hardening-cloud-posture

Installation
SKILL.md

Hardening Cloud Posture

A CSPM scan returns a thousand findings. Almost none of them are the way in. The job is not to close a thousand findings; it is to find the handful that form an attack path and close those, then set guardrails so they cannot recur. Posture work that treats every finding as equal drowns the real one.

The organizing principle: identity is the perimeter. In cloud, the attack path is almost always a chain of IAM permissions, not a network hop. Rank by "what does this let a principal reach?", not by a scanner's severity label.

When to Use

  • Reviewing an AWS/Azure/GCP account or organization's security posture
  • Triaging a Prowler, ScoutSuite, Security Hub, or Defender for Cloud report
  • Deciding which of many misconfigurations actually matter
  • Setting preventive guardrails (SCPs, Azure Policy, org policies)
  • Enabling the logging and controls an investigation will later depend on
Installs
21
GitHub Stars
146
First Seen
Jul 31, 2026
hardening-cloud-posture — trilwu/secskills