@tg_infosec · Post #3198 · 05/12/2025, 09:31 AM
👨💻 Attacking IaC. • Least Privilege; • Secrets Management; • Encryption of Sensitive Data; • Compliance as code; • terraform plan; • pet Infra; • Storing Terraform State Securely; • Malicious Terraform Providers or Modules; • Securing Terraform Executions with Isolation; • Protecting Sensitive Variables in Terraform Logs; • Securing API Keys and Archivist URLs in HCP Terraform; • Use dynamic credentials; • Terraform Plan vs Terraform Apply; • Replace blacklisted provider. #IaC#DevSecOps
Hashtags