aws-summarize-account-activity Logo

aws-summarize-account-activity

0
Free
Visit Website

Analyzes CloudTrail data of a given AWS account and generates a summary of recently active IAM principals, API calls they made, as well as regions, IP addresses and user agents they used. The summary is written to a JSON output file and can optionally be visualized as PNG files. Usage: - Make sure you have AWS credentials configured for your target account. - This can either be done using environment variables or by specifying a named profile in the optional --profile argument. Example run: - pip install -r requirements.txt - python aws_summarize_account_activity.py Supported arguments: - All arguments are optional: --activity-type {ALL,SUCCESSFUL,FAILED}: type of CloudTrail data to analyze: all API calls (default), only successful API calls, or only API calls that AWS declined with an error message --dump-raw-cloudtrail-data: store a copy of all gathered CloudTrail data in JSONL format --past-hours HOURS: hours of CloudTrail data to look back and analyze default: 336 (=14 days), minimum: 1, maximum: 2160 (=90 days) --plot-results: generate PNG files that visualize the JSON output file --profile PROFILE: named AWS profile to use when running the command Notes: - The script requires AWS credentials to access the CloudTrail data.

FEATURES

ALTERNATIVES

Implements a cloud version of the Shadow Copy attack against domain controllers in AWS, allowing theft of domain user hashes.

A tool to enumerate S3 buckets for a specific target

Cloud Container Attack Tool (CCAT) is a tool for testing security of container environments.

Discover and understand the Docker Layer 2 ICC Bug and its implications on inter-container communication.

A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

Commercial

A tool for spinning up insecure AWS infrastructure with Terraform for training and security assessment purposes.

Open-source policy-as-code software for multi-cloud and SaaS environments with GPT model conversations and custom analysis policies.

A Python script to test the security of AWS S3 buckets