<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Quentin Brusa &#8211; SCRT Team Blog</title>
	<atom:link href="/author/qbr/feed/" rel="self" type="application/rss+xml" />
	<link>/</link>
	<description>Orange Cyberdefense Switzerland&#039;s technical blog</description>
	<lastBuildDate>Thu, 16 Jan 2025 15:17:23 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>/wp-content/uploads/2024/10/cropped-favicon-32x32-1-32x32.png</url>
	<title>Quentin Brusa &#8211; SCRT Team Blog</title>
	<link>/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>The effect of granting Azure Reader role on Azure Container Registry instances</title>
		<link>/2024/12/13/understanding-azure-container-registry-permissions-a-security-concern/</link>
		
		<dc:creator><![CDATA[Quentin Brusa]]></dc:creator>
		<pubDate>Fri, 13 Dec 2024 08:27:13 +0000</pubDate>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[azure]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[research]]></category>
		<guid isPermaLink="false">/?p=6672</guid>

					<description><![CDATA[We observed that granting Azure Reader role at subscription or resource group level allows users to pull container images from Azure Container Registry instances, thus potentially reveling confidential or sensitive data to unauthorised parties. In a recent security configuration review of one our client’s Azure workloads,&#160;we uncovered a significant issue regarding the Azure Container Registry &#8230; <a href="/2024/12/13/understanding-azure-container-registry-permissions-a-security-concern/" class="more-link">Continue reading <span class="screen-reader-text">The effect of granting Azure Reader role on Azure Container Registry instances</span></a>]]></description>
		
		
		
			</item>
		<item>
		<title>Splunk Boss Of The SOC (BOTS) @Insomni&#8217;hack</title>
		<link>/2022/04/04/splunk-boss-of-the-soc-bots-insomnihack/</link>
		
		<dc:creator><![CDATA[Quentin Brusa]]></dc:creator>
		<pubDate>Mon, 04 Apr 2022 09:28:41 +0000</pubDate>
				<category><![CDATA[Analytics]]></category>
		<category><![CDATA[Insomni'hack]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">/?p=3453</guid>

					<description><![CDATA[It&#8217;s was a pleasure this year to meet you at the 2022 edition of our amazing security conference Insomni&#8217;hack ! With Splunk collaboration, we come back this year with &#8220;Splunk Boss Of The SOC&#8221; challenge. What is BOTS and his history Boss Of The SOC (BOTS) is a blue-team version of capture the flag competition. &#8230; <a href="/2022/04/04/splunk-boss-of-the-soc-bots-insomnihack/" class="more-link">Continue reading <span class="screen-reader-text">Splunk Boss Of The SOC (BOTS) @Insomni&#8217;hack</span></a>]]></description>
		
		
		
			</item>
		<item>
		<title>Event Masker &#8211; 2021.08 Release</title>
		<link>/2021/07/26/event-masker-2021-08-release/</link>
		
		<dc:creator><![CDATA[Quentin Brusa]]></dc:creator>
		<pubDate>Mon, 26 Jul 2021 12:43:15 +0000</pubDate>
				<category><![CDATA[Analytics]]></category>
		<guid isPermaLink="false">/?p=3192</guid>

					<description><![CDATA[We are proud to announce a new release for Event Masker, with many productivity tweaks and significant enhancements. ES Integration It was cumbersome to move from the tab where you had the notable event you wanted to mask, to the tab with Event Masker opened on the correct rule. That is why you may now &#8230; <a href="/2021/07/26/event-masker-2021-08-release/" class="more-link">Continue reading <span class="screen-reader-text">Event Masker &#8211; 2021.08 Release</span></a>]]></description>
		
		
		
			</item>
		<item>
		<title>Splunk &#038; advanced filtering with Event Masker</title>
		<link>/2021/05/03/splunk-advanced-filtering-with-event-masker/</link>
		
		<dc:creator><![CDATA[Quentin Brusa]]></dc:creator>
		<pubDate>Mon, 03 May 2021 14:34:47 +0000</pubDate>
				<category><![CDATA[Analytics]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">/?p=3164</guid>

					<description><![CDATA[What is Splunk ? Splunk is a Data-to-Everything Platform designed to ingest and analyze all kind of data. They can be visualized and correlated through Splunk searches, alerts, dashboards, and reports. Splunk is the #1 of 2020 Gartner Magic Quadrants in SIEMs for its performant analysis and visionary in Application Performance Management category. Splunk and &#8230; <a href="/2021/05/03/splunk-advanced-filtering-with-event-masker/" class="more-link">Continue reading <span class="screen-reader-text">Splunk &#38; advanced filtering with Event Masker</span></a>]]></description>
		
		
		
			</item>
	</channel>
</rss>
