Security Response Automation is a cloud-based system that automatically responds to security findings from Google Cloud Security Command Center and Cloud Logging. The system processes security findings through a multi-stage architecture that includes filtering, routing, and automated remediation functions. The tool operates through a Pub/Sub messaging system where security findings trigger automated responses. Initial filtering uses Rego policies to identify and automatically close false positive findings. Valid findings are then routed to appropriate remediation functions based on YAML configuration. Automated response capabilities include creating disk snapshots for forensic analysis, revoking IAM permissions, and sending notifications to external systems. The service account operates with minimal required permissions that can be configured at specific granularity levels. All automated actions are logged to Cloud Logging for audit purposes and accountability. The system includes a monitor mode that logs potential actions without executing them, allowing for testing and validation of automation rules before full deployment.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
Request Tracker for Incident Response (RTIR) is a tool for incident response teams to manage incident reports, correlate data, and facilitate communication.
RedEye is a visual analytic tool that provides enhanced situational awareness and operational insights for both Red and Blue Team cybersecurity operations.
A community repository of workflow templates for the Ayehu NG platform that enables automated IT and business process execution.
IRIS-SOAR is a Python-based modular SOAR platform that automates security incident response workflows and integrates with DFIR-IRIS for enhanced digital forensics operations.
StackStorm is an open-source automation platform that connects and automates DevOps workflows and integrates with existing infrastructure.
A community-driven repository and development framework for creating custom automation activities within the Ayehu NG IT orchestration platform.
Incident response and case management solution for efficient incident response and management.
Shuffle Automation provides an open-source platform for security orchestration, automation, and response.
Open-source security automation platform for automating security alerts and building AI-assisted workflows.
PINNED

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.