AWS Security Automation Logo

AWS Security Automation

0
Free
Visit Website

Collection of scripts and resources for DevSecOps, Security Automation and Automated Incident Response Remediation. IAM Access Denied Responder: This example solution will setup an automated response to an access denied event that occurs within a CloudTrail event, a Failed authentication attempt to the AWS console, or a Client.UnauthorizedOperation event occurs. EC2 Auto Clean Room Forensics: This example solution will take an instance ID from an SNS topic and through a series of AWS Lambda functions co-ordinated by AWS Step Functions will automatically notify, isolate and run basic forensics on the identified instance. CloudTrailRemediation: Demo script to automatically restart CloudTrail. The script have placeholders for forensics etc. to avoid enabling CloudTrail without finding the causing user. force-user-mfa: Demo script to automatically create and attach virtual MFA to any newly created IAM user. The use can fetch the MFA Seed themselves using AWS CLI. Copyright 2016 Amazon.com, Inc. or its affiliates. All Rights Reserved. Licensed under the Apache License, Version 2.0 (the 'License'). You may not use this file except in compliance with the License. A copy

FEATURES

ALTERNATIVES

An investigative analytics platform that uses machine learning to fuse and analyze data from multiple sources, enabling security organizations to extract insights and identify patterns for threat prevention and complex investigations.

A collection of Cyber Incident Response Playbook Battle Cards (PBC) for combating cyber threats and attacks, following a prescriptive approach inspired by CERT Societe Generale's IRM.

A System for Abuse- and Incident Handling with log file analysis capabilities.

Migrated Splunk SOAR Connectors to new GitHub organization for better organization and management.

Scumblr is a web application for periodic syncs of data sources and security analysis to streamline proactive security.

A project that uses Athena and EventBridge to investigate API activity and notify of actions for incident response and misconfiguration detection.

A cybersecurity incident management platform for tracking and reporting incidents with agility and speed.

WALKOFF is an automation framework for integrating capabilities and devices to streamline tasks.

PINNED