Skip to content

Infrastructure Documentation

ℹ️ The published site sidebar is generated from the filesystem and always complete; the curated tables below can lag. Auto-generated list of docs missing from these tables: Recently Added.

This repository contains operational and architectural documentation for the Cirius Group healthcare infrastructure environment. All infrastructure is managed as code using Terraform across Azure and AWS, with GitHub Actions CI/CD pipelines enforcing compliance and security scanning on every change.

Compliance scope: SOC2 · HIPAA · HITRUST


Environment Overview

EnvironmentPlatformRegionRepositoryPurpose
Primary productionAzureUS West 2azure-infraCore business workloads, identity, logging
Customer AVD (DDE)AzureUS West 2azure-dde-infraMedicare-facing published app, isolated tenant
Disaster recoveryAWSUS West 2aws-infra7-account org: DR workloads, Veeam targets

Azure Subscriptions (ciriusgroup.com, tenant d477c9f8)

SubscriptionKey Resources
ProductionVMs, storage, application workloads
DevelopmentDev VMs, test databases
IdentityEntra domain services VMs
FirewallPalo Alto VM-Series, hub VNet
LoggingLog Analytics (cirius-logging-law-central), Event Hub, archive storage, Defender
MainOIDC federation, Key Vault, Terraform state storage
Dashboarddashboard.ciriusgroup.com

Key People

PersonRoleResponsibilities
RorySole IT/Security EngineerAll infrastructure decisions, PR review authority, security operations
KevinT1 Domain AdminDR escalation, compliance reports
GregT1 Domain AdminDR escalation, compliance reports
AdrianaCompliance coordinatorBAA/vendor/risk documents, SharePoint uploads

Start Here — New Engineer Guide

If you are new to this environment, read these five documents first in order:

  1. Azure Infrastructure Overview — What Azure looks like: subscriptions, networking, security layers
  2. AWS DR Overview — The AWS disaster recovery environment: 7-account org, firewalls, failover design
  3. Security Monitoring Architecture — The 17-agent monitoring system, how incidents are created, the SecOps platform
  4. CI/CD Pipeline Overview — How every infrastructure change gets deployed
  5. Incident Response — What to do when something goes wrong

Then read Key Learnings — 289 lines of hard-won gotchas that will save you hours.

If you are working on the security monitoring agents (kill chain Phase 2, new detections), also read Agent Development Guide before writing any code.

If you are preparing for the SOC2 audit, start with SOC2 PBC Guide — it maps every auditor request to the exact evidence location.


Architecture & Design

Core design documents — authoritative references for how the infrastructure is structured.

DocumentDescription
Network TopologyIP ranges, subnet design, firewall placement, route design — authoritative network reference
Security Monitoring Architecture17-agent system, Container Apps Jobs, incident lifecycle, agent inventory, notification rules
Agent Development GuideHow to build, test, and deploy a new monitoring agent — output contract, KQL patterns, kill chain agent specs, deployment
Two-Firewall ArchitecturePublicFW/PrivateFW design principles and component overview
UDR Routing DesignUser-Defined Route strategy — forcing spoke-to-spoke traffic through Palo Alto NVA
Domain Consolidation — Current StateCurrent AD forests, DNS zones, registrar mapping
Domain Consolidation — Target StatePlanned identity consolidation design

CI/CD

All infrastructure changes flow through GitHub Actions with OIDC federated authentication — no stored credentials.

DocumentDescription
CI/CD Pipeline OverviewGitHub Actions pipeline stages, triggers, and authentication
OIDC AuthenticationOIDC federated identity for GitHub Actions — Azure/AWS trust configuration
Checkov HIPAA ScanningHIPAA compliance scanning in the pipeline, findings, and suppressions
ops-automation OverviewAll scheduled automation: HIPAA audit, cost report, pen testing, Maester, Cortex XDR, PIM audit, config backup
Monthly Cost ReportingCost report schedule, pipeline architecture, and how to read and act on the report

Azure

Primary production environment (ciriusgroup.com) and customer-facing DDE environment (ciriusdde.com).

