<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Zenzora</title><description>Cloud infrastructure, security, and DevOps writing from Jake Berkowsky.</description><link>https://zenzora.com/</link><item><title>Log-to-Action</title><link>https://zenzora.com/2026/01/log-to-action/</link><guid isPermaLink="true">https://zenzora.com/2026/01/log-to-action/</guid><description>On-Demand Anomaly Analytics with Snowflake Cortex and Word2Vec A few weeks back, a customer came to me with an interesting problem. They, like many customers, had a massive amount...</description><pubDate>Mon, 05 Jan 2026 22:02:46 GMT</pubDate></item><item><title>Securing Remote MCP Servers</title><link>https://zenzora.com/2025/07/securing-remote-mcp-servers/</link><guid isPermaLink="true">https://zenzora.com/2025/07/securing-remote-mcp-servers/</guid><description>This week, I had the pleasure of speaking at FWD:Cloudsec about securing remote MCP servers. As I normally speak about security data analytics, it was a welcome break to research a...</description><pubDate>Wed, 02 Jul 2025 18:50:52 GMT</pubDate></item><item><title>Snowflake Agents for Cybersecurity</title><link>https://zenzora.com/2025/06/snowflake-agents-for-cybersecurity/</link><guid isPermaLink="true">https://zenzora.com/2025/06/snowflake-agents-for-cybersecurity/</guid><description>I often run a Capture The Flag (CTF) session for customers of Snowflake. I provide a dataset with access logs, vulnerability data, Jira tickets, and cloud audit logs. We work toget...</description><pubDate>Mon, 16 Jun 2025 19:54:49 GMT</pubDate></item><item><title>Building a Threat Intelligence Agent with Snowflake and Streamlit</title><link>https://zenzora.com/2025/04/building-a-threat-intelligence-agent-with-snowflake-and-streamlit/</link><guid isPermaLink="true">https://zenzora.com/2025/04/building-a-threat-intelligence-agent-with-snowflake-and-streamlit/</guid><description>Last week, Google announced Sec-Gemini , a large language model (LLM) specifically designed to tackle cybersecurity challenges. Among the highlights of their announcement was the i...</description><pubDate>Tue, 08 Apr 2025 20:01:46 GMT</pubDate></item><item><title>Small Coffee Social</title><link>https://zenzora.com/2025/04/small-coffee-social/</link><guid isPermaLink="true">https://zenzora.com/2025/04/small-coffee-social/</guid><description>A social network for bots Tldr ; I wrote a social network for bots view the current iteration here: https://smallcoffee.social Over the holidays I had a dream about a social networ...</description><pubDate>Wed, 02 Apr 2025 17:16:41 GMT</pubDate></item><item><title>Should You Own Security Ingestion Pipelines?</title><link>https://zenzora.com/2025/03/should-you-own-security-ingestion-pipelines/</link><guid isPermaLink="true">https://zenzora.com/2025/03/should-you-own-security-ingestion-pipelines/</guid><description>Tradeoffs in security data lakes The idea of using a security data lake to power your threat detection workloads is nothing new. Since the launch of Snowflake’s AI Data Cloud for C...</description><pubDate>Mon, 24 Mar 2025 18:46:21 GMT</pubDate></item><item><title>Snowflake Siem Integration Architectures</title><link>https://zenzora.com/2025/02/snowflake-siem-integration-architectures/</link><guid isPermaLink="true">https://zenzora.com/2025/02/snowflake-siem-integration-architectures/</guid><description>For IT and Security teams tasked with monitoring Snowflake, integration with a SIEM or other centralized monitoring solution is critical. This article goes over which logs are typi...