change can be simple, but understanding whether it was expected, risky, or just part of a deployment can take much longer than the alert itself.&lt;/p&gt;

&lt;p&gt;That’s one of the problems I started working on with Kultarr. The idea is to bring that context together: who made the change, what changed, what existed before, what was affected, and whether there’s related Terraform or GitHub activity.&lt;/p&gt;

&lt;p&gt;I’m still working through a lot of the IAM edge cases, especially around understanding effective access without making assumptions.&lt;/p&gt;

&lt;p&gt;For people working with AWS: when you investigate an unexpected change, which part usually takes you the most time?&lt;/p&gt;


&lt;div class="crayons-card c-embed text-styles text-styles--secondary"&gt;
    &lt;div class="c-embed__content"&gt;
      &lt;div class="c-embed__body flex items-center justify-between"&gt;
        &lt;a href="https://kultarr.io/" rel="noopener noreferrer" class="c-link fw-bold flex items-center"&gt;
          &lt;span class="mr-2"&gt;kultarr.io&lt;/span&gt;
          

        &lt;/a&gt;
      &lt;/div&gt;
    &lt;/div&gt;
&lt;/div&gt;


</description>
      <category>aws</category>
      <category>devops</category>
      <category>terraform</category>
      <category>security</category>
    </item>
  </channel>
</rss>
