ã¯ããã«
é²ååç»ã®é³è³ªãæªãã£ãã®ã§ããã¹ãçãäœæããŸãããç®æ¬¡ã«èšèŒããŠããåé ç®ã®æé垯ã¯ç®å®ã§ãã
èªå·±çŽ¹ä» 1:25ã2:23
åç»ã«ãŠèªåã®çµæŽãç°¡åã«èšèŒããã¹ã©ã€ããåããŠãŸãã®ã§ããã¡ããåç §ãã ããã
ã¢ãžã§ã³ã 2:24ã3:14
- æšä»ã®ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã®ç¶æ³ãšããããã«ã«ã€ããŠ
- AWSã®äž»èŠãªã»ãã¥ãªãã£ãµãŒãã¹ã«ã€ããŠ
- AWS Configã«ãŒã«ã䜿ã£ãŠã¿ã
- çµããã«
æ¬æ¥ã®ãŽãŒã« 3:15ã5:20
- IPAãã¬ãŒãããŒãå ¬éããŠããè³æã®æ å ±ããæšä»ã©ã®ãããªã»ãã¥ãªãã£ã€ã³ã·ãã³ããèµ·ããŠããã®ããä»åŸã©ã®ããã«ãªã£ãŠããã®ãã倧ãŸããªåŸåãçè§£ããã
- ããã«å©çšã§ããAWSã®äž»èŠãªã»ãã¥ãªãã£ãµãŒãã¹ãæç²ãè§£èª¬ãæŠèŠãææ¡ããã
- AWS Configã«ã€ããŠã¯æ·±æãããã«ãŒã«æ©èœãProactiveã¢ãŒããDetectiveã¢ãŒããDetectiveã¢ãŒãã®èªå修埩æ©èœã«ã€ããŠæŠèŠãææ¡ããã
å眮ãïŒä»åã®å 容ã¯2024幎ã®1ææç¹ãŸã§ã®æ å ±ãããšã«äœæããŠããŸãã
æ¬é¡ 5:21ã35:27
1.æšä»ã®ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã®ç¶æ³ãšãããã 5:21ã10:02
çŽè¿ã®ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã®ç¶æ³ãææ¡ããã«ããããäžèšIPAã®è³æãåç §ããã
- äžæ£ã¢ã¯ã»ã¹ã®å±åºä»¶æ°
- 2020å¹Žã«æ¥å¢ãã21幎ã¯ããã«äžããã22幎ã¯äžãã£ããã®ã®ã20幎ãè¶ ããæ°Žæºãšãªã£ãŠããã
- äžæ£ã¢ã¯ã»ã¹ã®åå ä»¶æ°
- 2022幎ãæãå€ãã®ãå€ãããŒãžã§ã³ã®å©çšãä¿®æ£ããã°ã©ã ã»å¿ èŠãªãã©ã°ã€ã³çã®æªå°å ¥ã2020幎æç¹ã§ã¯æ¬¡ç¹ã ã£ããã21幎ã22幎ã«ããä»¶æ°ãæ¥å¢ããã
- 2çªç®ã«å€ãã®ããèšå®ã®äžåã(ã»ãã¥ãªãã£äžåé¡ã®ããããã©ã«ãèšå®ãå«ã)
- 3çªç®ãIDããã¹ã¯ãŒã管çã®äžåã
ç¶ããŠã¯ã¬ãŒãããŒãå ¬éããŠããIs the Cloud Secureãšããè³æãåç §ããããã®è³æã®äžãããç§ãæ°ã«ãªã£ãç®æãããã€ãæç²ããç§ã®è§£éããŒã¹ã§æ¥æ¬èªã«èŠçŽããŠããã
Is the Cloud Secure? Gartner October 10, 2019 Contributor: Kasey Panetta
- ã»ãã¥ãªãã£ã«é¢ããçŸç¶ã®åŸåãå°æ¥çãªäºæž¬ã«ã€ããŠ
