FRIENDS CORP.

FRIENDS CORP. FRIENDS CORP. is a global venture builder born in Japan.

We bring together technology, people, and local expertise to build and grow businesses across borders, turning ideas into sustainable ventures with global impact.

24/09/2026

A day to connect, reflect, and grow together. 💜

Our FRIENDS CORP. Bangladesh team recently came together for a meetup filled with conversations, shared ideas, and memorable moments.

We were glad to have our MD of Engineering Team, Mohammad Monir Hossain, join us . He shared his thoughts on our business, encouraged the team, and spoke about how we can keep growing together.

Here’s a glimpse of the people and moments that made the day special. Thank you to everyone who joined us!

𝗘𝗻𝗴𝗶𝗻𝗲𝗲𝗿𝗶𝗻𝗴 𝗖𝗵𝗿𝗼𝗻𝗶𝗰𝗹𝗲𝘀 | 𝗘𝗽𝗶𝘀𝗼𝗱𝗲 05💸 Most AWS bills don't grow because you're using more. Sometimes, they grow because y...
10/09/2026

𝗘𝗻𝗴𝗶𝗻𝗲𝗲𝗿𝗶𝗻𝗴 𝗖𝗵𝗿𝗼𝗻𝗶𝗰𝗹𝗲𝘀 | 𝗘𝗽𝗶𝘀𝗼𝗱𝗲 05

💸 Most AWS bills don't grow because you're using more. Sometimes, they grow because you forgot to turn something off.

A test server gets created and never shut down.

A storage volume outlives the project it belonged to.

A temporary resource gets spun up for a quick task and simply… stays.

Nothing breaks.

No alerts go off.

Everything appears to be working normally.

It just quietly shows up on the AWS bill.

We realised we didn't need better instances or more sophisticated architecture to address this.

We needed better visibility into what we were actually paying for.

So we built a script that scans our AWS environment and identifies potentially unused resources across 27 different resource types.

It runs directly from AWS CloudShell, without requiring special billing access, making the process easy for the engineering team to use when needed.

From there, our process is simple:

🔎 Identify — The script flags resources that appear to be unused

👀 Verify — We manually review each resource before making any changes

🗑️ Remove — Only confirmed unused resources are cleaned up

🔁 Repeat — Instead of treating this as a one-time cleanup, we now review our environment regularly

The result?

💰 A noticeably lower AWS bill — without changing our architecture.

We simply stopped paying for infrastructure we no longer needed.

The lesson was straightforward:

Cloud optimization isn't always about making what you use cheaper.

Sometimes, the bigger win is discovering what you shouldn't be paying for at all.

𝗘𝗻𝗴𝗶𝗻𝗲𝗲𝗿𝗶𝗻𝗴 𝗖𝗵𝗿𝗼𝗻𝗶𝗰𝗹𝗲𝘀 | 𝗘𝗽𝗶𝘀𝗼𝗱𝗲 04🛡️ 𝗡𝗼𝘁 𝗲𝘃𝗲𝗿𝘆 𝘀𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝘄𝗶𝗻 𝗰𝗼𝗺𝗲𝘀 𝗳𝗿𝗼𝗺 𝗯𝘂𝗶𝗹𝗱𝗶𝗻𝗴 𝘀𝗼𝗺𝗲𝘁𝗵𝗶𝗻𝗴 𝗰𝗼𝗺𝗽𝗹𝗲𝘅. 𝗦𝗼𝗺𝗲𝘁𝗶𝗺𝗲𝘀, 𝗱𝗼𝗶𝗻𝗴 𝘁𝗵𝗲...
03/09/2026

