GDPatrol
A serverless SOAR framework for AWS GuardDuty that automatically executes configurable response actions based on security findings and threat severity.

GDPatrol
A serverless SOAR framework for AWS GuardDuty that automatically executes configurable response actions based on security findings and threat severity.
GDPatrol Description
GDPatrol is a serverless Security Orchestration Automation and Response (SOAR) framework designed specifically for AWS GuardDuty integration. The framework operates as a Lambda function that automatically receives GuardDuty findings through CloudWatch Event Rules and executes predefined response actions based on threat types and severity levels. The tool supports multiple automated response capabilities including IP blacklisting and whitelisting, domain blocking, EC2 instance quarantine and snapshot creation, account disabling, EC2 access control management, security group access modifications, and Auto Scaling Group instance detachment. All response actions are configurable through a config.json file, allowing organizations to customize their automated threat response workflows. GDPatrol integrates natively with AWS services and leverages serverless architecture to provide scalable, event-driven security automation without requiring dedicated infrastructure management. The framework processes GuardDuty findings in real-time and applies appropriate mitigation measures automatically, reducing manual intervention requirements for security teams.
GDPatrol FAQ
Common questions about GDPatrol including features, pricing, alternatives, and user reviews.
GDPatrol is A serverless SOAR framework for AWS GuardDuty that automatically executes configurable response actions based on security findings and threat severity.. It is a Security Operations solution designed to help security teams with Lambda, Security Orchestration, Serverless.