DocumentDescription
Azure Infrastructure OverviewPrimary Azure environment — network topology, subscriptions, security layers
Azure Network TopologyHub-spoke network architecture, VNet peering, traffic flow
DDE Infrastructure OverviewCustomer-facing AVD environment in isolated Azure tenant (ciriusdde.com)
DDE Network TopologyDDE two-VNet topology, AD colocation design
CiriusSvcs VNet DependenciesLegacy CiriusSvcsVNET dependency map and H2 2026 decommission blockers
Domain Consolidation PlanActive identity consolidation project plan
WRKBIZAP01 Migration PlanPayer API server migration plan

AWS

Seven-account organization used for disaster recovery and services. Not primary production traffic.

Account Structure

AccountIDPurpose
Management206820231356Org root
Backup863609217450Veeam backup targets
Dev040067931468Development
Identity414134953818IAM and identity
Logging038901680748CloudTrail, S3 archive, syslog VM
Networking238342914131Palo Alto firewall infrastructure
Prod807267566999DR workloads, Cloud PC
DocumentDescription
AWS DR OverviewDR environment architecture, 7-account org, firewall/Panorama, MDR coverage
AWS Network TopologyTransit Gateway hub-spoke, VPC isolation model
DR Failover ProcedureStep-by-step Azure → AWS failover instructions
DR Failback ProcedureFailback procedure — placeholder, pending June 2026 DR test

Security

Firewall & Network Security

DocumentDescription
Palo Alto Firewall OverviewFirewall architecture, security zones, Panorama status, syslog infrastructure
Panorama Operations GuideDisk sizing, log forwarding, PAN-OS upgrade procedure, SCP workaround
Firewall Change Request ProcedureFormal change classification, approval, implementation, and documentation process
Palo Alto Config Backup & AuditAutomated config backup, log forwarding architecture, weekly security audit
Palo Alto Credential RotationBackup credential rotation procedure for all 4 firewalls
Firewall Rule ReferenceFirewall rule governance and operational change runbook
Network Segmentation — Communication MapAllowed inter-segment communication matrix
Network Segmentation — Proposed RulesProposed NSG/firewall rule changes

EDR, MDR & Endpoint

DocumentDescription
EDR — Cortex XDRCortex XDR coverage, MDE Passive Mode requirement, agent deployment
Arctic Wolf MDR — Scope Gap AnalysisMDR coverage gaps and remediation status
Patch ManagementPatch cadence, approval workflow, emergency patch procedure
Penetration TestingMonthly pen test scope, tools (Nuclei + Nmap), results interpretation
Velociraptor Architecture EvaluationDFIR tool evaluation for on-demand artifact collection
Vulnerability ManagementAutomated vulnerability notification system (Lambda, S3, SES)

Identity & Access Control

DocumentDescription
Three-Layer Access ArchitectureZTNA (Twingate) + Entra Conditional Access + Intune compliance — the full access model
DDE Privileged Access ReviewDDE tenant privileged access audit
DDE Subscription Security ControlsSecurity controls applied to the DDE Azure subscription
Least Privilege BaselinePrinciple of least privilege baseline across all systems
Least Privilege — ops-automationLeast privilege analysis for ops-automation agents
Least Privilege — SecOpsLeast privilege analysis for SecOps platform
Privileged Role Cleanup (PROD)Privileged role reduction in the production tenant
Credential ExceptionsDocumented exceptions to the no-long-lived-credentials policy
Unavoidable Long-Lived SecretsSecrets that cannot be rotated to managed identity — documented with compensating controls
Secrets & Managed Identity EvaluationDecision analysis for migrating service secrets to managed identity
Graph API Certificate Auth EvaluationEvaluation of certificate-based Graph API authentication

