ThreatResponse / aws_ir
Python installable command line utiltity for mitigation of host and key compromises.
☆344Updated 3 years ago
Alternatives and similar repositories for aws_ir:
Users that are interested in aws_ir are comparing it to the libraries listed below
- Remote Memory Acquisition Tool☆245Updated 4 years ago
- ☆368Updated 10 months ago
- Collection of scripts and resources for DevSecOps and Automated Incident Response Security☆621Updated 4 years ago
- for AWS Security material☆246Updated 2 years ago
- Dow Jones Hammer : Protect the cloud with the power of the cloud(AWS)☆437Updated last year
- Example detection of compromise credentials in AWS☆119Updated 6 years ago
- Blazing CloudTrail since 2018☆133Updated 5 years ago
- A MITRE ATT&CK Navigator export for AWS GuardDuty Findings☆137Updated 3 years ago
- A small set of scripts to summarize AWS Security Groups, and generate visualizations of the rules.☆62Updated 4 years ago
- AWS Inventory and Compliance Framework☆223Updated last year
- Resource types that can be publicly exposed on AWS☆320Updated 2 years ago
- ☆378Updated last year
- (DEPRECATED) Diffy is a triage tool used during cloud-centric security incidents, to help digital forensics and incident response (DFIR)…☆633Updated last year
- Built-in Panther detection rules and policies☆349Updated this week
- Google Cloud Platform Security Tool☆233Updated 5 years ago
- A python module for orchestrating content acquisitions and analysis via amazon ssm.☆58Updated last year
- ☆152Updated last year
- This script is used to generate some basic detections of the aws security services☆71Updated 2 years ago
- Aardvark is a multi-account AWS IAM Access Advisor API☆474Updated 2 months ago
- Open Cloud Security Posture Management Engine☆336Updated 2 years ago
- Open source security career ladders☆115Updated 2 years ago
- 'Continuous' AWS perimeter monitoring: Periodically scan internet facing AWS resources to detect misconfigured services.☆63Updated 5 years ago
- Open source demos, concept and guidance related to the AWS CIS Foundation framework.☆618Updated 5 years ago
- This repository can be used to generate and evaluate findings detected by Amazon GuardDuty☆356Updated last month
- barq: The AWS Cloud Post Exploitation framework!☆386Updated 2 years ago
- The SOCless automation framework☆134Updated last month
- CloudTracker helps you find over-privileged IAM users and roles by comparing CloudTrail logs with current IAM policies.☆891Updated 3 years ago
- SkyWrapper helps to discover suspicious creation forms and uses of temporary tokens in AWS☆104Updated 3 years ago
- ☆82Updated 5 years ago