Netflix-Skunkworks / diffy
(DEPRECATED) Diffy is a triage tool used during cloud-centric security incidents, to help digital forensics and incident response (DFIR) teams quickly identify suspicious hosts on which to focus their response.
☆635Updated 10 months ago
Related projects ⓘ
Alternatives and complementary repositories for diffy
- Python installable command line utiltity for mitigation of host and key compromises.☆344Updated 3 years ago
- A repository for using osquery for incident detection and response☆828Updated 2 years ago
- an osquery fleet manager☆621Updated last year
- Dow Jones Hammer : Protect the cloud with the power of the cloud(AWS)☆436Updated last year
- BinaryAlert: Serverless, Real-time & Retroactive Malware Detection.☆1,409Updated 11 months ago
- A tool to help forensicate offline docker acquisitions☆529Updated last month
- Remote Memory Acquisition Tool☆242Updated 4 years ago
- honeyλ - a simple, serverless application designed to create and monitor fake HTTP endpoints (i.e. URL honeytokens) automatically, on top…☆513Updated 6 years ago
- AWS Least Privilege for Distributed, High-Velocity Deployment☆1,121Updated last year
- Google Cloud Platform Security Tool☆232Updated 5 years ago
- AWS Security Tools (AST) in a simple Docker container.☆285Updated 3 years ago
- for AWS Security material☆246Updated 2 years ago
- An information security preparedness tool to do adversarial simulation.☆1,102Updated 5 years ago
- Aardvark is a multi-account AWS IAM Access Advisor API☆473Updated 3 weeks ago
- Fetch all public IP addresses tied to your AWS account. Works with IPv4/IPv6, Classic/VPC networking, and across all AWS services☆634Updated 3 years ago
- Security auditing tool for AWS environments☆1,725Updated 5 years ago
- A flexible control server for osquery fleets☆1,103Updated 3 years ago
- A graph-based tool for visualizing effective access and resource relationships in AWS environments.☆922Updated 2 years ago
- Collection of scripts and resources for DevSecOps and Automated Incident Response Security☆620Updated 3 years ago
- CloudTracker helps you find over-privileged IAM users and roles by comparing CloudTrail logs with current IAM policies.☆887Updated 2 years ago
- ☆364Updated 8 months ago
- A Linux Auditd rule set mapped to MITRE's Attack Framework☆778Updated 4 years ago
- A UNIX security auditing tool based on several security frameworks☆309Updated 4 months ago
- AWS Serverless Security☆400Updated 2 years ago
- Open Cloud Security Posture Management Engine☆335Updated 2 years ago
- Hubble is a modular, open-source security compliance framework. The project provides on-demand profile-based auditing, real-time security…☆379Updated last year
- A collection of AWS penetration testing junk☆1,173Updated last year
- Distributed alerting for the masses!☆995Updated 6 years ago