𝗘𝗻𝗴𝗶𝗻𝗲𝗲𝗿𝗶𝗻𝗴 𝗖𝗵𝗿𝗼𝗻𝗶𝗰𝗹𝗲𝘀 | 𝗘𝗽𝗶𝘀𝗼𝗱𝗲 04

🛡️ 𝗡𝗼𝘁 𝗲𝘃𝗲𝗿𝘆 𝘀𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝘄𝗶𝗻 𝗰𝗼𝗺𝗲𝘀 𝗳𝗿𝗼𝗺 𝗯𝘂𝗶𝗹𝗱𝗶𝗻𝗴 𝘀𝗼𝗺𝗲𝘁𝗵𝗶𝗻𝗴 𝗰𝗼𝗺𝗽𝗹𝗲𝘅. 𝗦𝗼𝗺𝗲𝘁𝗶𝗺𝗲𝘀, 𝗱𝗼𝗶𝗻𝗴 𝘁𝗵𝗲 𝗯𝗮𝘀𝗶𝗰𝘀 𝗰𝗼𝗻𝘀𝗶𝘀𝘁𝗲𝗻𝘁𝗹𝘆 𝗶𝘀 𝘄𝗵𝗮𝘁 𝗽𝗿𝗲𝘃𝗲𝗻𝘁𝘀 𝗮𝗻 𝗶𝗻𝗰𝗶𝗱𝗲𝗻𝘁 𝗳𝗿𝗼𝗺 𝗵𝗮𝗽𝗽𝗲𝗻𝗶𝗻𝗴 𝗮𝘁 𝗮𝗹𝗹.

Recently, we saw multiple attack attempts targeting our systems within a short period of time.

Different targets. Different patterns. Same intent.

Most of them didn't get very far.

Not because we had built an overly complicated defense system, but because some fundamental protections were already in place and, more importantly, 𝘄𝗲 𝘄𝗲𝗿𝗲 𝗮𝗰𝘁𝗶𝘃𝗲𝗹𝘆 𝗺𝗼𝗻𝗶𝘁𝗼𝗿𝗶𝗻𝗴 𝘁𝗵𝗲𝗺.

But while reviewing the activity, something caught our attention:

𝗢𝘂𝗿 𝘀𝘁𝗮𝗴𝗶𝗻𝗴 𝘀𝗲𝗿𝘃𝗲𝗿𝘀.

Staging environments exist for development and testing, so it's easy to think of them as lower priority.

Attackers don't see them that way.

To an attacker, a reachable staging server is still a server worth probing. And if it receives less attention than production, it can become an easier target.

So we went back to the fundamentals 𝗮𝗰𝗿𝗼𝘀𝘀 𝗲𝘃𝗲𝗿𝘆 𝗲𝗻𝘃𝗶𝗿𝗼𝗻𝗺𝗲𝗻𝘁.

We now:

✔️ Use 𝗪𝗔𝗙 𝗿𝘂𝗹𝗲𝘀 to automatically detect and block common attack patterns

✔️ Apply the same security protections across 𝗽𝗿𝗼𝗱𝘂𝗰𝘁𝗶𝗼𝗻, 𝘀𝘁𝗮𝗴𝗶𝗻𝗴, 𝗮𝗻𝗱 𝗱𝗲𝘃𝗲𝗹𝗼𝗽𝗺𝗲𝗻𝘁 𝗲𝗻𝘃𝗶𝗿𝗼𝗻𝗺𝗲𝗻𝘁𝘀

✔️ Continuously monitor all environments so unusual activity can be identified early

The result?

🛡️ 𝗠𝗼𝘀𝘁 𝗮𝘁𝘁𝗮𝗰𝗸 𝗮𝘁𝘁𝗲𝗺𝗽𝘁𝘀 𝗮𝗿𝗲 𝘀𝘁𝗼𝗽𝗽𝗲𝗱 𝗲𝗮𝗿𝗹𝘆 𝗮𝗻𝗱 𝗾𝘂𝗶𝗲𝘁𝗹𝘆 𝗯𝗲𝗳𝗼𝗿𝗲 𝘁𝗵𝗲𝘆 𝗯𝗲𝗰𝗼𝗺𝗲 𝗶𝗻𝗰𝗶𝗱𝗲𝗻𝘁𝘀 𝘁𝗵𝗮𝘁 𝗿𝗲𝗾𝘂𝗶𝗿𝗲 𝗮 𝗺𝗮𝗷𝗼𝗿 𝗿𝗲𝘀𝗽𝗼𝗻𝘀𝗲.

The lesson for us was simple:

𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗱𝗼𝗲𝘀𝗻'𝘁 𝗮𝗹𝘄𝗮𝘆𝘀 𝗻𝗲𝗲𝗱 𝘁𝗼 𝗯𝗲𝗰𝗼𝗺𝗲 𝗺𝗼𝗿𝗲 𝗰𝗼𝗺𝗽𝗹𝗲𝘅.

Sometimes the biggest improvement comes from making sure the right protections are 𝗶𝗻 𝗽𝗹𝗮𝗰𝗲 𝗲𝘃𝗲𝗿𝘆𝘄𝗵𝗲𝗿𝗲, 𝗰𝗼𝗻𝘀𝗶𝘀𝘁𝗲𝗻𝘁𝗹𝘆 𝗺𝗮𝗶𝗻𝘁𝗮𝗶𝗻𝗲𝗱, 𝗮𝗻𝗱 𝗮𝗰𝘁𝘂𝗮𝗹𝗹𝘆 𝗺𝗼𝗻𝗶𝘁𝗼𝗿𝗲𝗱.

