{"@attributes":{"version":"2.0"},"channel":{"title":"Rami McCarthy","description":{},"link":"https:\/\/speakerdeck.com\/ramimac","lastBuildDate":"2019-10-19 12:04:54 -0400","item":[{"title":"Move Fast and Break Things: 10 in 20","description":"Sharing 10 AI experiments and the lessions \nBuilders & Breakers - Stockholm, 03\/26\/2026","pubDate":"Thu, 26 Mar 2026 00:00:00 -0400","link":"https:\/\/speakerdeck.com\/ramimac\/move-fast-and-break-things-10-in-20","guid":"https:\/\/speakerdeck.com\/ramimac\/move-fast-and-break-things-10-in-20"},{"title":"Zeal of the Convert: Taming Shai-Hulud with AI","description":"2025 was the year of Shai-Hulud: a series of attacks leaking massive amounts of victim data onto GitHub, ungraciously scheduled for whenever I was traveling. As a responder, these internet-scale incidents were a real-world lab for evolving AI capabilities. This talk is a raw post-mortem of moving from simple \u201cvibe-coded\u201d scrapers to multi-agent triage engines that parallelize victimology and automate secret-impact analysis. Demos will drive a conversation on what actually worked, where the ground has shifted, and how \u201clazy\u201d AI will let you down. Walk away with prompts, scripts, skills, and lessons from my scars.","pubDate":"Wed, 11 Mar 2026 00:00:00 -0400","link":"https:\/\/speakerdeck.com\/ramimac\/zeal-of-the-convert-taming-shai-hulud-with-ai","guid":"https:\/\/speakerdeck.com\/ramimac\/zeal-of-the-convert-taming-shai-hulud-with-ai"},{"title":"The Forensic Trail On GitHub: Hunting For Supply Chain Activity","description":"Ultralytics. tj-actions. Grafana. GitHub Actions are increasingly targeted by attackers and\nimplicated in industry-impacting incidents. Thankfully, GitHub's public surface offers numerous\nthreat intelligence sources for the discerning defender. This talk covers a comprehensive\nmethodology for investigating and tracking real-world supply chain attacks exploiting GitHub\nActions, inspired by our work responding to the aforementioned incidents. It adds a new\ndimension and set of tools to threat intelligence research.\n\nWe'll expose the wealth of intelligence available directly from both GitHub and the underlying Git\nplane. Through concrete demos, we'll show how to effectively pivot on user metadata and\nbehavioral heuristics, uncover attacker forks, and recover deleted gists and commits. We'll also\ndemonstrate how to trace attacker aliases, identify targets of reconnaissance, and unmask\nattackers and researchers in real-time. Attackers are hiding in the complexity of this ecosystem,\nbut with automation we can peel back the noise, empowering detection and investigation.\n\nThis approach is practical, repeatable, and relies exclusively on publicly available data, ensuring\naccessibility for all defenders without the need for private threat intelligence feeds.","pubDate":"Mon, 19 Jan 2026 00:00:00 -0500","link":"https:\/\/speakerdeck.com\/ramimac\/the-forensic-trail-on-github-hunting-for-supply-chain-activity","guid":"https:\/\/speakerdeck.com\/ramimac\/the-forensic-trail-on-github-hunting-for-supply-chain-activity"},{"title":"And I Would've Gotten Away With It, Too, If It Wasn't For You Meddling Researchers","description":"Some research is a slow burn; but mine is often a frantic scramble to keep up with threat actors or CloudSec Twitter. This talk uses the tj-actions\/changed-files incident to expose the raw reality of rapid response research in cloud security. Using the incident as our backdrop, I'll walk you through the nitty-gritty of how a leading cloud security research team investigates urgent supply chain attacks. You'll get actionable takeaways on leveraging external data (okay \u2026 Twitter and Hacker News), the critical role of community, and the behind the scenes collaboration involved in publishing authoritative analysis. Expect a few frantic Slack screenshots and a stark look at how the research sausage is made.","pubDate":"Tue, 16 Sep 2025 00:00:00 -0400","link":"https:\/\/speakerdeck.com\/ramimac\/and-i-wouldve-gotten-away-with-it-too-if-it-wasnt-for-you-meddling-researchers","guid":"https:\/\/speakerdeck.com\/ramimac\/and-i-wouldve-gotten-away-with-it-too-if-it-wasnt-for-you-meddling-researchers"},{"title":"You Are Not Netflix: How to learn from conference talks","description":"Conference talks and engineering blogs are often quilted from small omissions and half-truths. These include subtle white lies about collaboration, minimize of technical challenges, inflate outcomes, and omit critical details regarding risks, technical debt, and unresolved issues. This is part of the unspoken social contract in sharing sensitive internal information publicly.\n\nThe key is to read between the lines, spot the implicit, and still extract meaningful insights. This talk will provide you with a framework to navigate these nuances effectively.