Rrathsarainrr-cyber.hashnode.dev·Aug 14 · 31 min readUnderstanding OAuth 2.0: Delegation, Grant Types, and the Attacks That Actually HappenThe first time I heard the term OAuth, I didn't know what it meant. I was in a conversation with a DBA lead about something adjacent to authentication and authorization, and he mentioned, almost in pa00
Rrathsarainrr-cyber.hashnode.dev·Aug 6 · 15 min readIdentity Foundations: Everything Before OAuthBefore any protocol makes sense on its own terms, a few things underneath it need to be settled first: what authentication and authorization actually are as distinct concepts, how identity gets carrie13N
Rrathsarainrr-cyber.hashnode.dev·Aug 5 · 9 min readIdentity Was the Gap I Did Not Know I HadI had worked across cloud security engineering, vulnerability assessment, penetration testing, and application security. I had reviewed IAM configurations across multiple cloud platforms, flagged over11N
Rrathsarainrr-cyber.hashnode.dev·Jul 18 · 14 min readOperationalising It: Making Prisma Cloud Actually UsefulAfter the Rollout: The Work That Actually Starts Deploying Prisma Cloud took months. Making it operational took longer. By the time CWPP was live across OCI and GCP and CSPM was covering all four clou11N
Rrathsarainrr-cyber.hashnode.dev·Jun 26 · 17 min readThree Vendors, One Verdict: Evaluating CSPM and CWPP at Enterprise ScaleA Note Before This Goes Further Everything in this article reflects a specific environment: an OCI-majority estate, thirty compartments, fifty-plus business units, and compliance obligations across IS10
Rrathsarainrr-cyber.hashnode.dev·Jun 27 · 9 min readDeploying Prisma Cloud Across AWS, Azure, OCI and GCP: What Actually Happened ?A proof of concept tells you a product works. It doesn't tell you what happens when you try to onboard fifty-plus business units, four cloud providers, and four identity stacks without breaking anythi00
Rrathsarainrr-cyber.hashnode.dev·May 23 · 10 min readFour Clouds, No Visibility: The Multi-Cloud Security Problem Nobody Had Budgeted ForHow We Ended Up Here I joined as a Cloud and Operations Security Specialist. Secure the cloud stack, operationalise it. That was the brief. Nobody mentioned there were four. Before anything else, I wa10
Rrathsarainrr-cyber.hashnode.dev·May 19 · 11 min readBuilding The Technical Foundation For Continuous Vulnerability VisibilityThis is the second article in the series. The first one covered why our periodic scanning model had stopped working at scale. This one is the technical account of what we built in its place. A quick n10
Rrathsarainrr-cyber.hashnode.dev·May 17 · 23 min readROOTING THE WORLD’S FIRST CYBER SUPER-WEAPON: STUXNETIn June 2010, a Belarusian security firm received a routine support request. A client's Windows PC kept crashing with the infamous Blue Screen of Death. Malware analyst Sergey Ulasen dug in, expecting20
Rrathsarainrr-cyber.hashnode.dev·May 16 · 6 min readThe Vulnerability Scanning Model That Stopped Working at ScaleMost vulnerability management programmes are designed to produce reports, not to maintain a continuously answerable state of exposure. Ours was one of them. We had a working Qualys deployment and no o00