AWS Incident Response Investigation of API activity using Athena and notification of actions using EventBridge
This project provides a framework for investigating AWS API activity during security incidents using CloudTrail event analysis through Amazon Athena queries and automated notifications via EventBridge. The tool focuses on identifying and analyzing CloudTrail events that are critical for incident response activities, including the detection of security misconfigurations and potential indicators of compromise. It includes documented queries and filters specifically designed to extract relevant security events from CloudTrail logs. Key capabilities include building incident timelines, determining the scope of security events, and identifying suspicious API activities that may indicate unauthorized access or malicious behavior. The framework supports both manual investigation processes and automated response workflows. The project emphasizes the development of standardized incident response playbooks by formalizing the investigation process. This approach helps security teams maintain consistent methodologies when responding to AWS-based security incidents. The tool addresses both immediate security threats and configuration vulnerabilities that could potentially be exploited, making it useful for proactive security monitoring as well as reactive incident response scenarios.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A library for read-only access to QEMU Copy-On-Write (QCOW) image files, supporting multiple versions and compression formats for digital forensics analysis.
Exterro is a data risk management platform that optimizes e-discovery, digital forensics, and cybersecurity compliance operations.
A library for accessing and parsing Windows NT Registry File (REGF) format files, designed for digital forensics and registry analysis applications.
A library for accessing and parsing Extensible Storage Engine (ESE) Database Files used by Microsoft applications like Windows Search, Exchange, and Active Directory for forensic analysis purposes.
TestDisk is a free data recovery software that can recover lost partitions and undelete files from various file systems.
A command-line tool for creating hex dumps, converting between binary and human-readable representations, and patching binary files.
A library to access the Windows New Technology File System (NTFS) format with read-only support for NTFS versions 3.0 and 3.1.
A library and set of tools for accessing and analyzing storage media devices and partitions for forensic analysis and investigation.
A comprehensive incident response tool for Windows computers, providing advanced memory forensics and access to locked systems.
PINNED

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.