\n\nWe\u2019ll explore what is often left unsaid, examine real-world examples, and equip you with the tools to make the most of fwd:cloudsec and similar events!","pubDate":"Tue, 01 Jul 2025 00:00:00 -0400","link":"https:\/\/speakerdeck.com\/ramimac\/you-are-not-netflix-how-to-learn-from-conference-talks","guid":"https:\/\/speakerdeck.com\/ramimac\/you-are-not-netflix-how-to-learn-from-conference-talks"},{"title":"Scale Security Programs with Scorecarding","description":"\nSecurity teams increasingly take a collaborative, partnership-based approach to securing their applications and organizations. Scaling these efforts requires thoughtfully distributing awareness and ownership of security risk. Scorecarding is used at leading companies to make security posture visible, actionable, and engaging across the entire organization.\n\nIn this session, we dive into how companies like Netflix, Chime, GitHub, and DigitalOcean use scorecarding to distribute security ownership, drive continuous improvement, and align risk management with business goals. You\u2019ll walk away with practical, tool-agnostic strategies for implementing your own scorecarding program that not only enhances security posture but fosters a culture of shared responsibility and proactive risk management.\n","pubDate":"Fri, 30 May 2025 00:00:00 -0400","link":"https:\/\/speakerdeck.com\/ramimac\/scale-security-programs-with-scorecarding","guid":"https:\/\/speakerdeck.com\/ramimac\/scale-security-programs-with-scorecarding"},{"title":"How to 10X Your Cloud Security (Without the Series D)","description":"I\u2019ll summarize and distill the actionable guidance for scaling Cloud Security programs from the vast array of talks and blog posts our there. We'll blaze through a dense view of what cloud security is, how you can do it more effectively, and what the near future looks like. After the talk, you'll have practical takeaways, and a lengthy, curated bibliography to lean on.","pubDate":"Wed, 11 Sep 2024 00:00:00 -0400","link":"https:\/\/speakerdeck.com\/ramimac\/how-to-10x-your-cloud-security-without-the-series-d","guid":"https:\/\/speakerdeck.com\/ramimac\/how-to-10x-your-cloud-security-without-the-series-d"},{"title":"The Path to Zero Touch Production","description":"Zero Touch Prod is a Google-ism, and also a good idea. It's common that engineers, even at companies with strong security programs and cloud-native architecture, organically evolve operational processes that require they touch production daily.\n\nAs security practitioners, it's our job to keep our companies safe - both from bad actors, and also humans making mistakes. Allowing humans to work directly in production infrastructure introduces mitigable risks.\n\nThis talk shares my universal theory of how to incrementally and collaboratively move a cloud-native organization to Zero Touch Prod. We'll talk about why people touch prod, how they touch prod, and what we can do about it. I'll include a summary of the various production access primitives available in AWS, when to use them, and how to do so safely. We'll dive deep on the implementation options for building blocks like JIT\/Temporary Access and operational script running.\n\nWherever you are in your Access Journey, you'll walk away with practical and pragmatic next steps!","pubDate":"Tue, 18 Jun 2024 00:00:00 -0400","link":"https:\/\/speakerdeck.com\/ramimac\/the-path-to-zero-touch-production","guid":"https:\/\/speakerdeck.com\/ramimac\/the-path-to-zero-touch-production"},{"title":"Beyond the Baseline: Horizons for Cloud Security Programs","description":"There is a definitive resource for cloud-native companies to build a security program and posture in AWS: Scott Piper\u2019s AWS Security Maturity Roadmap. However, mature programs quickly progress past the end of Scott\u2019s roadmap. In this talk, I\u2019ll take you on a rapid fire tour beyond the end of the roadmap, focusing on the problems you\u2019ll encounter scaling a cloud security program. A key framework will be \u201cbuild versus buy,\u201d and the talk will be opinionated about where cloud security teams can fall into the trap of undifferentiated work. The goal is to leave you with a clear view of the possibilities at the leading edge of cloud security, risk-informed guidance on priorities, and a crucial new reference for writing cloud security roadmaps.","pubDate":"Fri, 15 Sep 2023 00:00:00 -0400","link":"https:\/\/speakerdeck.com\/ramimac\/beyond-the-baseline-horizons-for-cloud-security-programs","guid":"https:\/\/speakerdeck.com\/ramimac\/beyond-the-baseline-horizons-for-cloud-security-programs"},{"title":"Beyond the AWS Security Maturity Roadmap","description":"Scott (Piper)\u2019s AWS Security Maturity Roadmap is the definitive resource for cloud-native companies to build a security program and posture in AWS. It does an amazing job at providing broadly applicable guidance along the maturity curve. However, for many fwd:cloudsec attendees, the roadmap ends too soon.