<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cloud Security on Packets &amp; Regrets</title><link>https://matijazezelj.github.io/packets-and-regrets/tags/cloud-security/</link><description>Recent content in Cloud Security on Packets &amp; Regrets</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Mon, 31 Aug 2026 18:00:00 +0200</lastBuildDate><atom:link href="https://matijazezelj.github.io/packets-and-regrets/tags/cloud-security/index.xml" rel="self" type="application/rss+xml"/><item><title>I Built the Cloud Audit SIEM I Kept Wishing Existed</title><link>https://matijazezelj.github.io/packets-and-regrets/posts/i-built-the-cloud-audit-siem-i-kept-wishing-existed/</link><pubDate>Mon, 31 Aug 2026 18:00:00 +0200</pubDate><guid>https://matijazezelj.github.io/packets-and-regrets/posts/i-built-the-cloud-audit-siem-i-kept-wishing-existed/</guid><description>&lt;p&gt;Cloud audit logs contain some of the best evidence in an incident and some of the least pleasant data to operate.&lt;/p&gt;
&lt;p&gt;Every provider has a different delivery mechanism, event shape, pagination model, failure mode, and idea of what an actor or target should look like. Getting the logs is only the start. You still need to normalize them without throwing away the original event, detect hostile behavior, notice when collection silently stops, retain enough history to investigate, and prove that the whole thing survives a database failure and a restore.&lt;/p&gt;</description></item></channel></rss>