𝗘𝗻𝗴𝗶𝗻𝗲𝗲𝗿𝗶𝗻𝗴 𝗖𝗵𝗿𝗼𝗻𝗶𝗰𝗹𝗲𝘀 | 𝗘𝗽𝗶𝘀𝗼𝗱𝗲 𝟬𝟯🔐 𝗔𝗻 𝘂𝗻𝗹𝗼𝗰𝗸𝗲𝗱 𝗱𝗼𝗼𝗿 𝗱𝗼𝗲𝘀𝗻'𝘁 𝗻𝗲𝗲𝗱 𝘁𝗼 𝗯𝗲 𝗯𝗿𝗼𝗸𝗲𝗻 𝗱𝗼𝘄𝗻. 𝗜𝘁 𝗷𝘂𝘀𝘁 𝗻𝗲𝗲𝗱𝘀 𝘁𝗼 𝘀𝘁𝗮𝘆 𝘂𝗻𝗹𝗼𝗰𝗸𝗲𝗱.Tha...
17/08/2026

𝗘𝗻𝗴𝗶𝗻𝗲𝗲𝗿𝗶𝗻𝗴 𝗖𝗵𝗿𝗼𝗻𝗶𝗰𝗹𝗲𝘀 | 𝗘𝗽𝗶𝘀𝗼𝗱𝗲 𝟬𝟯

🔐 𝗔𝗻 𝘂𝗻𝗹𝗼𝗰𝗸𝗲𝗱 𝗱𝗼𝗼𝗿 𝗱𝗼𝗲𝘀𝗻'𝘁 𝗻𝗲𝗲𝗱 𝘁𝗼 𝗯𝗲 𝗯𝗿𝗼𝗸𝗲𝗻 𝗱𝗼𝘄𝗻. 𝗜𝘁 𝗷𝘂𝘀𝘁 𝗻𝗲𝗲𝗱𝘀 𝘁𝗼 𝘀𝘁𝗮𝘆 𝘂𝗻𝗹𝗼𝗰𝗸𝗲𝗱.

That's essentially what happened to us.

A known vulnerability with a publicly documented CVE was exploited on one of our servers before the available patch had been applied. The attacker didn't take the server offline or cause an obvious failure.

Instead, they quietly installed a cryptocurrency miner and began using our computing resources for their own gain.

And that's what made this incident interesting from an engineering perspective.

The server was still running.
The application was still available.
No obvious alarm was going off.

But something wasn't normal.

📈 𝗖𝗣𝗨 𝘂𝘀𝗮𝗴𝗲 𝘀𝘂𝗱𝗱𝗲𝗻𝗹𝘆 𝗶𝗻𝗰𝗿𝗲𝗮𝘀𝗲𝗱 𝗯𝗲𝘆𝗼𝗻𝗱 𝘁𝗵𝗲 𝘀𝗲𝗿𝘃𝗲𝗿'𝘀 𝘂𝘀𝘂𝗮𝗹 𝗯𝗮𝘀𝗲𝗹𝗶𝗻𝗲.

That abnormal behavior triggered our investigation, and we discovered the unauthorized mining process running on the infrastructure.

We removed it, secured the affected environment, and patched the vulnerability.

But simply fixing the server wasn't enough.

𝗪𝗲 𝗰𝗵𝗮𝗻𝗴𝗲𝗱 𝘁𝗵𝗲 𝘄𝗮𝘆 𝘄𝗲 𝗮𝗽𝗽𝗿𝗼𝗮𝗰𝗵 𝗶𝗻𝗳𝗿𝗮𝘀𝘁𝗿𝘂𝗰𝘁𝘂𝗿𝗲 𝘀𝗲𝗰𝘂𝗿𝗶𝘁𝘆.
Now we:

✔️ Regularly review relevant CVEs across the technologies and services we operate

✔️ Treat unusual CPU and resource usage as potential security signals, not only performance issues

✔️ Prioritize known vulnerabilities as actionable risks rather than waiting for visible system problems

The biggest lesson?
𝗔 𝗵𝗲𝗮𝗹𝘁𝗵𝘆 𝘀𝗲𝗿𝘃𝗲𝗿 𝗶𝘀𝗻'𝘁 𝗻𝗲𝗰𝗲𝘀𝘀𝗮𝗿𝗶𝗹𝘆 𝗮 𝘀𝗲𝗰𝘂𝗿𝗲 𝘀𝗲𝗿𝘃𝗲𝗿.