- 2025幎ã«ããèµ·ãããäºè±¡ãšããŠããããªãã¯ã¯ã©ãŠããå©çšããã«ããããã©ã®ããã«ç°å¢ãå©çšããããå©çšæŠç¥ãç«ãŠãã«ãããªãã¯ã¯ã©ãŠããå©çšãããšãã»ã³ã·ãã£ããªããŒã¿ãå€ã«å ¬éããŠããŸããããªãªã¹ã¯ãã€ã³ã·ãã³ããèµ·ãããããªãã
- 2024幎ã«ãããå ã ãããªãã¯ã¯ã©ãŠããå©çšããã«ããããªã¹ã¯ãé倧è©äŸ¡ããåŸåã«ãã£ãããã ããé転çŸè±¡ãèµ·ããŠããããªã¹ã¯ãéå°è©äŸ¡ããæµããšãªãã
- 2025幎ã«ãããã¯ã©ãŠãäžã®ã€ã³ã·ãã³ãã®99%ã¯èšå®äžåã«ãã£ãŠçããã
ãããã®æ å ±ãç·åãããšãä»åŸãããªãã¯ã¯ã©ãŠããã¯ãããã¯ã©ãŠããµãŒãã¹ã掻çšããæµãã¯å éããŠããããšæãããããã ããã©ã®ããã«å©çšããããäŸãã°ãã©ã®ãŠãŒã¶ãŒã«ã©ã®æš©éãå²ãåœãŠãããå©çšæŠç¥ãæ£ããèšèšããŠããªããã°ãã»ãã¥ãªãã£ã€ã³ã·ãã³ããèµ·ãããããªãã
2.AWSã®äž»èŠãªã»ãã¥ãªãã£ãµãŒãã¹ã«ã€ã㊠10:03ã22:30
- 玹ä»ããŠãããµãŒãã¹
- CloudTrail
- IAMãŠãŒã¶ãŒãããŒã«ãAWSã®ãµãŒãã¹ã«ãã£ãŠå®è¡ãããã¢ã¯ã·ã§ã³ãèšé²ãããããã€ãã誰ããããã©ã®AWSãµãŒãã¹ããªãœãŒã¹ã«ããã©ã®ãããªæäœãè¡ãªã£ãããAPIæäœã®ã€ãã³ããã°ãèšé²ããŠãããã€ãã³ããã°ã¯ã管çã€ãã³ããããããŒã¿ã€ãã³ããããã€ã³ãµã€ãã€ãã³ããã®3çš®é¡ã
- 䜿çšäŸã¯äœãããã®AWSãªãœãŒã¹ãèšå®å€æŽãããŠããå Žåããã®ãªãœãŒã¹ãã©ã®IAMãŠãŒã¶ãŒã«ãããã©ã®APIãå®è¡ãããã®ããç¹å®èª¿æ»ããããå Žåã«äœ¿çšããããã®éã«ç¢ºèªãããã°ã管çã€ãã³ããšãªãã管çã€ãã³ãã¯ç¡æã§å©çšã§ããCloudTrailäžã§ã¯ææ°ã®90æ¥éåã®ãã°ãåç §ã§ããã
- ããŒã¿ã€ãã³ããšã€ã³ãµã€ãã€ãã³ãã«ã€ããŠããããã¯ãªãã·ã§ã³ãšãªãã
- ããŒã¿ã€ãã³ãã¯èšé²å¯Ÿè±¡ãAWSãªãœãŒã¹å ã®ããŒã¿æäœã«ç¹åããæ©èœãšãªããäŸãã°S3ã®ç¹å®ã®ãã±ããã«å¯Ÿããæžã蟌ã¿åŠçïŒPUTïŒã®APIã®ã¿èšé²ããšãããããªèšå®ãå¯èœã
- ã€ã³ãµã€ãã€ãã³ãã¯ããã®AWSã¢ã«ãŠã³ãäžã§æ®æ®µå®è¡ãããŠããªãAPIãAPIãšã©ãŒçãåæããäžå¯©ãªã¢ã¯ãã£ããã£ãæ€åºããæ©èœãšãªããäžå¯©ãªã¢ã¯ãã£ããã£ãããªã¬ãŒã«EventBridgeã皌åãããéç¥ãéãä»çµã¿ãäœãããšãå¯èœã