Email & DNS Security

DocumentDescription
DMARC Enforcement PlanDMARC policy progression to enforcement across both tenants
DNSSEC FeasibilityDNSSEC implementation feasibility analysis
CiriusSupport Email SecurityEmail security controls for the support address

Threat Model

DocumentDescription
Threat ModelLiving threat model — crown jewels, threat actors, STRIDE analysis, controls mapped to kill chain. Start here for security context.
Kill Chain CoveragePer-stage detection coverage map — what is detected, what has gaps
Crown Jewel InventoryFormal crown jewel asset list
Maester M365 Audit GuideMaester test categories, scoring interpretation, remediation priority
Maester M365 Security AuditWeekly Maester audit results and remediation tracks

Deception & Canary

DocumentDescription
Deception LayerCanary token and honeypot architecture — what is deployed and where
Canary Token InventoryActive canary tokens: names, locations, alert routing

CMDB & Inventory

DocumentDescription
CMDB GuideWhat is in the CMDB, how it is maintained, how agents use it
Terraform StandardsSecurity-layer Terraform coding standards

Runbooks

Incident Response & Security Operations

DocumentDescription
Incident ResponseStep-by-step response for ransomware, breaches, outages — incorporates November 2024 lessons
Alerting RunbookAlert sources, routing, severity levels, escalation paths
Out-of-Band Communications PlanHow to communicate when primary channels are compromised
Break-Glass ProcedureEmergency break-glass account activation for all 18 accounts — when to use, step-by-step per system
SecOps Platform GuideHow to use secops.bedrockcybersecurity.org — incident triage, known-good rules, troubleshooting, deployment
Admin Account HygieneAdministrative account standards and periodic hygiene checks
Monthly Security ReviewMonthly security review checklist and procedure
Monthly Threat Hunt ScopeMonthly threat hunt hypothesis framework, KQL queries, evidence retention
Kill Chain Audit PolicyWindows audit policy configuration enabling kill-chain detection (EventID 4688, 4698, etc.)

Arctic Wolf (MDR)

DocumentDescription
Arctic Wolf Health CheckWeekly MDR health check — agent connectivity, log ingestion, alert queue
Arctic Wolf Ingestion ValidationVerify Arctic Wolf is receiving all required log sources
Arctic Wolf CMDB CheckReconcile Arctic Wolf device inventory against CMDB
Arctic Wolf AWS ConnectorAWS log connector setup and troubleshooting
Arctic Wolf OneLogin ConnectorOneLogin integration setup for Arctic Wolf

Backup & Disaster Recovery

DocumentDescription
Backup ArchitectureAzure Recovery Services Vault, Veeam DR replication, DDE vault coverage, validation
Veeam Restore ProcedureHow to actually recover data — RSV file/VM/SQL restore, Veeam DR to AWS, Glacier recovery, restore decision tree
Offline Backup ProcedureAir-gapped backup procedure — when and how to create offline copies
DR Test ChecklistPre/during/post DR test checklist
BGKIT DR Checklist NoteBusiness continuity kit DR checklist notes
Annual BGKIT VerificationAnnual business continuity kit verification procedure

Intune & Device Management

DocumentDescription
Intune MAM MobileMobile Application Management policy — what is enforced on mobile devices
Intune Non-Compliance InvestigationHow to investigate non-compliant devices and restore compliance
Intune Orphaned DevicesFinding and cleaning up orphaned device records
Intune USB Storage BlockUSB storage blocking policy configuration
DDE ASR ConfigurationAttack Surface Reduction rule configuration for the DDE environment

System Maintenance

DocumentDescription
Common Infrastructure TasksRoutine operations — server management, firewall changes, certificate rotation
Twingate Operations GuideAdding users and resources, troubleshooting access, connector health check, outage procedure
Twingate Compliance EnforcementEnforcing device compliance certificates for Twingate access
Twingate Connector IPsConnector IP inventory and firewall allowlist
Cloud PC RebuildKobe Cloud PC (AWS EC2 Ubuntu) rebuild procedure from scratch
Cloudflare Terraform IntegrationCloudflare DNS and WAF management via Terraform
Velociraptor OperationsVelociraptor DFIR agent deployment and artifact collection
Ultra Disk EvaluationAzure Ultra Disk evaluation for high-IOPS workloads
BIZFTPAZP01 Stale CredentialsStale credential remediation on the BIZFTPAZP01 server