\n\nIn my experience there is a set of technical capabilities and controls that companies should consider once they\u2019ve \u201cshipped the roadmap.\" In this talk, I\u2019ll take you on a rapid fire tour beyond Scott's paved road, focusing on the problems you\u2019ll encounter scaling a cloud security program. A key framework will be \u201cbuild versus buy,\u201d and the talk will be opinionated about where cloud security teams can fall into the trap of undifferentiated work.\n\nThe goal is to walk away with a clear view of the possibilities at the leading edge of cloud security, risk-informed guidance on priorities, and a crucial new reference for writing cloud security roadmaps.\n","pubDate":"Mon, 12 Jun 2023 00:00:00 -0400","link":"https:\/\/speakerdeck.com\/ramimac\/beyond-the-aws-security-maturity-roadmap","guid":"https:\/\/speakerdeck.com\/ramimac\/beyond-the-aws-security-maturity-roadmap"},{"title":"Buying Security","description":"You can\u2019t buy security, but vendors play a key role in effective security programs. This talk will provide a comprehensive guide to buying and getting value, based on experiences on both sides of the marketplace, a comprehensive literature review, and a survey of clients and vendors of all stripes.","pubDate":"Sat, 04 Jun 2022 00:00:00 -0400","link":"https:\/\/speakerdeck.com\/ramimac\/buying-security","guid":"https:\/\/speakerdeck.com\/ramimac\/buying-security"},{"title":"Learning from AWS Customer Security Incidents [2022]","description":"This show will discuss the public catalog of AWS Customer Security Incidents (https:\/\/github.com\/ramimac\/aws-customer-security-incidents), covering over twenty different public breaches. We\u2019ll walk through the technical details of these attacks, establish the common root causes, look at lessons learned, and establish how you can proactively secure your environment against these real world risks.","pubDate":"Sun, 15 May 2022 00:00:00 -0400","link":"https:\/\/speakerdeck.com\/ramimac\/learning-from-aws-customer-security-incidents-2022","guid":"https:\/\/speakerdeck.com\/ramimac\/learning-from-aws-customer-security-incidents-2022"},{"title":"Cloud Security Orienteering","description":"Most of us are not lucky enough to have architected the perfect cloud environment, according to this month's best practices, and without any legacy elements or \"\"surprise\"\" assets. Over the course of a career in cloud security, you'll likely find yourself walking into a new environment and needing to rapidly orient yourself to both mitigate the biggest risks and also develop a roadmap towards a sustainable, secure future. As a security consultant, I had the challenge and opportunity to enter blind into a variety of cloud environments. They were across Azure, GCP, and AWS, some well-architected and others organically sprawling, containing a single account\/project and hundreds. This gave me a rapid education in how to find the information necessary to familiarize myself with the environment, dig in to identify the risks that matter, and put together remediation plans that address short, medium, and long term goals. This talk will present a cloud and environment agnostic methodology for getting your bearings if tasked with securing a novel cloud environment. We'll learn by applying this to a sample AWS environment in order to cover:\nAn archeological guide for where and how to find organizational context\nHow to quickly find and kill the most common attack vectors at the perimeter (both network and identity)\nCommon architectural and deployment patterns, how to spot them, and their security implications\nWhat you need to know, what you need to prioritize, and what \"\"best practices\"\" aren't worth the squeeze when you're in a crunch.","pubDate":"Sun, 08 Aug 2021 00:00:00 -0400","link":"https:\/\/speakerdeck.com\/ramimac\/cloud-security-orienteering","guid":"https:\/\/speakerdeck.com\/ramimac\/cloud-security-orienteering"},{"title":"Learning from AWS (Customer) Security Incidents","description":"Presented at BSidesCT 2020\n\nIn light of the increasing adoption of cloud computing, there have has been broad coverage of the compromise of customer environments in the cloud. In both popular and technical literature however, there has been a focus on the most egregious, simplest breaches (i.e open S3 buckets). However, deeper analysis shows a much broader variety of tactics currently exploited by attackers and researchers to compromise cloud environments.