</description><pubDate>Tue, 18 Feb 2025 15:16:17 GMT</pubDate></item><item><title>A guide to reporting on developer security with Snyk and Snowflake</title><link>https://zenzora.com/2024/09/a-guide-to-reporting-on-developer-security-with-snyk-and-snowflake/</link><guid isPermaLink="true">https://zenzora.com/2024/09/a-guide-to-reporting-on-developer-security-with-snyk-and-snowflake/</guid><description>Everyone wants to shift left to stop vulnerabilities as early in the process as possible. This makes sense, a bug (security or otherwise) stopped before it’s even deployed is not o...</description><pubDate>Thu, 12 Sep 2024 14:01:44 GMT</pubDate></item><item><title>Implementing Schema Search on Snowflake</title><link>https://zenzora.com/2024/08/implementing-schema-search-on-snowflake/</link><guid isPermaLink="true">https://zenzora.com/2024/08/implementing-schema-search-on-snowflake/</guid><description>How to search multiple log sources at once Security and observability data lakes have allowed customers to have access to more data than ever before and have given them the tools t...</description><pubDate>Tue, 13 Aug 2024 14:07:21 GMT</pubDate></item><item><title>Normalization in Security Data Lakes</title><link>https://zenzora.com/2024/08/normalization-in-security-data-lakes/</link><guid isPermaLink="true">https://zenzora.com/2024/08/normalization-in-security-data-lakes/</guid><description>Early this summer I had the opportunity to present at my favorite conference, FWD:Cloudsec. I presented on the specific topic of data normalization for security data lakes. The con...</description><pubDate>Tue, 06 Aug 2024 16:17:48 GMT</pubDate></item><item><title>Security Analytics with Wiz and Snowflake</title><link>https://zenzora.com/2024/02/security-analytics-with-wiz-and-snowflake/</link><guid isPermaLink="true">https://zenzora.com/2024/02/security-analytics-with-wiz-and-snowflake/</guid><description>If you’re looking for a high value, low effort way to boost your security program, analytics on cloud risk data is a fantastic contender. If you have Snowflake and you use Wiz then...</description><pubDate>Wed, 07 Feb 2024 12:00:00 GMT</pubDate></item><item><title>Security Data Lakes, Normalization and OCSF</title><link>https://zenzora.com/2024/01/security-data-lakes-normalization-and-ocsf/</link><guid isPermaLink="true">https://zenzora.com/2024/01/security-data-lakes-normalization-and-ocsf/</guid><description>As Snowflake’s Cybersecurity Field CTO, I get asked fairly frequently around my thoughts on the Open Cybersecurity Schema Framework (OCSF) and about normalization in general. The f...</description><pubDate>Thu, 04 Jan 2024 12:00:00 GMT</pubDate></item><item><title>Navigating the Journey from SPL to SQL</title><link>https://zenzora.com/2023/11/navigating-the-journey-from-spl-to-sql/</link><guid isPermaLink="true">https://zenzora.com/2023/11/navigating-the-journey-from-spl-to-sql/</guid><description>As the field of security data engineering continues to evolve, workloads that once lived in the siem are being migrated to or augmented with a security data lake. Often time this m...</description><pubDate>Mon, 27 Nov 2023 12:00:00 GMT</pubDate></item><item><title>9 ways to give access to an internal tool</title><link>https://zenzora.com/2022/11/9-ways-to-give-access-to-an-internal-tool/</link><guid isPermaLink="true">https://zenzora.com/2022/11/9-ways-to-give-access-to-an-internal-tool/</guid><description>The following is a work of fiction. However all the solutions are real things I&apos;ve attempted in my time as a Cloud Consultant. Image this, you&apos;re minding your own business when an...</description><pubDate>Fri, 25 Nov 2022 08:15:40 GMT</pubDate></item><item><title>Tips for managing a team&apos;s stress</title><link>https://zenzora.com/2022/05/tips-for-managing-a-teams-stress/</link><guid isPermaLink="true">https://zenzora.com/2022/05/tips-for-managing-a-teams-stress/</guid><description>As a leader, it can be tempting to push your team to get the most out of them and to get results. People don&apos;t like like saying no and often just want to be helpful and give it the...