Generated by All in One SEO v5.0.0.1, this is an llms.txt file, used by LLMs to index the site. # ARGOS Cloud Security Visualize the cloud ## Sitemaps - [XML Sitemap](https://argos-security.io/sitemap.xml): Contains all public & indexable URLs for this website. ## Posts - [ARGOS Cloud Security Blog](https://argos-security.io/blog/) - [Overprivileged Azure Users and the Hidden Risk of Managed Identities](https://argos-security.io/2026/02/11/overprivileged-azure-users-and-the-hidden-risk-of-managed-identities/) - Many teams are confident they have virtual machine access under control. Interactive access is tightly restricted.SSH and RDP are only available through jump hosts.Privileged sessions are brokered via tools like CyberArk.Local administrator credentials are rotated, logged, and reviewed. From an operating system perspective, this model often works well. The problem is that these controls only - [Why Cloud Infrastructure Pentests Matter](https://argos-security.io/2026/01/19/why-cloud-infrastructure-pentests-matter/) - Cloud compliance assessments don’t tell you how you’ll actually be breached. Cloud infrastructure pentests exist for that exact reason. Here’s where the difference really matters… - [Create Entra ID App Registration using PowerShell](https://argos-security.io/2025/01/29/create-entra-id-app-registration-using-powershell/) - Quite regularly teams need to create Entra ID App Registrations. One use case might be the onboarding of a SaaS (like ARGOS Cloud Security) into their environment. To simplify this process, we’ve developed a PowerShell script that automates the creation of an App Registration in Entra ID and assigns the necessary permissions. The script can - [The AI Executive Order - What Does It Mean For Security Teams?](https://argos-security.io/2023/12/21/the-ai-executive-order-what-does-it-mean-for-security-teams/) - The recent Executive Order on AI by President Biden heralds a new era in AI governance, with profound implications for security teams. This guide will delve into what this order means for these teams, focusing on safety, security, and privacy in AI applications. - [Unpacking Azure's Private Subnet - Closer Look at Security and Functionality](https://argos-security.io/2023/12/01/unpacking-azures-private-subnet-closer-look-at-security-and-functionality/) - Let's dive into a new feature in Azure virtual networking: the Azure private subnet. It's more than just a feature, it's a strategic approach to enhancing network security and management. Albeit, in our opinion, a few years late. Note: AWS has always required customers to provide explicit outbound connectivity. - [Discovering Attack Paths in Microsoft Azure for Enhanced Security](https://argos-security.io/2023/11/18/discovering-attack-paths-in-microsoft-azure-for-enhanced-security/) - We’re changing the way consultants assess Azure Subscriptions and detect Attack Paths. All you need is “Reader” access to an Azure Subscription and a few minutes time, that’s it, nothing more. In The Olden Days Typically, as consultants being tasked with a security assessment of an Azure Subscription we would have manually clicked around the - [Uncovering Lateral Movement Paths in Azure](https://argos-security.io/2023/10/04/uncovering-lateral-movement-paths-in-azure/) - In the sprawling metropolis of cloud environments, Azure shines as a central hub, teeming with a myriad of services. However, amidst this vast expanse, lurk unseen alleyways known as lateral movement or attack paths, which could be exploited by adversaries to traverse through the cloud undetected. - [Common Azure Kubernetes (AKS) Misconfigurations and How to Fix Them](https://argos-security.io/2023/05/03/common-azure-kubernetes-aks-misconfigurations-and-how-to-fix-them/) - In this article, we will detail the most common AKS misconfigurations, explain their security implications, and provide tips on how to detect and fix them using Azure CLI or Resource Graph examples. - [Top 5 Azure VM Security Blunders That Get You Owned](https://argos-security.io/2023/04/08/top-5-azure-vm-security-blunders-that-get-you-owned/) - In this article, we'll explore the top 5 security misconfigurations of Azure VMs and provide tips on how to fortify your infrastructure against potential risks. - [Is Your Azure SQL at Risk? Learn How to Secure It with this Step-by-Step Guide](https://argos-security.io/2023/03/18/is-your-azure-sql-at-risk-learn-how-to-secure-it-with-this-step-by-step-guide/) - Azure SQL is a cloud-based relational database management system that is widely used by businesses and organizations around the world. It offers a range of security features to help protect data and prevent unauthorized access, ensuring that sensitive information remains safe and secure. In this blog post, we will discuss some of the key security - [Identifying and