AWS Incident Response Investigation of API activity using Athena and notification of actions using EventBridge Logo

AWS Incident Response Investigation of API activity using Athena and notification of actions using EventBridge

0
Free
Updated 11 March 2025
Visit Website

This project explores useful CloudTrail events that support incident response and detection of misconfigurations. Documenting the queries and filters used to identify these CloudTrail events helps to: * build a timeline of events * understand the scope of the incident * identify indicators of compromise * decrease time to containment and recovery Mis-configurations are important events to identify early. These configurations may introduce a vulnerability, but may also be an indicator of compromise. Whether executed manually or by automating, this information may be used to develop incident response playbooks. These types of formalization activities promote a consistent, efficient, and effective response to security incidents.

FEATURES

SIMILAR TOOLS

Dispatch helps manage security incidents by integrating with existing tools and automating incident response tasks.

A collection of AWS security architectures for various security operations.

Darktrace is a cyber security solution that uses AI to detect and prevent cyber attacks in real-time.

A DevSecOps command line asset inventory tool

Fast suspicious file finder for threat hunting and live forensics.

Anvilogic is a SIEM platform that streamlines detection engineering, offers cost-effective data management, and enhances threat detection capabilities.

Metadata repository with installation tools and cloud provider support.

Fast Intercept is a security automation platform that empowers users to maximize their existing security products and automate routine tasks.

Cortex XSOAR is a comprehensive SOAR platform that automates and standardizes security processes for faster response times and increased team productivity.

CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Operated by:

Mandos Cyber • KVK: 97994448

Netherlands • contact@mandos.io

Copyright © 2025 - All rights reserved