← Back to context

Comment by __s

4 days ago

There are companies like Helix Guard scanning registries. They advertise static analysis / LLM analysis, but honeypot instances can also install packages & detect certain files like cloud configs being accessed

But relying on the goodwill of commercial sec vendors is it's own infrastructure risk.

  • You can also pay a commercial sec vendor if you don't want to rely on their goodwill.