The Onam blog
New findings, deep dives on cloud attacks, and product updates from the Onam team.
Onam vs. Wiz vs. Orca vs. Prisma Cloud: how to actually evaluate a cloud security platform
Wiz, Orca Security, and Prisma Cloud dominate every CSPM shortlist. Here are the seven questions that actually separate platforms — with Onam's answers on the record, and a checklist to run against every vendor on your list.
Beyond GuardDuty: how three-tier behavioral detection catches what rules miss
Rule-based detection catches known attack signatures. Statistical behavioral baselines catch incremental privilege escalation. ML anomaly detection catches the rest. Here's why you need all three.
The 5 AWS misconfigurations we find in 90% of first scans
After thousands of first-time AWS scans, the same five misconfigurations show up in nearly every environment. Here's what they are — and how to fix them fast.
CIEM vs IAM Security: what's actually the difference?
They sound identical. They aren't. Here's the practical split between IAM Security and Cloud Infrastructure Entitlement Management — and why you need both.
AI-powered cloud remediation: from finding to fix in minutes
The average MTTR for cloud security findings is 47 days. AI-powered remediation — context-aware code fixes, Ansible playbooks for CVEs, and threat narratives — is how we close that gap.
Attack paths vs. misconfigurations: why toxic combinations are your real cloud risk
Most CSPM tools surface hundreds of misconfigurations. The ones that actually lead to breaches are the ones that chain together — and most tools can't show you which chains are dangerous.
The FAIR model for cloud security: putting a dollar value on your attack surface
CVSS scores rank vulnerability severity. FAIR answers the question your board actually cares about: what does this attack surface cost if it's breached? Here's how we apply it at Onam.
Kubernetes RBAC pitfalls that grant cluster-admin by accident
A ClusterRoleBinding here, an aggregated role there — and suddenly your read-only role can create pods that mount the host filesystem. Six patterns to audit today.
EPSS over CVSS: prioritising the CVEs attackers actually exploit
CVSS tells you how bad a vulnerability could be. EPSS tells you how likely it is to be exploited in the next 30 days. Guess which one predicts breaches.
Why 90% of cloud IAM permissions are never used — and why that matters
Your IAM policies are accumulating unused permissions faster than your team can audit them. Here's what the data shows and how to close the gap.
MITRE ATT&CK for Cloud: mapping real attacks to your posture score
How MITRE ATT&CK for Cloud translates abstract threat techniques into concrete cloud misconfigurations — and how your posture score tracks each one.
How we check thousands of rules without agents: the architecture behind Onam
A technical deep-dive into how Onam scans dozens of cloud services across 7 clouds using only read-only access — no agents, no network changes, no configuration drift.