<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Defense-in-Depth on Security Blueprints</title>
    <link>https://securityblueprints.io/invariant_tags/defense-in-depth/</link>
    <description>Recent content in Defense-in-Depth on Security Blueprints</description>
    <generator>Hugo</generator>
    <language>en</language>
    <managingEditor>user@example.com (Niels Provos)</managingEditor>
    <webMaster>user@example.com (Niels Provos)</webMaster>
    <copyright>Security Blueprints, LLC</copyright>
    <lastBuildDate>Sun, 06 Sep 2026 23:57:45 +0000</lastBuildDate>
    <atom:link href="https://securityblueprints.io/invariant_tags/defense-in-depth/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Egress Control</title>
      <link>https://securityblueprints.io/security-invariants/egress-control/</link>
      <pubDate>Mon, 28 Oct 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/security-invariants/egress-control/</guid>
      <description>Overview Egress control is a security invariant that requires all outbound network traffic from services to be explicitly allowed through domain-based allowlists. By enforcing that services can only connect to pre-approved external destinations, this security control:&#xA;Prevents exploitation of vulnerabilities that require external connectivity, e.g. to download a second stage payload. Blocks command and control (C2) traffic from compromised systems Limits data exfiltration attempts from compromised hosts Provides clear visibility into legitimate vs.</description>
    </item>
  </channel>
</rss>
