The AWS Incident Response Kit (AIRK) is a module-based AWS response tool that allows users to perform various actions using Python. It provides functionalities like listing modules, module details, dry runs, and taking specific actions based on instance IDs, security group IDs, VPC IDs, usernames, access key IDs, and other necessary values.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A human risk management platform that identifies, assesses, and mitigates security risks associated with employee behavior through monitoring, targeted interventions, and comprehensive reporting.
An open-source SOAR tool for automating threat and incident response workflows using CACAO security playbooks.
A collaborative and open-source incident response platform for sharing observables among analysts.
A DFIR Playbook Spec based on YAML for collaborative incident response processes.
Shuffle is a platform for automating security workflows with confidence, offering templates, collaboration tools, and a large app library.
A DFIR console integrating various cybersecurity tools and frameworks for efficient incident response.
AIL Framework is a modular system for analyzing and detecting information leaks from unstructured data sources, with capabilities for data extraction, correlation, and integration with threat intelligence platforms.
A Security Orchestration, Automation and Response (SOAR) platform for incident response and threat hunting.
DFIRTrack is an open source web application focused on incident response for handling major incidents with many affected systems, tracking system status, tasks, and artifacts.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.