Recurring Cadence

DocumentDescription
Annual Communications Test ScheduleAnnual schedule for testing all communication channels
Quarterly Service Principal CleanupQuarterly cleanup of expired or unused service principals
Quarterly SP Permission ReviewQuarterly service principal permission audit
Post-Cleanup Drift VerificationVerifying no configuration drift after a cleanup cycle
Year-End ChecklistAnnual year-end security and compliance review checklist

Active Projects & Migration Work

DocumentDescription
Dashboard Migration Plandashboard.ciriusgroup.com migration plan
iMacros Migration ScopeScope and plan for retiring iMacros automation
June 2026 Decommission ChecklistResources scheduled for decommission by June 2026

Compliance

SOC2 Audit Readiness

DocumentDescription
SOC2 PBC GuideProvided By Client guide — maps every common auditor request to exact evidence location. Start here for the September 2026 audit.
HIPAA Risk AssessmentFormal §164.308(a)(1)(ii)(A) risk assessment — 7 risks with likelihood × impact scoring, residual scores, treatment plan, acknowledgment
Training Completion LogWho completed what training and when — KnowBe4, HIPAA, IR tabletop, phishing sims. Update within 5 days of each event.
Emergency Mode Operation Plan§164.308(a)(7)(ii)(C) — what continues during an outage, who decides, minimum security controls, communication plan
Pen Test Results LogMonthly scan results tracker — finding severity, SLAs, open findings, false positives, auditor evidence package instructions

Frameworks & Core Controls

DocumentDescription
HIPAA Controls MatrixComplete mapping of infrastructure controls to HIPAA requirements
HIPAA Administrative ProceduresSix HIPAA safeguard procedures: risk management, sanction policy, workforce training, incident procedures, contingency planning, evaluation
HIPAA Policy SetFull policy framework documents — information security, acceptable use, data classification
Logging ArchitectureDual logging system (hot/SIEM/archive), all log sources wired, 6-year WORM archive
Tagging StandardTerraform naming conventions and required tags for all resources
Compliance ScorecardCurrent compliance posture across SOC2/HIPAA/HITRUST — control scores and gaps

Audit Evidence

DocumentDescription
Least Privilege — CI/CD AuditEvidence: CI/CD pipeline least-privilege assessment
Least Privilege — ops-automation AuditEvidence: ops-automation agents least-privilege assessment
Least Privilege — SecOps AuditEvidence: SecOps platform least-privilege assessment
Least Privilege — Evidence MappingEvidence traceability: least-privilege controls → HIPAA/SOC2 requirements
VPNLYR Audit EvidenceHIPAA/SOC2 control mapping evidence for Twingate ZTNA layer
Annual Review ChecklistAnnual security review checklist for SOC2/HIPAA
Keeper License AuditKeeper password manager license audit and user reconciliation

Risk Management

DocumentDescription
Risk Acceptance RegisterFormal log of accepted risks — all items require Rory approval
Cyber Insurance Review ChecklistAnnual cyber insurance renewal checklist
IR Retainer EvaluationIncident response retainer vendor analysis
Vendor PHI InventoryAll vendors that handle PHI — BAA status, data flows
Vendor Risk InventoryThird-party vendor risk assessments

IR Tabletop

DocumentDescription
IR Tabletop Scenario 20262026 tabletop exercise scenario (ransomware)
IR Tabletop CoordinationLogistics, participant roles, facilitation guide
IR Tabletop Findings TemplateStructured findings template for post-exercise documentation