Securing Hidden Attack Paths in Azure Infrastructure](https://argos-security.io/2023/03/17/identifying-and-securing-hidden-attack-paths-in-azure-infrastructure/) - Identifying and Securing Hidden Attack Paths in Azure Infrastructure - [Why We Started ARGOS - Cloud Security FOR Consultants](https://argos-security.io/2023/01/25/why-we-started-argos-cloud-security-for-consultants/) - Today, we wanted to give you a little history lesson into why we started ARGOS. What lead us to build this Cloud Security SaaS in a time where there seemingly already are so many others around? Tools are not made for Consultants Our founder David has been a cloud security consultant for over a decade - [How to protect SaaS with Strong Azure MFA Authentication](https://argos-security.io/2022/10/14/how-to-protect-saas-with-strong-azure-mfa-authentication/) - Often customers ask us how they can protect the information stored within ARGOS from individuals that should not have access to it. Attackers regularly gain access to administrators’ identities and attempt to understand what those identities might have access to. This access more often than not includes third party SaaS products, like ARGOS. We are - [How to make sense of CSPM, CAASM, CIEM, CNAPP](https://argos-security.io/2022/06/07/how-to-make-sense-of-cspm-casm-ciem-cnapp/) - Did you come here because you typed “What is CSPM” or “Do I need a CIEM?” into the search engine? Maybe even “Do I really need 20 different security products?”.You’re not alone. These are questions we have been hearing from many people over the last 2 years. Because the last few years were not great - [How To Secure an AWS IAM Role by IP Address](https://argos-security.io/2022/01/12/how-to-secure-an-aws-iam-role-by-ip-address/) - Amazon Web Services (AWS) Identity and Access Management (IAM) is one of the things that is often, let’s say, overly complicated, but it is paramount to get it right. Incorrectly applied or overly permissive IAM policies and roles are often factors in cloud incidents. Correct configuration of IAM permissions is especially important when granting access - [How to Secure an Azure Service Principal with Conditional Access](https://argos-security.io/2021/11/29/how-to-secure-an-azure-service-principal-with-conditional-access/) - Identity and Access Management (IAM) is absolutely fundamental to a Cloud operation, however, sometimes you had to make allowances for certain scenarios. For example, in order to gain access to a Microsoft Azure environment the most common way for Software as a Service (SaaS) products was to ask a customer for a Service Principal / - [How to Integrate with Microsoft Sentinel SIEM](https://argos-security.io/2021/11/23/how-to-integrate-with-microsoft-sentinel-siem/) - Cloud teams tell us they want to be able to see security issues in their environment in a central location. Going from one proprietary dashboard to another with several context switches, different query languages and only limited views of the whole picture is not just a very arduous task, it also means that things get - [Cloud Security Report 2021](https://argos-security.io/2021/10/27/cloud-security-report-2021/) - We are coming to the end of 2021, and it is a good time to look at the state of cloud security. Several events this year have again highlighted the importance for an increased focus on one’s cloud security posture. An interesting observation of the market is that even though we are well into the - [How to Detect Potentially Dangerous Dangling DNS on AWS](https://argos-security.io/2021/09/22/how-to-detect-potentially-dangerous-dangling-dns-on-aws/) - Dangling DNS records are a real security issue and without going into too much detail as to why this is, here is a quick overview of what “dangling DNS” means in the context of AWS. If you do want to know more about the in-depth problem of dangling DNS we can highly recommend this paper by the - [How To Monitor For Risky Public Azure Virtual Machines](https://argos-security.io/2021/09/15/how-to-monitor-for-risky-public-azure-virtual-machines/) - Public Azure Virtual Machines are one of the most exploited resources in the Azure cloud. As we mentioned in our recent white paper (here) it only takes a few seconds on average for someone to test your Virtual Machine for weaknesses, if they are available on the internet. As we also state, it is very - [How to Monitor for Secrets in AWS Lambda](https://argos-security.io/2021/09/20/how-to-monitor-for-secrets-in-aws-lambda/) - AWS Lambda Functions have been, are and will be a major part of most AWS implementations. They are super handy, quick to develop, can be really cheap and generally just does what it needs to do. In general it is considered good practice to not hard code any values into code, functions / methods (depending - [How to find those stupid & annoying public AWS S3 Buckets](https://argos-security.io/2021/09/07/how-to-find-those-stupid-annoying-public-aws-s3-buckets/) - One of probably the most commonly referred to services in breaches / data leaks is Amazon AWS's storage service S3. Why? Because it is easy to misconfigure it. - [Azure CosmosDB Vulnerability - What do I need to do?](https://argos-security.io/2021/09/02/azure-cosmosdb-vulnerability-what-do-i-need-to-do/) - Just recently Wiz released an announcement into a very critical vulnerability in one of Microsoft Azure’s flagship services, Azure Cosmos DB. Because these things all need great names, Wiz called this one #ChaosDB. Is my Cosmos DB Database Secure? Microsoft states “no customer data was accessed because of this vulnerability by third parties or security researchers” If you were - [Cloud Security - a Shared Responsibility](https://argos-security.io/2018/06/22/cloud-security-a-shared-responsibility/) - Why is Cloud Security such a big challenge? Many organisations seem to struggle with insecure cloud environments even though their Cloud Providers (Microsoft Azure, Amazon AWS, Google GCP) provide them with all the tools they need to create secure platforms. - [Context Matters](https://argos-security.io/2018/06/22/context-matters/) - We have all likely been in situations where someone said something and it did not make much sense or it did not apply in the situation you were in at that time. - [Data Is Important – But Not Everything](https://argos-security.io/2018/06/20/data-is-important-but-not-everything/) - What is one of the worst things that can happen to your company? What you're thinking about is probably related to data. Am I right? - [Write Custom Functionality with ARGOS APIs](https://argos-security.io/2018/06/20/write-custom-functionality-with-argos-apis/) - A very common feature request over the last few months was to enable people in the ARGOS ecosystem to write custom functionality against our APIs. Initially this was not possible as we did not expose our APIs for direct consumption. - [Most Common Cloud Misconfigurations 2021 - Not What You Might Have Thought](https://argos-security.io/2018/06/22/most-common-cloud-misconfigurations-2021-not-what-you-might-have-thought/) - ARGOS has deep insights into our customers' cloud environments across the three major public clouds providers. There are a handful of common recurring themes when it comes to cloud misconfigurations. ## Pages - [Automated Cloud Assessments for Consultants](https://argos-security.io/) - Revolutionize your cloud security assessments: Save loads of time, let ARGOS gather, visualize and analyze the data. Support for Azure and Entra ID. - [Features](https://argos-security.io/features/) - Cloud security assessments that go beyond configuration checks Map customer environments, uncover real attack paths and generate client-ready reports automatically. BOOK DEMO SAMPLE REPORT One workflow, from connection to report ARGOS brings cloud inventory, risk analysis, attack paths, diagrams and reporting into one repeatable assessment workflow. Connect → Assess → Visualise → Report No agents. - [ARGOS Sample Report](https://argos-security.io/argos-sample-report/) - See what an ARGOS assessment delivers Download a sanitised sample report with executive findings, attack paths, architecture diagrams and technical remediation guidance. Please fill out the form below and we will send you the report download links to your email address.Want to see how it’s created instead? Click the button here. Book a Walkthrough Request - [About Us](https://argos-security.io/about-us/) - About ARGOS Cloud Security and its team - [ARGOS for MSPs](https://argos-security.io/argos-for-msps/) - Turn cloud security assessments into a repeatable MSP service Assess Azure, Entra ID, Microsoft 365 and AWS environments within hours. Identify real attack paths, verify exposure and deliver customer-ready reports without building your own assessment tooling. Book an MSP walkthrough View a sample report Built for MSPs, MSSPs and cloud consultancies. Understand the risk before - [Pricing](https://argos-security.io/pricing/) - One Plan For All Detailed assessment reports Azure / Entra ID / M365 / AWS ARGOS Cloud Security AI Continuous, near-real-time scans (optional, contact us) Multi-tenant capable ITSM integration SIEM integration Full API access Slack / Teams integration Unlimited users SSO / MFA USD $1100 / per assessment* All good? Sign up! Let's talk if - [Frequently asked Questions](https://argos-security.io/faq/) - Everything you need to know in order to get started and be successful with ARGOS. How do I sign up to ARGOS? Signing up to ARGOS is done in three simple steps. Browse to https://app.argos-security.io/register You'll be asked to log in with your Entra ID / Gmail account first. Add your details (no credit card required!) - [Trust](https://argos-security.io/trust/) - ARGOS Trust Centre Our Trust Centre provides you with the most up to date information on the security, compliance and privacy of ARGOS. Security is front of mind of everything we do at ARGOS which is why we only work with the most trusted providers in the industry that are absolutely aligned to our own - [Videos](https://argos-security.io/videos/) - Find helpful walkthroughs and tutorials here. Starting an Azure Cloud assessment SIGN UP Drilling into Cloud Compliance SIGN UP Azure Application Gateway - AI explains SIGN UP Find deprecated Azure TLS 1.0 and 1.1 resources SIGN UP Start an Entra ID / M365 Assessment SIGN UP Start a Continuous Entra ID / M365 Assessment SIGN - [ARGOS Terms and Conditions](https://argos-security.io/terms-and-conditions/) - Last updated: 01/04/2025 1. OVERVIEW 1.1.These general terms and conditions (Agreement) are a master agreement that governs your relationship with ARGOS Cloud Security Pty Ltd. (us, our) when you access or use in any way our software-as-a-service products and their outputs or capabilities (Services). 1.2.Your use of each Service may also be governed by applicable Service-specific - [ARGOS: Designed for Consulting Companies](https://argos-security.io/argos-for-consultants/) - Scan in minutes, and offer high-margin security assessments at competitive pricing With ARGOS, consulting firms can quickly scan client environments, deliver detailed cloud vulnerability reports, and earn higher margins – all at a competitive price. Our customers tell us this is what they did before ARGOS: average time spent data gathering and analyzing in customer - [ARGOS for Not for Profits](https://argos-security.io/argos-for-not-for-profits/) - Special Offer for Nonprofits ARGOS Cloud Security is committed to serving organisations that create social impact. We offer discounted rates so you can maintain a strong security posture without cutting into your mission budget. Nonprofits receive 25% discount on one-off assessments and a waiver on the minimum spend for continuous 24/7 assessments as published on - [Contact Us](https://argos-security.io/contact-us/) - Get in touch with us! Twitter Linkedin - [Join Waitlist](https://argos-security.io/cloud-consultants-unlock-superior-cloud-audits-with-our-new-ai/) - ARGOS AI will help you make faster, and more accurate assessments of a cloud environment, through the click of a button. Let ARGOS AI help you spot the not so obvious issues in an environment, and fix them quickly. Wow your colleagues and customers with unique and detailed diagrams and recommendations. Join the waitlist now to be among the first to use ARGOS AI. - [Compliance and Security assessments](https://argos-security.io/compliance-and-security-assessments/) - Are you a cloud consultant who regularly executes security and compliance assessments in the Microsoft Azure cloud? Using ARGOS you increase your efficiency and productivity. What used to take days or weeks now only takes minutes. Quickly and easily ARGOS creates a comprehensive report of security and compliance issues in the cloud. ARGOS checks cloud - [Compliance und Security assessments](https://argos-security.io/landing-compliance-und-security-assessments/) - Sind Sie ein Cloud Consultant, der Sicherheits- und Compliance-Assessments in der Microsoft Azure Cloud durchführt? Mit ARGOS steigern Sie ihre Effizienz und Produktivität! ARGOS erstellt schnell und unkompliziert einen umfangreichen Report über die Umgebung. ARGOS prüft die Cloud-Infrastruktur und -Identities gründlich und liefert einen detaillierten ISO27001- und Security-Report mit Handlungsempfehlungen. Erhöhen Sie Ihren Mehrwert für - [Azure consultant beta registration](https://argos-security.io/azure-consultant-beta-registration/) - Thanks for registering to get access to the ARGOS consultant beta for Azure. We will soon be releasing support for individual consultants to use ARGOS with their Microsoft Azure customers and are currently looking for some beta testers that are willing to test the features and give feedback to the ARGOS team. Please enable JavaScript - [Public Cloud Security Implications​](https://argos-security.io/public-cloud-security-implications/) - - most common attack vectors seen with Cloud infra & apps - 100% of environments are targets - remediating actions you can implement now - [ARGOS and Iconic Australian Retailer](https://argos-security.io/argos-and-iconic-australian-retailer/) - The Customer This large, iconic Australian retailer, with operations spanning Australia, New Zealand and the United States, is always innovating with the latest digital tools and platforms. The business uses the three leading public cloud platforms to host its solutions: AWS, Azure and GCP. The Challenge The business’s IT team is always pushing