AWS Security Automation Logo

AWS Security Automation

A collection of AWS-native scripts and automation tools for DevSecOps, incident response, and security remediation in cloud environments.

626
Security Operations
Free
Visit website
0

AWS Security Automation Description

AWS Security Automation is a collection of scripts and resources designed for DevSecOps, security automation, and automated incident response remediation within AWS environments. The toolkit includes several key components: IAM Access Denied Responder automatically responds to access denied events occurring within CloudTrail events, failed AWS console authentication attempts, or Client.UnauthorizedOperation events through automated workflows. EC2 Auto Clean Room Forensics provides automated incident response capabilities by taking instance IDs from SNS topics and coordinating through AWS Lambda functions and Step Functions to automatically notify stakeholders, isolate compromised instances, and perform basic forensic analysis. CloudTrail Remediation offers demonstration scripts for automatically restarting CloudTrail logging with built-in placeholders for forensic procedures to prevent re-enabling CloudTrail without proper investigation of the root cause. Force User MFA includes demonstration scripts that automatically create and attach virtual multi-factor authentication to newly created IAM users, allowing users to retrieve MFA seeds through AWS CLI. The solution leverages AWS native services including Lambda, Step Functions, SNS, and CloudTrail to provide automated security response capabilities for common AWS security scenarios.

FEATURED

Proton Pass Logo

Password manager with end-to-end encryption and identity protection features

NordVPN Logo

VPN service providing encrypted internet connections and privacy protection

Mandos Fractional CISO Services Logo

Fractional CISO services for B2B companies to accelerate sales and compliance

Stay Updated with Mandos Brief

Get the latest cybersecurity updates in your inbox

POPULAR

RoboShadow Logo

Automated vulnerability assessment and remediation platform

11
TestSavantAI Logo

Security platform that provides protection, monitoring and governance for enterprise generative AI applications and LLMs against various threats including prompt injection and data poisoning.

6
Cybersec Feeds Logo

A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.

5
Fabric Platform by BlackStork Logo

Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.

5
Mandos Brief Newsletter Logo

A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.

5
View Popular Tools →