GDPatrol Logo

GDPatrol

0
Free
Visit Website

A Serverless Security Orchestration Automation and Response (SOAR) Framework for AWS GuardDuty. The GDPatrol Lambda function receives the GuardDuty findings through the CloudWatch Event Rule and executes the appropriate actions to mitigate the threats according to their types and severity. Supported actions include blacklist_ip, whitelist_ip, block_domain, quarantine_instance, snapshot_instance, disable_account, disable_ec2_access, enable_ec2_access, disable_sg_access, enable_sg_access, and asg_detach_instance. The actions to be executed are configured in the config.json file.

FEATURES

ALTERNATIVES

A Live Response collection script for Incident Response that automates the collection of artifacts from various Unix-like operating systems.

A comprehensive auditd configuration for Linux systems following best practices.

A collection of AWS security architectures for various security operations.

Todyl is a modular cybersecurity platform that consolidates SASE, SIEM, EDR/NGAV, MXDR, and GRC capabilities into a single-agent solution with centralized management.

An AI-powered SOC automation platform that performs autonomous alert triage, investigation, and incident response while augmenting human analyst capabilities.

Automated tool for scripting complex sequences in cybersecurity frameworks.

Scripts to quickly fix security and compliance issues

DFIRTrack is an open source web application focused on incident response for handling major incidents with many affected systems, tracking system status, tasks, and artifacts.

PINNED