the boundaries - [Case Studies](https://argos-security.io/case-studies/) - ARGOS Case Studies ARGOS secures IDS property valuation data on AWS ARGOS protects retailer's data on Azure, AWS and GCP - [ARGOS and Insight Data Solutions](https://argos-security.io/argos-and-insight-data-solutions/) - The Customer Insight Data Solutions (IDS) is an Australia-based technology business that provides property valuation data and solutions through a unique product suite. IDS prides itself on providing accurate data at speed, and uses the AWS cloud platform to achieve that goal. The Challenge IDS’s cross-functional IT team is tasked with ensuring the security of - [Privacy Policy](https://argos-security.io/privacy-policy/) - ARGOS PRIVACY POLICY OVERVIEW ARGOS Cloud Security Pty Ltd. (We, us) respects your privacy and is committed to protecting your personal information. Our privacy policy outlines our approach to privacy and how we collect, use and protect your personal information and sets out your rights in relation to accessing the personal information we hold ## Landing Pages - [ARGOS Newsletter](https://argos-security.io/argos-newsletter/) - Sign up to our regular ARGOS Cloud Security Newsletter About once a month we send out a newsletter with new product announcements, call for beta testers and community feedback, but also general cloud security news you should be aware of. This won’t be spammy, don’t worry. Use the form below to sign up. - [ARGOS AI waitlist](https://argos-security.io/elementor-landing-page-16765/) - ARGOS AI Join the ARGOS AI waitlist ARGOS AI will help you make faster, and more accurate assessments of a cloud environment, through the click of a button. Let ARGOS AI help you spot the not so obvious issues in an environment, and fix them quickly. Wow your colleagues and customers with unique and detailed ## Categories - [Cloud security](https://argos-security.io/category/cloud-security/) - [Start up](https://argos-security.io/category/start-up/) - [Development](https://argos-security.io/category/development/) - [Devsecops](https://argos-security.io/category/devsecops/) - [CSPM](https://argos-security.io/category/cspm/) - [aws](https://argos-security.io/category/aws/) - [azure](https://argos-security.io/category/azure/) - [entraid](https://argos-security.io/category/entraid/) - [cloud infrastructure pentests](https://argos-security.io/category/cloud-infrastructure-pentests/) ## Tags - [cspm](https://argos-security.io/tag/cspm/) - [devsecops](https://argos-security.io/tag/devsecops/) - [startup](https://argos-security.io/tag/startup/) - [cloud security](https://argos-security.io/tag/cloud-security/) - [chaosdb](https://argos-security.io/tag/chaosdb/) - [azure](https://argos-security.io/tag/azure/) - [vulnerability](https://argos-security.io/tag/vulnerability/) - [cosmosDB](https://argos-security.io/tag/cosmosdb/) - [aws](https://argos-security.io/tag/aws/) - [s3](https://argos-security.io/tag/s3/) - [aws s3](https://argos-security.io/tag/aws-s3/) - [cloud](https://argos-security.io/tag/cloud/) - [security](https://argos-security.io/tag/security/) - [omigod](https://argos-security.io/tag/omigod/) - [aws lambda](https://argos-security.io/tag/aws-lambda/) - [serverless](https://argos-security.io/tag/serverless/) - [dns](https://argos-security.io/tag/dns/) - [report](https://argos-security.io/tag/report/) - [siem](https://argos-security.io/tag/siem/) - [azure sentinel](https://argos-security.io/tag/azure-sentinel/) - [microsoft sentinel](https://argos-security.io/tag/microsoft-sentinel/) - [conditional access](https://argos-security.io/tag/conditional-access/) - [azure active directory](https://argos-security.io/tag/azure-active-directory/) - [iam](https://argos-security.io/tag/iam/) - [iam role](https://argos-security.io/tag/iam-role/) - [cybersecurity](https://argos-security.io/tag/cybersecurity/) - [ciem](https://argos-security.io/tag/ciem/) - [cnapp](https://argos-security.io/tag/cnapp/) - [cwpp](https://argos-security.io/tag/cwpp/) - [casm](https://argos-security.io/tag/casm/) - [gartner](https://argos-security.io/tag/gartner/) - [gcp](https://argos-security.io/tag/gcp/) - [authentication](https://argos-security.io/tag/authentication/) - [azure ad](https://argos-security.io/tag/azure-ad/) - [mfa](https://argos-security.io/tag/mfa/) - [compliance](https://argos-security.io/tag/compliance/) - [msp](https://argos-security.io/tag/msp/) - [mssp](https://argos-security.io/tag/mssp/) - [sql server](https://argos-security.io/tag/sql-server/) - [network](https://argos-security.io/tag/network/) - [entraid](https://argos-security.io/tag/entraid/) - [m365](https://argos-security.io/tag/m365/) - [powershell](https://argos-security.io/tag/powershell/) - [pentests](https://argos-security.io/tag/pentests/) - [attack paths](https://argos-security.io/tag/attack-paths/)