GDPatrol Logo

GDPatrol

0
Free
Visit Website

A Serverless Security Orchestration Automation and Response (SOAR) Framework for AWS GuardDuty. The GDPatrol Lambda function receives the GuardDuty findings through the CloudWatch Event Rule and executes the appropriate actions to mitigate the threats according to their types and severity. Supported actions include blacklist_ip, whitelist_ip, block_domain, quarantine_instance, snapshot_instance, disable_account, disable_ec2_access, enable_ec2_access, disable_sg_access, enable_sg_access, and asg_detach_instance. The actions to be executed are configured in the config.json file.

FEATURES

ALTERNATIVES

A security operations platform that provides automated threat detection, access control, and protection against various online attacks through Cloudflare integration.

A remediation orchestration platform that consolidates security alerts, automates triage, and streamlines the remediation process across hybrid environments.

An AI-powered security operations platform that automates alert investigation, triage, and response workflows for SOC analysts.

A defense-in-depth security automation and monitoring framework utilizing threat intelligence, machine learning, and serverless technologies.

Automated tool for scripting complex sequences in cybersecurity frameworks.

A DFIR Playbook Spec based on YAML for collaborative incident response processes.

Shuffle is a platform for automating security workflows with confidence, offering templates, collaboration tools, and a large app library.

A DevSecOps command line asset inventory tool