Cloud threat hunting, detection engineering, and security tooling.
I hunt threats in cloud environments. This is where I publish what I find: offensive techniques and the telemetry that catches them, detection engineering notes, and the tooling I build along the way.
Creating a second access key on a compromised IAM user is one of the quietest persistence mechanisms in AWS. Here is what it looks like in CloudTrail, and a detection that survives contact with production.