AWS Incident Response Investigation of API activity using Athena and notification of actions using EventBridge
This project explores useful CloudTrail events that support incident response and detection of misconfigurations. Documenting the queries and filters used to identify these CloudTrail events helps to: * build a timeline of events * understand the scope of the incident * identify indicators of compromise * decrease time to containment and recovery Mis-configurations are important events to identify early. These configurations may introduce a vulnerability, but may also be an indicator of compromise. Whether executed manually or by automating, this information may be used to develop incident response playbooks. These types of formalization activities promote a consistent, efficient, and effective response to security incidents.
FEATURES
SIMILAR TOOLS
Dispatch helps manage security incidents by integrating with existing tools and automating incident response tasks.
A collection of AWS security architectures for various security operations.
Darktrace is a cyber security solution that uses AI to detect and prevent cyber attacks in real-time.
Anvilogic is a SIEM platform that streamlines detection engineering, offers cost-effective data management, and enhances threat detection capabilities.
Fast Intercept is a security automation platform that empowers users to maximize their existing security products and automate routine tasks.
Cortex XSOAR is a comprehensive SOAR platform that automates and standardizes security processes for faster response times and increased team productivity.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.