DR Testing

DocumentDescription
Q2 2026 DR Test PlanQ2 2026 scheduled DR test plan — Azure → AWS failover validation
Q4 2026 DR Test PlanQ4 2026 DR test plan
Q3 Enforce Mode ReviewQ3 review of Purview DLP and Intune enforce mode rollout

Access Control & Privileged Access

DocumentDescription
Three-Layer Access ArchitectureZTNA + Entra + Intune — full access control model and compliance mapping
Access Control ReviewPeriodic access control review procedure and evidence
PIM Exclusion ListAccounts excluded from PIM enforcement — all require justification
PAM EvaluationPrivileged Access Management solution evaluation
PAM ScopePAM scope definition — what accounts and systems are in scope
Purview DLP Enforce Mode CriteriaCriteria required before moving DLP policies to Enforce mode
Onboarding Security ChecklistNew employee security provisioning checklist

Training & Awareness

DocumentDescription
Security Awareness Training EvaluationTraining program vendor evaluation and selection
Phishing Simulation ScheduleMonthly phishing simulation campaign schedule and metrics

Database

DocumentDescription
MySQL Server SetupMySQL installation, configuration, and maintenance procedures

Threat Hunting

DocumentDescription
Hunt 001 — Baseline Threat HuntFirst formal threat hunt: hypothesis, KQL queries, evidence template. Also serves as the template for future hunts.

Key Learnings

DocumentDescription
Key Learnings289 lines of infrastructure gotchas and hard-won lessons — Palo Alto quirks, Azure limitations, AWS behavior differences, KQL normalization, Terraform pitfalls. Read this before troubleshooting anything.

Infrastructure Tools

ToolPurpose
TerraformInfrastructure as code across Azure and AWS
GitHub ActionsCI/CD pipeline orchestration
CheckovHIPAA compliance scanning (IaC layer)
TrivyContainer image vulnerability scanning
Azure PolicyRuntime compliance monitoring (Azure) — HIPAA/HITRUST + ISO 27001
AWS Security HubRuntime compliance monitoring (AWS) — NIST 800-53 R5
AWS Audit ManagerContinuous HIPAA Omnibus assessment (all 7 accounts)
Palo Alto VM-SeriesNetwork traffic inspection and zone enforcement (4 firewalls)
PanoramaCentralized firewall management and log aggregation
Arctic Wolf MDRActive security monitoring — VLC active across all 4 firewalls, act-first authority
Cortex XDREDR on all Windows VMs and managed devices
MaesterWeekly M365 security testing — both tenants
Nuclei + NmapMonthly automated penetration testing
TwingateZero-trust network access (primary remote access)
GlobalProtectVPN access (CEO/CTO only)
IntuneDevice management and compliance enforcement
KeeperPassword management
Azure Container Apps JobsAgent runtime for the 17-agent security monitoring system
Azure OpenAI (gpt-4o)LLM inference for SecurityAgent and Detection Agent

Recently Added Docs (auto-generated)

Docs present in the repo but not yet placed in the curated tables above. Regenerate with the one-liner in this section's comment. Last generated: 2026-06-10.

