Skip to content

Archive

Monitoring

6 articles
Cybersecurity 08 Sep 2026 9 min read

Monitor Certificate Transparency for Unexpected Certificates

A public TLS certificate can make a server appear to belong to your domain. If a certificate is issued when you did not expect one, the cause may be harmless automation, an undocumented service, or a mistake. It may also indicate that someone obtained certificate issuance through a path you did not intend to authorize. Looking only at certificates deployed on your own servers is not enough. An unexpected certificate may never appear on infrastructure you control.

Cybersecurity 08 Sep 2026 11 min read

Detect Security Configuration Drift Before It Becomes Exposure

A service can start with a careful security configuration and still become exposed later. A debug endpoint is enabled during an incident and never disabled. An access rule is widened for a migration. A storage policy changes outside the normal deployment path. None of these failures requires a new software vulnerability. The security boundary changed because the running configuration stopped matching the state the team intended. This kind of divergence is configuration drift: a meaningful difference between an approved or expected configuration and the configuration that actually controls a system. Drift matters when the changed setting affects who can reach a resource, what they can do, what data is exposed, or which security controls remain active.

Cybersecurity 07 Sep 2026 12 min read

Keep Security Log Timestamps Comparable Across Systems

Security logs often become most important when several systems disagree about what happened. An identity service records a login, an API records a privileged request, and a database records a change. Investigators then sort those events by time to reconstruct the sequence. That reconstruction can be wrong even when every log entry is genuine. If one system’s clock is two minutes fast and another is one minute slow, sorting their timestamps can place effects before causes. A detector that expects two events within 30 seconds can miss a real sequence for the same reason.

Cybersecurity 05 Sep 2026 10 min read

Use Honeytokens to Detect Credential Misuse

Many security alerts begin with ordinary activity: a login, an API request, or a secret being read. The difficult question is whether that activity is legitimate. A real credential may be used by several expected systems, so a single use often provides weak evidence of compromise. A honeytoken changes that problem by creating an identity or credential that has no legitimate operational use. If something tries to use it, the event is unusual by design and can produce a high-signal alert.

Cybersecurity 05 Sep 2026 8 min read

Protect Security Logs from the Systems They Observe

Logs are most valuable during a security incident, exactly when the system producing them may no longer be trustworthy. If an attacker gains administrative control of an application server and its only audit trail is stored on that same server, the attacker may be able to alter or remove both the activity and the evidence of it. The defensive problem is therefore not just what to log. It is also who can change the log after it is created.

Cybersecurity 02 Sep 2026 6 min read

Design Security Logs for Incident Detection

Security logging is not simply collecting more application output. Its purpose is to leave reliable evidence of security-relevant activity so that suspicious behaviour can be detected, investigated, and explained. Useful logs answer practical questions: what happened, when did it happen, which identity or client was involved, what resource was affected, and what was the result? Log security decisions, not every detail Start with events that represent changes in identity, authority, access, or security state.