- IAMãŠãŒã¶ãŒãããŒã«ãAWSã®ãµãŒãã¹ã«ãã£ãŠå®è¡ãããã¢ã¯ã·ã§ã³ãèšé²ãããããã€ãã誰ããããã©ã®AWSãµãŒãã¹ããªãœãŒã¹ã«ããã©ã®ãããªæäœãè¡ãªã£ãããAPIæäœã®ã€ãã³ããã°ãèšé²ããŠãããã€ãã³ããã°ã¯ã管çã€ãã³ããããããŒã¿ã€ãã³ããããã€ã³ãµã€ãã€ãã³ããã®3çš®é¡ã
- IAM Access Analyzer
- 察象ãµãŒãã¹ã«ãããŠå€éšãšã¢ã¯ã»ã¹å¯èœç¶æ
ã®ãªãœãŒã¹ãæ€åºããã
- IAMããŒã«ãS3ãSQSãã¥ãŒãªã©å¯Ÿè±¡ãµãŒãã¹ã«ãããŠãIAM Access Analyzerãæå¹åããã¢ã«ãŠã³ããšã¯å¥ã®ã¢ã«ãŠã³ãã®ãããªå€éšã«å¯Ÿããèš±å¯ããªã·ãŒãæã£ãŠãããå€éšããã¢ã¯ã»ã¹ã§ããç¶æ ã«ãªã£ãŠãã察象ãµãŒãã¹ã®ãªãœãŒã¹ãæ€åºããã
- æ€åºãããªãœãŒã¹ã¯ãã¢ã¯ãã£ããããã¢ãŒã«ã€ãæžã¿ããã解決æžã¿ãã®3ã€ã«åé¡ãããããŸãã¢ã¯ãã£ãã«åºåãããåé¡ãªãå€éšã¢ã¯ã»ã¹å ã§ããã°ãã¢ãŒã«ã€ãæžã¿ã«ç§»ãã®ãåºæ¬çãªéçšãšãªããå€éšããã¢ã¯ã»ã¹ã§ããç¶æ ããããã®èšå®ãåé€ãèšå®å€æŽãããå Žåã解決æžã¿ã«åé¡ãããã
- ã¢ãŒã«ã€ãã«ãŒã«ãèšå®ããã°ãæå®æ¡ä»¶ã§èªåçã«ã¢ãŒã«ã€ãæžã¿ã«ç§»ãããšãå¯èœã
- ãã¢ã¯ãã£ãããæ€åºããéããããããªã¬ãŒã«EventBridgeã皌åãããéç¥ãéãä»çµã¿ãäœãããšãå¯èœã
- æªäœ¿çšã®IAMããŒã«ãã¢ã¯ã·ã§ã³ã®ç¢ºèªãã§ããæ©èœãããã
- ãæªäœ¿çšã®ã¢ã¯ã»ã¹åæããšããæ©èœãããããããå©çšãããšããã©ã«ãã ãš90æ¥éãæªäœ¿çšã®IAMããŒã«ãã¢ã¯ã·ã§ã³ã®äžèЧãåç §ã§ããã
- 察象ãµãŒãã¹ã«ãããŠå€éšãšã¢ã¯ã»ã¹å¯èœç¶æ
ã®ãªãœãŒã¹ãæ€åºããã
- GuardDuty
- DNSã¯ãšãªãã°ãªã©ã®ããŒã¿ãœãŒã¹ãå ã«æªæããã¢ã¯ãã£ããã£ããªããã確èªããæ€åºçµæãæäŸããè åšæ€åºãµãŒãã¹ã
- EC2ãIAMãS3ãªã©ãè åšæ€åºç¢ºèªå¯Ÿè±¡ã§ãæ€åºããè åšã¯ãHIGHãããMEDIUMãããLOWãã«åé¡ãããã
- GuardDutyã¯ããã©ã«ãã§ã¯ãªãç¶æ ããªã³ã«ãããšãDNSã®ã¯ãšãªãã°ãCloudTrailãVPCãããŒãã°ãªã©ãæ å ±æºã«ç°åžžãªã¢ã¯ãã£ããã£ãæ€åºããã
- ç°åžžãªã¢ã¯ãã£ããã£ãšããŠæ€åºãããã¯GuardDutyã«ãŠå®çŸ©ãããŠãããäŸãã°EC2ã€ã³ã¹ã¿ã³ã¹ãæå·é貚é¢é£ã®IPã¢ãã¬ã¹ããã¡ã€ã³ãã¯ãšãªãããã€ãã³ã°ã«æŽ»çšãããŠããå¯èœæ§ããã£ãå Žåãããã¯è åšå€å®ãHIGHããšããŠæ€åºããã
- ãHIGHãã®è åšãæ€ç¥ããéããããããªã¬ãŒã«EventBridgeã皌åãããéç¥ãéãä»çµã¿ãäœãããšãå¯èœã