</description><pubDate>Sun, 15 May 2022 03:40:06 GMT</pubDate></item><item><title>A response to &quot;Thinking About the Future of InfoSec&quot;</title><link>https://zenzora.com/2022/04/a-response-to-thinking-about-the-future-of-infosec/</link><guid isPermaLink="true">https://zenzora.com/2022/04/a-response-to-thinking-about-the-future-of-infosec/</guid><description>I recently read an article by Daniel Miessler about his predictions for the future of cybersecurity. He talks about changes to organizations, the market and the day to day of cybersecurity professionals. I decided to write down some of my thoughts in response.</description><pubDate>Tue, 12 Apr 2022 02:55:44 GMT</pubDate></item><item><title>WordPress on AWS, begrudgingly</title><link>https://zenzora.com/2022/04/wordpress-on-aws-begrudgingly/</link><guid isPermaLink="true">https://zenzora.com/2022/04/wordpress-on-aws-begrudgingly/</guid><description>Don&apos;t do it, but if you must then read this first</description><pubDate>Fri, 01 Apr 2022 20:02:25 GMT</pubDate></item><item><title>Helping engineers make better estimates</title><link>https://zenzora.com/2022/03/helping-engineers-make-better-estimates/</link><guid isPermaLink="true">https://zenzora.com/2022/03/helping-engineers-make-better-estimates/</guid><description>One insight that I&apos;ve found pretty ubiquitous in my career is that engineers hate being made to provide estimates on things. Still, in my role selling consulting engagements and pr...</description><pubDate>Mon, 28 Mar 2022 22:25:57 GMT</pubDate></item><item><title>Setting up Github Actions with AWS using CloudFormation</title><link>https://zenzora.com/2022/01/setting-up-github-actions-with-aws-using-cloudformation/</link><guid isPermaLink="true">https://zenzora.com/2022/01/setting-up-github-actions-with-aws-using-cloudformation/</guid><description>I recently helped a client migrate their Devops Pipelines to Github Actions. One of the nice features about GH is that its relatively easy to setup and use an identity provider tha...</description><pubDate>Wed, 26 Jan 2022 02:21:50 GMT</pubDate></item><item><title>Critiquing cloud lockin</title><link>https://zenzora.com/2021/03/critiquing-cloud-lockin/</link><guid isPermaLink="true">https://zenzora.com/2021/03/critiquing-cloud-lockin/</guid><description>I hear a lot of talk about cloud lockin. I hear it from people with self funded startups, authors on tech blogs and developers. The argument I hear most is that if you start using...</description><pubDate>Sat, 06 Mar 2021 05:23:17 GMT</pubDate></item><item><title>Calling the brute(force) squad</title><link>https://zenzora.com/2020/11/brute-force-squad/</link><guid isPermaLink="true">https://zenzora.com/2020/11/brute-force-squad/</guid><description>I got this picture in my family chat recently with a the question &quot;is this correct?&quot; The short answer is &quot;kinda&quot;. The long answer is this blog post :) What is Brute Forcing Put sim...</description><pubDate>Mon, 02 Nov 2020 21:11:33 GMT</pubDate></item><item><title>Network security concepts in school safety plans</title><link>https://zenzora.com/2020/08/network-security-concepts-in-school-safety-plans/</link><guid isPermaLink="true">https://zenzora.com/2020/08/network-security-concepts-in-school-safety-plans/</guid><description>As summer nears its end, there&apos;s a lot of discussion about how and when to reopen schools and universities. As a security professional, I can&apos;t help but see the parallels between p...