ThreatResponse / aws_irLinks
Python installable command line utiltity for mitigation of host and key compromises.
☆346Updated 3 years ago
Alternatives and similar repositories for aws_ir
Users that are interested in aws_ir are comparing it to the libraries listed below
Sorting:
- Remote Memory Acquisition Tool☆247Updated 4 years ago
- ☆373Updated last year
- for AWS Security material☆248Updated 3 years ago
- Collection of scripts and resources for DevSecOps and Automated Incident Response Security☆626Updated 4 years ago
- Example detection of compromise credentials in AWS☆122Updated 6 years ago
- A MITRE ATT&CK Navigator export for AWS GuardDuty Findings☆137Updated 3 years ago
- (DEPRECATED) Diffy is a triage tool used during cloud-centric security incidents, to help digital forensics and incident response (DFIR)…☆633Updated last year
- Blazing CloudTrail since 2018☆138Updated 6 years ago
- Dow Jones Hammer : Protect the cloud with the power of the cloud(AWS)☆442Updated last year
- A small set of scripts to summarize AWS Security Groups, and generate visualizations of the rules.☆62Updated 5 years ago
- AWS Inventory and Compliance Framework☆224Updated 2 years ago
- A python module for orchestrating content acquisitions and analysis via amazon ssm.☆59Updated last year
- This script is used to generate some basic detections of the aws security services☆71Updated 3 years ago
- A Terraform module for GRR: the distributed incident forensics and response framework☆51Updated 5 years ago
- Incident Response and Forensic on AWS☆20Updated 5 years ago
- Open Cloud Security Posture Management Engine☆343Updated 3 years ago
- ☆97Updated last year
- Google Cloud Platform Security Tool☆234Updated 5 years ago
- ☆37Updated 5 years ago
- Welcome to Sumo Logic's Community Content Repository!☆108Updated 2 months ago
- SkyWrapper helps to discover suspicious creation forms and uses of temporary tokens in AWS☆108Updated 4 years ago
- ☆156Updated 2 years ago
- The SOCless automation framework☆140Updated 5 months ago
- This repository can be used to generate and evaluate findings detected by Amazon GuardDuty☆399Updated 3 weeks ago
- Aardvark is a multi-account AWS IAM Access Advisor API☆479Updated 8 months ago
- Resource types that can be publicly exposed on AWS☆327Updated 3 years ago
- A honey token manager and alert system for AWS.☆319Updated 3 years ago
- AWS Identity and Access Management Visualizer and Anomaly Finder☆295Updated last year
- ☆83Updated 5 years ago
- A production-friendly malware scanner for your AWS cloud☆199Updated 3 years ago