Skip to content
Navigation menu
Search
Powered by Algolia
Search
Log in
Create account
DEV Community
Close
Road to CloudSec LATAM Series' Articles
Back to Gerardo Castro Arica's Series
I Deployed OpenClaw on AWS and Here's What I Found as a Cloud Security Engineer (Part 1)
Gerardo Castro Arica
Gerardo Castro Arica
Gerardo Castro Arica
Follow
for
AWS Heroes
Mar 5
I Deployed OpenClaw on AWS and Here's What I Found as a Cloud Security Engineer (Part 1)
#
aws
#
openclaw
#
ai
#
security
3
reactions
Comments
2
comments
6 min read
A 2018 Access Key. Still Active in Production. Here's the Python Script That Found It Across an Entire AWS Organization.
Gerardo Castro Arica
Gerardo Castro Arica
Gerardo Castro Arica
Follow
for
AWS Heroes
Mar 7
A 2018 Access Key. Still Active in Production. Here's the Python Script That Found It Across an Entire AWS Organization.
#
aws
#
python
#
security
#
opensource
1
reaction
Comments
Add Comment
7 min read
The script worked. The CISO needed something else. iam-audit v2: interactive dashboard, root account detection and Docker.
Gerardo Castro Arica
Gerardo Castro Arica
Gerardo Castro Arica
Follow
for
AWS Heroes
Mar 10
The script worked. The CISO needed something else. iam-audit v2: interactive dashboard, root account detection and Docker.
#
aws
#
python
#
security
#
docker
3
reactions
Comments
Add Comment
8 min read
I Kept Auditing OpenClaw on AWS Lightsail: 53 Default Skills, No Channel Access Controls, Deletable Logs (Part 2)
Gerardo Castro Arica
Gerardo Castro Arica
Gerardo Castro Arica
Follow
for
AWS Heroes
Mar 12
I Kept Auditing OpenClaw on AWS Lightsail: 53 Default Skills, No Channel Access Controls, Deletable Logs (Part 2)
#
aws
#
openclaw
#
security
#
ai
3
reactions
Comments
Add Comment
10 min read
OpenClaw on AWS Lightsail — Threat Model Alignment: OWASP, MITRE ATLAS, and the Gap No Framework Anticipated (Part 3)
Gerardo Castro Arica
Gerardo Castro Arica
Gerardo Castro Arica
Follow
for
AWS Heroes
Mar 23
OpenClaw on AWS Lightsail — Threat Model Alignment: OWASP, MITRE ATLAS, and the Gap No Framework Anticipated (Part 3)
#
ai
#
aws
#
security
#
openclaw
1
reaction
Comments
Add Comment
12 min read
My manager asked if it could run itself. Here's how I automated iam-audit with Fargate, EventBridge and Terraform (Part 3)
Gerardo Castro Arica
Gerardo Castro Arica
Gerardo Castro Arica
Follow
for
AWS Heroes
Mar 24
My manager asked if it could run itself. Here's how I automated iam-audit with Fargate, EventBridge and Terraform (Part 3)
#
aws
#
security
#
python
#
boto3
1
reaction
Comments
Add Comment
7 min read
I automated an AWS Security Maturity Model recommendation across 40 accounts — design decisions included
Gerardo Castro Arica
Gerardo Castro Arica
Gerardo Castro Arica
Follow
for
AWS Heroes
Mar 25
I automated an AWS Security Maturity Model recommendation across 40 accounts — design decisions included
#
aws
#
security
#
cloud
#
python
Comments
Add Comment
10 min read
Mutable tags. 10,000 pipelines. One credential. — What the Trivy attack taught me about implicit trust
Gerardo Castro Arica
Gerardo Castro Arica
Gerardo Castro Arica
Follow
for
AWS Heroes
Mar 27
Mutable tags. 10,000 pipelines. One credential. — What the Trivy attack taught me about implicit trust
#
ai
#
security
#
devsecops
#
aws
Comments
Add Comment
10 min read
We're a place where coders share, stay up-to-date and grow their careers.
Log in
Create account