\n\nThis talk will, with a focus on AWS, discuss over a dozen different public breaches. We'll walk through the technical details of these attacks, establish the common root causes, look at lessons learned, and establish how you can proactively secure your environment against these real world risks.","pubDate":"Sat, 14 Nov 2020 00:00:00 -0500","link":"https:\/\/speakerdeck.com\/ramimac\/learning-from-aws-customer-security-incidents","guid":"https:\/\/speakerdeck.com\/ramimac\/learning-from-aws-customer-security-incidents"},{"title":"AWS Security: Easy Wins and Enterprise Scale","description":"Presented at BSides Boston 2020\n\nCloud computing continues its rampant growth, and AWS maintains its lead as the predominant platform. Since the last BSidesBoston in 2017, AWS adoption has gone from 57% to 76% of enterprises (Per RigthScale\/Flexera State of the Cloud 2017\/2020). Whether your organization has two feet firmly in the cloud, is dipping a toe in the water, or you personally are wondering \"where do I even start,\" it's important to learn to adjust security to cloud environments.\n\nThis talk will look at two ends of the spectrum. First, we'll go through the easy wins that almost any one or any organization can identify and apply. Then, we'll pivot to look as the the big picture security problems to consider as either your security maturity or AWS usage grows. We won't be able to go deep into all the weeds of the topic, but instead we'll provide the essential information, and pointers for next steps. No matter the size, complexity, or sophistication of your AWS environment, you should walk away with an idea of where to look for your next actionable improvements.","pubDate":"Sat, 26 Sep 2020 00:00:00 -0400","link":"https:\/\/speakerdeck.com\/ramimac\/aws-security-easy-wins-and-enterprise-scale","guid":"https:\/\/speakerdeck.com\/ramimac\/aws-security-easy-wins-and-enterprise-scale"},{"title":"Building Castles in the Cloud: AWS Security and Self-Assessment","description":"As comfort and familiarity with cloud computing is now more mainstream, companies are leaning more and more on cloud resources to host and run even their most-sensitive technical assets. With these new technologies\/innovations come new (and old!) security concerns. As a consultant, I\u2019ve had experience breaking into a AWS environments with varying sophistication of security posture, and then helping those clients patch holes and harden their environments. This talk with lean on those experiences to provide you with a guide on securing your AWS environment, and then validating that security.\n\nWe\u2019ll start by walking through AWS\u2019s Shared Responsibility Model. Then we\u2019ll identify the features of AWS that are most important for security, and give tips on best practices and easy wins. After establishing these security standards, we\u2019ll take a quick look at a few (free) tools for auditing AWS configurations, including NCC Group\u2019s own open-source ScoutSuite. You\u2019ll leave this talk with concrete next steps for improving your own cloud security posture.","pubDate":"Sat, 09 Nov 2019 00:00:00 -0500","link":"https:\/\/speakerdeck.com\/ramimac\/building-castles-in-the-cloud-aws-security-and-self-assessment","guid":"https:\/\/speakerdeck.com\/ramimac\/building-castles-in-the-cloud-aws-security-and-self-assessment"},{"title":"AWS Cloud Security Fundamentals","description":"Workshop presented at OWASP BASC 2019 by Rami McCarthy and Joshua Dow\n\nAbstract:\n\n\"As comfort and familiarity with cloud computing is now more mainstream, companies are leaning more and more on cloud resources to host and run even their most-sensitive technical assets. With these new technologies\/innovations come new (and old!) security concerns. In this workshop, we will take participants through a baseline understanding of cloud security - with a focus on AWS security fundamentals.\n\nFirst, we will briefly outline the cloud security model, the similarities across platforms, and the shared responsibility model that Amazon employs. From there, we will introduce participants to open-source tooling for AWS account auditing and hardening, including NCC's own ScoutSuite. We will provide access to an intentionally vulnerable AWS environment, to allow workshop attendees to follow along and explore misconfigurations with their own eyes. We also will support attendees who want to immediately dive into auditing their own AWS accounts\/environments.\n\nNext, we'll highlight easy wins for AWS security, that the audience will be able to immediately apply to their own environments. Following that, we'll speak to Amazon's built-in security tooling, including:\n\n    Security Hub\n    Trusted Advisor\n    CloudTrail\n    Inspector\n    GuardDuty\n    Macie (and why it's probably wrong for you!)\n\nWe'll focus on actionable guidance to walk away and be able to use these tools to harden your own posture. Subsequently, we'll work with attendees through the misconfigurations that led to the Capital One breach, via the CloudGoat scenario. Wrapping up, we'll provide a easy to follow cheatsheet of best practices, easy wins, and open source tools that attendees can reference to improve their own environments. \"","pubDate":"Sat, 19 Oct 2019 00:00:00 -0400","link":"https:\/\/speakerdeck.com\/ramimac\/aws-cloud-security-fundamentals","guid":"https:\/\/speakerdeck.com\/ramimac\/aws-cloud-security-fundamentals"}]}}