- Amazon Detective
- ã»ãã¥ãªãã£ã«é¢ããæ€åºçµæãçãããã¢ã¯ãã£ããã£ã®åå åæã調æ»ã«å©çšããã
- CloudTrailãVPCãããŒãã°ãGuardDutyã®ããŒã¿ãåéããæ©æ¢°åŠç¿ (ML)ãçµ±èšåæãã°ã©ãçè«ã掻çšãã»ãã¥ãªãã£èª¿æ»ã®èŠèŠåãå®çŸããã
- GuardDutyã§ã¯çºçããã€ãã³ãããŒã¹ã§äºè±¡ãèªç¥ã調æ»ãã圢ãšãªãããDetectiveãæå¹åããŠããã°ãæç³»åããŒã¿ãã°ã©ãã§è¡šç€ºã§ããç¹ã§èŠãŠããäºè±¡ãç·ã§ææ¡ã§ããããã«ãªãã
- GuardDutyãæå¹åãã48æéçµéããŠããªããã°æå¹åã§ããªãã
- Security Hub
- AWS Configããããããæå¹åããŠããå¿
èŠãããã
- AWSç°å¢ãã»ãã¥ãªãã£èгç¹ã§å
æ¬çã«ææ¡ã§ãããµãŒãã¹ã
- ã»ãã¥ãªãã£ç³»ãµãŒãã¹ïŒex.GuardDutyïŒã®æ€åºçµæãçµ±åã§ããã
- ã»ãã¥ãªãã£æšæºãæ°çš®é¡çšæãããŠãããæå®ããã»ãã¥ãªãã£æšæºãæºãã圢ã§ãªãœãŒã¹ãèšå®ãããŠããããã»ãã¥ãªãã£ã¹ã³ã¢ãšããŠçµæãå®éçã«èªèããããšãã§ããã
- æå®ããã»ãã¥ãªãã£æšæºã«ãããŠãã©ããã©ã®åºæºã§éåããŠããããèŠãããšãã§ããã
- ãã³ãã€ã³ãã§å©çšãããã»ãã¥ãªãã£æšæºããªããã°ãAWS Foundational Security Best PracticeïŒAWSåºç€ã»ãã¥ãªãã£ã®ãã¹ããã©ã¯ãã£ã¹ïŒã®å©çšãæšå¥šããã
- AWS Foundational Security Best PracticeïŒAWSåºç€ã»ãã¥ãªãã£ã®ãã¹ããã©ã¯ãã£ã¹ïŒã¯AWSã®ã»ãã¥ãªãã£å°éå®¶ãäœæããŠãããé©å®ã¢ããããŒããæœãããã
- AWSç°å¢ãã»ãã¥ãªãã£èгç¹ã§å
æ¬çã«ææ¡ã§ãããµãŒãã¹ã
- AWS Configããããããæå¹åããŠããå¿
èŠãããã
- AWS Config
- AWSãªãœãŒã¹ã®å€æŽç¶æ³ã管çã§ãã倿Žå±¥æŽã確èªã§ãããµãŒãã¹ã
- Configã«ãŒã«ãå©çšããã°ããã®ã«ãŒã«ã®ç¶æ
ããä¹é¢ããŠãããªãœãŒã¹ãéæºæ ç¶æ
ãšããŠäžèЧåã§ããã
- äžèЧåããã ãã§ãªããéæºæ ç¶æ ããæºæ ç¶æ ã«æ»ãããã®æ©èœãä»åž¯ããŠããã
- Configã«ãŒã«ã«ã¯ProactiveãšDetectiveã®è©äŸ¡ã¢ãŒããããã
- Proactiveã¯ãªãœãŒã¹ããããã€ãäœæããåã«Configã«ãŒã«ãé©çšããéã«äœ¿çšããã
- Detectiveã¯æ¢ã«ãããã€ãäœæããããªãœãŒã¹ã«Configã«ãŒã«ãé©çšããéã«äœ¿çšããã
- CloudTrail