DocumentTitle
architecture/kill-chain-agent-development.mdKill Chain Agent Development Guide
architecture/secops-api-reference.mdCirius Group SOC API Reference
architecture/uba-architecture.mdUBA Architecture — User Behavioral Analytics
cicd/github-actions-security-review.mdGitHub Actions Security Review
compliance/baa-management.mdBAA Management — Business Associate Agreement Tracking and Renewal
compliance/dr-test-results-log.mdDisaster Recovery Test Results Log
compliance/hipaa-breach-notification-procedure.mdHIPAA Breach Notification Procedure
compliance/key-rotation-schedule.mdKey and Credential Rotation Schedule
compliance/physical-safeguards.mdHIPAA Physical Safeguards — §164.310
compliance/pim-operations.mdPIM Operations — Privileged Identity Management
compliance/soc2-audit-readiness.mdSOC2 Audit Readiness — September 2026
runbooks/active-directory-operations.mdActive Directory Operations Guide
runbooks/arctic-wolf-day-to-day.mdArctic Wolf Day-to-Day Operations
runbooks/auditd-setup-and-operations.mdauditd Setup and Operations — Linux VMs
runbooks/aws-account-access.mdAWS Account Access Guide
runbooks/aws-audit-manager.mdAWS Audit Manager — HIPAA Compliance Runbook
runbooks/aws-iam-identity-center.mdAWS IAM Identity Center Operations
runbooks/aws-security-hub-triage.mdAWS Security Hub Finding Triage
runbooks/azure-daily-operations.mdAzure Daily Operations Guide
runbooks/azure-monitor-alerts.mdAzure Monitor Alerts — Operations Runbook
runbooks/azure-openai-operations.mdAzure OpenAI Operations Runbook
runbooks/azure-policy-compliance.mdAzure Policy Compliance Runbook
runbooks/backup-restore-verification.mdBackup Restore Verification
runbooks/canary-token-response.mdRunbook: Canary Token Alert Response
runbooks/certificate-renewal-procedure.mdCertificate Renewal Procedure
runbooks/cloud-pc-operations.mdCloud PC Operations Guide
runbooks/conditional-access-reference.mdEntra Conditional Access Policy Reference
runbooks/container-apps-jobs-monitoring.mdContainer Apps Jobs Monitoring
runbooks/cortex-xdr-law-cef-integration.mdCortex XDR → LAW CEF Integration
runbooks/cortex-xdr-operations.mdCortex XDR Day-to-Day Operations
runbooks/cost-management.mdCost Management Guide
runbooks/dcr-ama-management.mdDCR and AMA Management Runbook
runbooks/dde-environment-operations.mdDDE Environment Operations
runbooks/dns-cloudflare-operations.mdDNS and Cloudflare Operations
runbooks/edr-silence-escalation.mdEDR Silence Escalation
runbooks/employee-offboarding.mdEmployee Offboarding Procedure
runbooks/employee-onboarding.mdEmployee Onboarding Procedure
runbooks/entra-connect-operations.mdEntra Connect Operations
runbooks/entra-identity-operations.mdEntra Identity Operations Guide
runbooks/entra-pim-operations.mdEntra ID PIM Operations — Cirius Group
runbooks/fim-coverage-verification.mdRunbook: FIM Coverage Verification
runbooks/first-time-login-unmanaged-device.mdFirst-Time Login From Unmanaged Device
runbooks/github-org-management.mdGitHub Organization Management Guide
runbooks/globalprotect-operations.mdGlobalProtect Operations
runbooks/intune-daily-management.mdIntune Daily Management Guide
runbooks/it-engineer-onboarding.mdIT / Security Engineer — First Week Onboarding
runbooks/keeper-credential-guide.mdKeeper Credential Guide
runbooks/key-vault-secrets-workflow.mdKey Vault Secrets Workflow
runbooks/kill-chain-credential-dumping-response.mdKill Chain — Credential Dumping Agent Response
runbooks/kill-chain-defense-evasion-response.mdKill Chain — Defense Evasion Agent Response
runbooks/kill-chain-execution-response.mdKill Chain — Execution Agent Response
runbooks/kill-chain-exfiltration-response.mdKill Chain — Exfiltration Agent Response
runbooks/kill-chain-incident-response.mdKill Chain Incident Response Playbook
runbooks/kill-chain-lateral-movement-response.mdKill Chain — Lateral Movement Agent Response
