Hardening Library

Security research, tutorials, and product updates from the Retrievy team

Multi-cloud security, FortiGate hardening, AD/identity risk, and configuration drift. Written by operators for operators.

15 articles match
of 34 total
Is My Firewall Actually Inspecting Traffic, or Just Pretending To?
Articles
12 min read

Is My Firewall Actually Inspecting Traffic, or Just Pretending To?

Most firewalls show four green UTM profile indicators on outbound policies while the SSL/SSH Inspection field is set to `certificate-inspection`. Meaning those engines receive no decrypted traffic and are effectively blind to nearly all modern HTTPS sessions.

N
Ney Gelbcke Junior
Read Now
Active Directory Security Groups: What Operators Need to Know
Articles
4 min read

Active Directory Security Groups: What Operators Need to Know

Security groups are the primary access-control primitive in Active Directory, and misconfigured membership is one of the most reliable paths to privilege escalation. Here is what operators need to audit right now.

R
Retrievy Team
Read Now
Domain Controller Hardening: The Seven Settings That Matter Most
Articles
4 min read

Domain Controller Hardening: The Seven Settings That Matter Most

A quarterly DC review checklist covering LDAP signing, channel binding, SMB signing, SMB v1, NTLM auditing, restricted RPC, and DCSync delegation hygiene. Each item shows what bad looks like, what good looks like, and why it matters.

R
Retrievy Team
Read Now