3.AWS Configã«ãŒã«ã䜿ã£ãŠã¿ã 22:31ã34:21
- ã«ãŒã«ã®çš®é¡
- ãããŒãžãã«ãŒã«
- ã©ã®ãããªè©äŸ¡ãè¡ãããAWSåŽã«ãŠå®çŸ©ãããŠããã«ãŒã«ã
- 300å以äžã®ã«ãŒã«ããããEC2ãS3ãIAMãRDSãELBçšã«äœæãããŠãããã®ãæ¯èŒçå€ãã
- ã«ã¹ã¿ã ã«ãŒã«
- å 容ãã®ãã®ãèªåã§èšå®ãããåºæ¬çã«ã¯Lambdaã§ã«ãŒã«ãäœæããã
- ããªã¬ãŒã¿ã€ãã«ã€ããŠ
- è©äŸ¡ã¢ãŒãDetectiveã«ãããŠãã©ã®ã¿ã€ãã³ã°ã§ã«ãŒã«ã®è©äŸ¡ãå®è¡ããããæ±ºããã®ãããªã¬ãŒã¿ã€ãã
- ããªã¬ãŒã¿ã€ãïŒèšå®å€æŽ
- ååã®éããèšå®å€æŽããã£ãå Žåããã®ãããŒãžãã«ãŒã«ã®ã¹ã³ãŒããšäžèŽãããªãœãŒã¹ã«å¯Ÿããã«ãŒã«ã®è©äŸ¡ãè¡ãããã察象ã¹ã³ãŒããçµãæ©èœããããäŸãã°æå®ã¿ã°ããã€ãªãœãŒã¹ã®ã¿ãè©äŸ¡å¯Ÿè±¡ãšãããããªèšå®ãå¯èœã
- ããªã¬ãŒã¿ã€ãïŒå®æç
- æå®ééã§è©äŸ¡ãå®è¡ããã
- ããªã¬ãŒã¿ã€ãïŒãã€ããªãã
- èšå®å€æŽãšå®æçã®äž¡æ¹ãæã€ã
- 泚æç¹ãšããŠãã¿ã°ã§å¶éãããŠããŠããã¹ã³ãŒããå¹ãã®ã¯èšå®å€æŽã®æã®ã¿ã§ã宿çã«ã¯ã¿ã°ã®ã¹ã³ãŒãã¯é©çšãããªãã
- è©äŸ¡ã¢ãŒãã«ã€ããŠ
- Proactiveã¢ãŒã
- åŸçºã§äœ¿ããããã«ãªã£ãæ©èœããªãœãŒã¹ããããã€ããåã«ã«ãŒã«ã®è©äŸ¡ãè¡ãããå Žåã«äœ¿çšããã
- çŸåšProactiveã¢ãŒãã§å©çšã§ãããããŒãžãã«ãŒã«ã¯ããã17åã
- çŸæç¹ã§ã¯ã³ã³ãœãŒã«ã§ã¯äœ¿çšã§ãããäœ¿çšæ¹æ³ã®äŸãšããŠã¯CLIã§APIãå®è¡ãããçºèŠççµ±å¶çã«æŽ»çšãããå ŽåãCI/CDã«ãããããã€ãå®è¡ããåã®ããã»ã¹ã«ããã®APIãèšå®ããã¹ã¯ãªãããå®è¡ããèšå®ãçµã¿èŸŒãæ¹æ³ãããã
- Proactiveã¢ãŒãã®äœ¿çšäŸã¯äžèšAWSã®ããã¥ã¡ã³ããåèãšãªãã
- Detectiveã¢ãŒã
- çºèŠççµ±å¶ç®çã«å©çšã§ããå©çšã§ãããããŒãžãã«ãŒã«ã¯300å以äžã
- ãªãœãŒã¹ãèšå®ãã«ãŒã«ã«éæºæ ç¶æ ãšãªã£ãéããããããªã¬ãŒã«ã¢ã¯ã·ã§ã³ã皌åããã修埩ã¢ã¯ã·ã§ã³æ©èœãããã
- Proactiveã¢ãŒã
- ãããŒãžãã«ãŒã«
ãããŒãžãã«ãŒã«ãšä¿®åŸ©ã¢ã¯ã·ã§ã³ã®èšå®äŸ 30:14ã34:21
䜿çšãããŒãžãã«ãŒã«ïŒguardduty-enabled-centralized
䜿çšä¿®åŸ©ã¢ã¯ã·ã§ã³ïŒAWSConfigRemediation-CreateGuardDutyDetector
æé ã³ã³ãœãŒã«ã§ã®èšå®æ¹æ³
