- Home
- Security Operations
- Digital Forensics and Incident Response
- aws-summarize-account-activity

aws-summarize-account-activity
A Python tool that analyzes AWS CloudTrail data to summarize IAM principal activities, API calls, regions, IP addresses, and user agents with configurable timeframes and visualization options.

aws-summarize-account-activity
A Python tool that analyzes AWS CloudTrail data to summarize IAM principal activities, API calls, regions, IP addresses, and user agents with configurable timeframes and visualization options.
aws-summarize-account-activity Description
A Python-based tool that analyzes AWS CloudTrail data to generate comprehensive summaries of account activity. The tool examines IAM principal activities, API calls, regions, IP addresses, and user agents within a specified timeframe. Key features include: - Analysis of CloudTrail data for recently active IAM principals - Tracking of API calls made by different principals - Identification of regions, IP addresses, and user agents used - Configurable analysis timeframe (1 hour to 90 days, default 14 days) - Support for analyzing all API calls, successful calls only, or failed calls only - JSON output format for structured data export - Optional PNG visualization generation for graphical representation - Raw CloudTrail data export capability in JSONL format - Support for AWS named profiles and environment variable credentials The tool requires proper AWS credentials configuration and CloudTrail access permissions to function. It processes historical CloudTrail logs to provide insights into account usage patterns and security-relevant activities across AWS services and regions.
FEATURED
Password manager with end-to-end encryption and identity protection features
VPN service providing encrypted internet connections and privacy protection
Fractional CISO services for B2B companies to accelerate sales and compliance
Stay Updated with Mandos Brief
Get the latest cybersecurity updates in your inbox
TRENDING CATEGORIES
POPULAR
A cybersecurity platform that offers vulnerability scanning, Windows Defender and 3rd party AV management, and MFA compliance reporting, among other features.
Security platform that provides protection, monitoring and governance for enterprise generative AI applications and LLMs against various threats including prompt injection and data poisoning.
A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.