GDPatrol Logo

GDPatrol

0
Free
Visit Website

A Serverless Security Orchestration Automation and Response (SOAR) Framework for AWS GuardDuty. The GDPatrol Lambda function receives the GuardDuty findings through the CloudWatch Event Rule and executes the appropriate actions to mitigate the threats according to their types and severity. Supported actions include blacklist_ip, whitelist_ip, block_domain, quarantine_instance, snapshot_instance, disable_account, disable_ec2_access, enable_ec2_access, disable_sg_access, enable_sg_access, and asg_detach_instance. The actions to be executed are configured in the config.json file.

FEATURES

ALTERNATIVES

Automate security incident handling and facilitate real-time activities of incident handlers.

A human risk management platform that identifies, assesses, and mitigates security risks associated with employee behavior through monitoring, targeted interventions, and comprehensive reporting.

Scripts to quickly fix security and compliance issues

Darktrace is a cyber security solution that uses AI to detect and prevent cyber attacks in real-time.

Sample security playbooks for security automation, orchestration and response (SOAR) using Microsoft Sentinel trigger

A DFIR console integrating various cybersecurity tools and frameworks for efficient incident response.

Scalable, cost-effective application recovery to AWS.

Todyl is a modular cybersecurity platform that consolidates SASE, SIEM, EDR/NGAV, MXDR, and GRC capabilities into a single-agent solution with centralized management.