- AWS Systems ManagerãªãŒãã¡ãŒã·ã§ã³çšIAMããŒã«ãšå®è¡ããããªãŒãã¡ãŒã·ã§ã³ã©ã³ããã¯ã®ã¢ã¯ã·ã§ã³ãæã€IAMããªã·ãŒãäœæããã
- ã«ãŒã«ãäœæããã
- äœæããã«ãŒã«ã®ç·šéã§ä¿®åŸ©ã¢ã¯ã·ã§ã³ãèšå®ããã
æé ã®1ã«ã€ããŠãIAMããŒã«ãšIAMããªã·ãŒãçšæããã
- IAMããŒã«
- ssm.amazonaws.comã®ä¿¡é Œããªã·ãŒãèšå®ãããäœæããããarnã¯æ§ããŠããã
- IAMããªã·ãŒ
- äžèšã¢ã¯ã·ã§ã³ãèšå®ããIAMããŒã«ã«ã¢ã¿ããããã
- ssm:StartAutomationExecution
- ssm:GetAutomationExecution
- guardduty:CreateDetector
- guardduty:GetDetector
- 修埩ã¢ã¯ã·ã§ã³ã«å¿ èŠãªèš±å¯èšå®æ å ±ã¯AWSããã¥ã¡ã³ãã®å修埩ã¢ã¯ã·ã§ã³ïŒäŸïŒAWSConfigRemediation-CreateGuardDutyDetectorïŒã®å¿ èŠãª IAM ã¢ã¯ã»ã¹èš±å¯ã«èšèŒãããã
- äžèšã¢ã¯ã·ã§ã³ãèšå®ããIAMããŒã«ã«ã¢ã¿ããããã
æé ã®2ã«ã€ããŠãã«ãŒã«ãäœæããã
- ãããŒãžãã«ãŒã«ãéžæããäžèЧã®äžããguardduty-enabled-centralizedãéžæãã圢ã§ã«ãŒã«ãäœæããã
æé ã®3ã«ã€ããŠãäœæããã«ãŒã«ã®ç·šéã§ä¿®åŸ©ã¢ã¯ã·ã§ã³ãèšå®ããã
- äœæããã«ãŒã«ã®ã¢ã¯ã·ã§ã³ãã¿ã³ããã修埩ã®ç®¡çãéžæãã修埩ã¢ã¯ã·ã§ã³ãèšå®ããã
- 修埩ã¢ã¯ã·ã§ã³ã®èšå®ç®æã«ãŠAWSConfigRemediation-CreateGuardDutyDetectorããã«ããŠã³ããéžæãããã©ã¡ãŒã¿ã«ã¯æ§ããŠãããIAMããŒã«ã®ARNãå ¥åããã
ããã§èšå®ã¯å®äºãGuardDutyãç¡å¹åç¶æ ã®å Žåãéæºæ ç¶æ ãšã«ãŒã«ãè©äŸ¡ãããã®è©äŸ¡ãããªã¬ãŒã«ä¿®åŸ©ã¢ã¯ã·ã§ã³ãçºåãããã¡ãªã¿ã«ä¿®åŸ©ã¢ã¯ã·ã§ã³ã¯èªå皌åã§ãªããæå皌åãšããããšãå¯èœã
4.çµããã« 34:22ã35:27
æšä»ã®ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã®ç¶æ³ãšAWSã®ã»ãã¥ãªãã£ç³»ãµãŒãã¹ã«ã€ããŠèª¬æãããããä»åã®å
容ã¯AWS Well-Architectedã®ã»ãã¥ãªãã£ã®ãã¬ãŒã ã¯ãŒã¯ããšããããæ€åºãé
ç®ãèæ
®ããã«ããããå
šãŠæçšãªã®ã§ãå°å
¥ããããšãå§ããã
https://wa.aws.amazon.com/wellarchitected/2020-07-02T19-33-23/wat.pillar.security.ja.html#sec.detective