Security isn't only about detecting an attacker after they get in. It's also about continuously identifying and closing the doors we already know could be open.

𝗘𝗻𝗴𝗶𝗻𝗲𝗲𝗿𝗶𝗻𝗴 𝗖𝗵𝗿𝗼𝗻𝗶𝗰𝗹𝗲𝘀 | 𝗘𝗽𝗶𝘀𝗼𝗱𝗲 𝟬𝟮💻 Knowing a server is healthy doesn't always mean your application is healthy.Think b...
02/08/2026

𝗘𝗻𝗴𝗶𝗻𝗲𝗲𝗿𝗶𝗻𝗴 𝗖𝗵𝗿𝗼𝗻𝗶𝗰𝗹𝗲𝘀 | 𝗘𝗽𝗶𝘀𝗼𝗱𝗲 𝟬𝟮

💻 Knowing a server is healthy doesn't always mean your application is healthy.

Think back to the hospital example from our last post.(Engineering Chronicles | Episode 01)

Server monitoring is like checking a patient's heartbeat. It tells you they're alivebut it doesn't explain why they're in pain.

We faced the same challenge.

Our infrastructure monitoring showed healthy servers, yet users still experienced slow pages and failed actions. Finding the root cause meant digging through multiple logs just to answer questions like:

Which request failed?
What caused the slowdown?
Is it a single endpoint or part of a larger issue?

So we built an Application Performance Monitoring (APM) pipeline that monitors the application itself not just the server.

Instead of seeing:
🔵 Server is healthy

We now see:
🔍𝗧𝗵𝗲 𝗰𝗵𝗲𝗰𝗸𝗼𝘂𝘁 𝗲𝗻𝗱𝗽𝗼𝗶𝗻𝘁 𝗶𝘀 𝗲𝘅𝗽𝗲𝗿𝗶𝗲𝗻𝗰𝗶𝗻𝗴 𝗮 𝗵𝗶𝗴𝗵𝗲𝗿 𝗲𝗿𝗿𝗼𝗿 𝗿𝗮𝘁𝗲 𝗯𝗲𝗰𝗮𝘂𝘀𝗲 𝗼𝗳 𝗮 𝘀𝗹𝗼𝘄 𝗱𝗮𝘁𝗮𝗯𝗮𝘀𝗲 𝗾𝘂𝗲𝗿𝘆 𝗼𝗻 𝘁𝗵𝗲 𝗼𝗿𝗱𝗲𝗿𝘀 𝘁𝗮𝗯𝗹𝗲.

The stack runs on Elastic. Elasticsearch stores and indexes every request, error log, and query in one place. Kibana turns that raw data into dashboards we can actually read and drill into.

Now we can:
✔Trace every request from start to finish
✔ Identify exactly where requests fail
✔ Detect slow database queries before they impact users
✔Find the root cause in minutes instead of hours

𝗦𝗲𝗿𝘃𝗲𝗿 𝗺𝗼𝗻𝗶𝘁𝗼𝗿𝗶𝗻𝗴 𝘁𝗲𝗹𝗹𝘀 𝘂𝘀 𝘁𝗵𝗲 𝗶𝗻𝗳𝗿𝗮𝘀𝘁𝗿𝘂𝗰𝘁𝘂𝗿𝗲 𝗶𝘀 𝗿𝘂𝗻𝗻𝗶𝗻𝗴.

𝗔𝗽𝗽𝗹𝗶𝗰𝗮𝘁𝗶𝗼𝗻 𝗣𝗲𝗿𝗳𝗼𝗿𝗺𝗮𝗻𝗰𝗲 𝗠𝗼𝗻𝗶𝘁𝗼𝗿𝗶𝗻𝗴 𝘁𝗲𝗹𝗹𝘀 𝘂𝘀 𝗵𝗼𝘄 𝘁𝗵𝗲 𝗮𝗽𝗽𝗹𝗶𝗰𝗮𝘁𝗶𝗼𝗻 𝗶𝘀 𝗮𝗰𝘁𝘂𝗮𝗹𝗹𝘆 𝗽𝗲𝗿𝗳𝗼𝗿𝗺𝗶𝗻𝗴.

That's how we reduce troubleshooting time, resolve issues faster, and deliver a more reliable experience for our users.