runbooks/kill-chain-persistence-response.mdKill Chain — Persistence Agent Response
runbooks/kill-chain-phase1-enablement.mdKill Chain Phase 1 — Event Enablement Runbook
runbooks/kill-chain-phase2-agent-development.mdKill Chain Phase 2 — Agent Development and Deployment Runbook
runbooks/known-good-rule-management.mdKnown-Good Rule Management
runbooks/kobe-bot-setup.mdkobe-bot Setup and Verification
runbooks/kql-query-reference.mdKQL / Log Analytics Query Reference
runbooks/log-retention-verification.mdLog Retention and Archive Verification
runbooks/m365-dlp-operations.mdMicrosoft Purview DLP Operations Guide
runbooks/m365-exchange-operations.mdM365 / Exchange Operations Guide
runbooks/mde-passive-mode.mdMDE Passive Mode — Operations Runbook
runbooks/mfa-operations.mdMFA Operations
runbooks/network-connectivity-troubleshooting.mdNetwork Connectivity Troubleshooting
runbooks/onelogin-operations.mdOneLogin Operations Guide
runbooks/orchestrator-split-operations.mdOrchestrator Split Operations Guide
runbooks/panorama-day-to-day.mdPanorama Day-to-Day Operations
runbooks/patch-management.mdPatch Management Procedure
runbooks/pgaudit-operations.mdpgaudit Operations — psql-secops-prod
runbooks/pgaudit-setup.mdpgaudit Setup — psql-secops-prod
runbooks/postgresql-operations.mdPostgreSQL Operations — psql-secops-prod
runbooks/ransomware-ir-playbook.mdRansomware Incident Response Playbook
runbooks/secops-agent-troubleshooting.mdSecOps Agent Pipeline — Troubleshooting Runbook
runbooks/secops-change-management.mdSecOps Change Management Operations Guide
runbooks/secops-findings-triage.mdSecOps Findings Triage Guide
runbooks/secops-platform-deployment.mdSecOps Platform Deployment Guide
runbooks/terraform-state-management.mdTerraform State Management
runbooks/twingate-device-compliance-certs.mdRunbook: Twingate Device Compliance Certificates
runbooks/uba-operations.mdUBA Operations — User Behavioral Analytics
runbooks/uba-system.mdUBA System — Baseline Builder and Longitudinal Analysis Agent
runbooks/veeam-console-operations.mdVeeam Console — Day-to-Day Operations
runbooks/vendor-contractor-access.mdVendor and Contractor Access Management
runbooks/vm-status-agent.mdVM Status Agent
security/threat-model/controls-mapping.mdControls Mapping — Kill Chain vs Controls
security/threat-model/crown-jewels.mdCrown Jewel Assets
security/threat-model/stride-analysis.mdSTRIDE Analysis — Crown Jewel Attack Paths
security/threat-model/threat-actors.mdThreat Actor Profiles
security/threat-model/threat-model-2026.mdCirius Group Threat Model 2026
threat-hunting/hunt-002-privilege-escalation.mdHunt 002 — Privilege Escalation
threat-hunting/hunt-003-lateral-movement.mdHunt 003 — Lateral Movement
threat-hunting/hunt-004-credential-theft.mdHunt 004 — Credential Theft
threat-hunting/hunt-005-ransomware-precursors.mdHunt 005 — Ransomware Precursors

Autonomous Builds

Some changes in this repo are produced autonomously by the Bedrock Orchestrator and opened as PRs for human review.


Document History

DateChangeAuthor
May 2026Comprehensive index rewrite: added Architecture section (6 docs), expanded Security to 9 subsections (30+ docs), expanded Runbooks to 6 subsections (40+ docs), expanded Compliance to 7 subsections (30+ docs), added Threat Hunting section, added Key Learnings, added New Engineer Guide. Total indexed: 131 docs. Added New Engineer Start Here guide.Rory
March 2026Added new docs: Panorama Operations Guide, Firewall Change Request Procedure, Maester M365 Audit Guide, Penetration Testing, Monthly Cost Reporting. Updated 7 existing docs.Rory
March 2026Added ops-automation-overview.md, palo-alto-config-backup.md, alerting-runbook.md; updated backup-architecture.md; fixed OIDC auth docRory
February 2026Initial draftRory

Runner e2e validated 2026-06-25.

Internal use only — Cirius Group