SyntheticSun Logo

SyntheticSun

0
Free
Visit Website

SyntheticSun is a defense-in-depth security automation and monitoring framework that utilizes threat intelligence, machine learning, managed AWS security services, and serverless technologies to prevent, detect, and respond to threats. It uses event- and time-based serverless automation to collect, normalize, enrich, and correlate security telemetry in Kibana. It leverages threat intelligence, geolocation data, open-source intelligence, machine learning (ML) backed anomaly detection, and AWS APIs to identify potential threats. Additionally, it utilizes Random Cut Forests (RCF) and IP Insights unsupervised ML algorithms to identify anomalies in timeseries and IP-entity pair data. It dynamically updates AWS WAFv2 IP Sets and Amazon GuardDuty threat intel sets to enhance protection against known threats.

FEATURES

ALTERNATIVES

A Live Response collection script for Incident Response that automates the collection of artifacts from various Unix-like operating systems.

Fast suspicious file finder for threat hunting and live forensics.

A Serverless Security Orchestration Automation and Response (SOAR) Framework for AWS GuardDuty with various supported actions.

A Sysmon configuration repository for customizing Microsoft Sysinternals Sysmon configurations with modular setup.

Open-source security automation platform for automating security alerts and building AI-assisted workflows.

Repository of templates for Ayehu's workflows with the ability to design, execute, and automate IT and business processes.

Automate security incident handling and facilitate real-time activities of incident handlers.

A System for Abuse- and Incident Handling with log file analysis capabilities.