𝗕𝗲𝘁𝘁𝗲𝗿 𝗣𝗿𝗼𝗰𝗲𝘀𝘀𝗲𝘀. 𝗕𝗲𝘁𝘁𝗲𝗿 𝗖𝗼𝗹𝗹𝗮𝗯𝗼𝗿𝗮𝘁𝗶𝗼𝗻. 𝗕𝗲𝘁𝘁𝗲𝗿 𝗥𝗲𝘀𝘂𝗹𝘁𝘀.Today, the 𝗙𝗥𝗜𝗘𝗡𝗗𝗦 𝗖𝗢𝗥𝗣. Process Development Meeting brought our ...
29/07/2026

𝗕𝗲𝘁𝘁𝗲𝗿 𝗣𝗿𝗼𝗰𝗲𝘀𝘀𝗲𝘀. 𝗕𝗲𝘁𝘁𝗲𝗿 𝗖𝗼𝗹𝗹𝗮𝗯𝗼𝗿𝗮𝘁𝗶𝗼𝗻. 𝗕𝗲𝘁𝘁𝗲𝗿 𝗥𝗲𝘀𝘂𝗹𝘁𝘀.

Today, the 𝗙𝗥𝗜𝗘𝗡𝗗𝗦 𝗖𝗢𝗥𝗣. Process Development Meeting brought our team together to strengthen the way we work and collaborate.

Our CEO, Mizuki Yasuda, shared the importance of building strong operational foundations that support sustainable business growth and long-term success.

Our MD of Engineering Team, Mohammad Monir Hossain , introduced newly developed processes and explained the thinking behind them, focusing on improving collaboration, standardising workflows, and enhancing development quality across teams.

At 𝗙𝗥𝗜𝗘𝗡𝗗𝗦 𝗖𝗢𝗥𝗣., we believe that continuous process improvement is the key to building better products and delivering greater value.

🔥 THE FIFA WORLD CUP 2026 FINAL IS KNOCKING AT THE DOOR! 🏆🇦🇷 Argentina 🆚 🇪🇸 SpainThe biggest match in football is almost...
19/07/2026

🔥 THE FIFA WORLD CUP 2026 FINAL IS KNOCKING AT THE DOOR! 🏆

🇦🇷 Argentina 🆚 🇪🇸 Spain

The biggest match in football is almost here. In just a few hours, one team will lift the most prestigious trophy in the world.

Will Argentina defend their crown, or will Spain write a new chapter in football history?

👇 Your Challenge: Predict Only These Two!

⚽ Today's Final Score:
🥇 Who Will Win the Golden Boot?

Example:

Score: Argentina 2–1 Spain
Golden Boot: Lionel Messi

🏆 The closest prediction will be crowned the FRIENDS CORP. World Cup Prediction Champion!

💬 Drop your prediction in the comments, tag your football-loving friends, and don't forget to share this post!

🚀We stopped guessing which part of our system broke and built something that tells us exactly what failed, while cutting...
19/07/2026

🚀We stopped guessing which part of our system broke and built something that tells us exactly what failed, while cutting our server monitoring costs.

Imagine running a hospital where the only alert is a single red light. You know something is wrong, but not which room, which patient, or what happened.
That was our server monitoring in the past. Not anymore!!

When production issues occurred, our monitoring tools could tell us a server was unhealthy but engineers still spent the first 10 minutes figuring out what had actually failed.

On top of that, we were running a dedicated server 24/7 just to monitor our infrastructure adding unnecessary infrastructure costs.
So we built something better using AWS managed services.

Every server now performs its own health checks every 30 seconds. AWS automatically detects issues, retrieves detailed diagnostics from the affected server, and sends a precise notification to the responsible engineering team within seconds.

Instead of:
🛑 Server is down
We now receive:
🛑 Payment processing worker on Server 3 stopped responding at 2:14 AM

The entire pipeline runs on AWS services like CloudWatch, Lambda, SNS, EventBridge, and SSM without requiring a dedicated monitoring server.

The result:
⚡️ Precise, actionable alerts delivered directly to the responsible engineering team
💰 Server monitoring costs reduced to just a few dollars per month
🔧 Less infrastructure to maintain by engineering team

The best engineering isn't always about building something more complex. Sometimes it's about connecting the right tools in the right way and letting the system take care of itself.

住所

Nihonbashi-Tomizawacho 9-4
Chuo-ku, Tokyo
103-0005

アラート

FRIENDS CORP.が新しいニュースやキャンペーンを投稿したら、いち早くメールでお知らせします。メールアドレスが他の目的に使われることはなく、いつでも配信を停止できます。

ショートカット

共有する

カテゴリー