</description><pubDate>Tue, 18 Aug 2020 19:28:05 GMT</pubDate></item><item><title>Security doesn&apos;t have to be a blocker</title><link>https://zenzora.com/2020/07/security-nonblockers/</link><guid isPermaLink="true">https://zenzora.com/2020/07/security-nonblockers/</guid><description>A few months ago during a conversation at a secops event, the topic of granting exceptions came up. One of the attendees was shared his dismay. &quot;Management is always steamrolling m...</description><pubDate>Fri, 31 Jul 2020 19:53:46 GMT</pubDate></item><item><title>SIGRed: A new critical vulnerability Explained</title><link>https://zenzora.com/2020/07/sigred-a-new-critical-vulnerability/</link><guid isPermaLink="true">https://zenzora.com/2020/07/sigred-a-new-critical-vulnerability/</guid><description>Last Tuesday, as they do every second Tuesday, Microsoft released its monthly patch updates. One in particular (CVE-2020-1350) has been drawing a lot of attention. The vulnerabilit...</description><pubDate>Tue, 21 Jul 2020 21:55:15 GMT</pubDate></item><item><title>ThiefQuest: The new macOS ransomware that&apos;s more than it seems</title><link>https://zenzora.com/2020/07/thiefquest-the-new-macos-ransomware-thats-more-than-it-seems/</link><guid isPermaLink="true">https://zenzora.com/2020/07/thiefquest-the-new-macos-ransomware-thats-more-than-it-seems/</guid><description>Last week a new macOS malware threat was discovered. Mac ransomware, while not unheard of, is still interesting enough to be of interest to security researchers. So, when Dinesh De...</description><pubDate>Fri, 10 Jul 2020 01:40:40 GMT</pubDate></item><item><title>A Threat Overview of Contact Tracing technology</title><link>https://zenzora.com/2020/06/contact-tracing/</link><guid isPermaLink="true">https://zenzora.com/2020/06/contact-tracing/</guid><description>This past year, as the Covid-19 virus began to spread so did the efforts to digitize the contact tracing process. As fast as the virus grew, so did the number of technical efforts...</description><pubDate>Mon, 22 Jun 2020 19:31:47 GMT</pubDate></item><item><title>Cleaning up users in 1password</title><link>https://zenzora.com/2020/06/cleaning-up-users-in-1password/</link><guid isPermaLink="true">https://zenzora.com/2020/06/cleaning-up-users-in-1password/</guid><description>Recently I was helping a company audit their 1password account. Thought I&apos;d share some useful snippets using jq and the 1password CLI tool . This command suspends users who haven&apos;t...</description><pubDate>Wed, 10 Jun 2020 18:48:46 GMT</pubDate></item><item><title>Shifting left with vulnerability management</title><link>https://zenzora.com/2020/05/shifting-left-with-vulnerability-management/</link><guid isPermaLink="true">https://zenzora.com/2020/05/shifting-left-with-vulnerability-management/</guid><description>Recently a friend of mine told me his company, in an effort to improve security, was launching a bug bounty program. I’m a huge fan of bug bounty programs, hiring professionals to...</description><pubDate>Sun, 31 May 2020 22:04:35 GMT</pubDate></item><item><title>Maturity in devops</title><link>https://zenzora.com/2020/05/maturity-in-devops/</link><guid isPermaLink="true">https://zenzora.com/2020/05/maturity-in-devops/</guid><description>As a consultant, I tend to work with a variety of clients and teams all across the product maturity spectrum. Some are just starting; maybe they have an MVP, maybe they are still b...</description><pubDate>Sun, 31 May 2020 22:01:26 GMT</pubDate></item><item><title>Trying Pritunl Zero</title><link>https://zenzora.com/2020/05/trying-pritunl-zero/</link><guid isPermaLink="true">https://zenzora.com/2020/05/trying-pritunl-zero/</guid><description>Pritunl is an open source OpenVPN and IPSec solution that comes with a somewhat popular VPN client. Pritunl Zero fills in a few more gaps by providing zero trust access to SSH and...</description><pubDate>Sun, 31 May 2020 21:59:38 GMT</pubDate></item></channel></rss>