ThreatResponse / aws_irView external linksLinks
Python installable command line utiltity for mitigation of host and key compromises.
☆347Jul 23, 2021Updated 4 years ago
Alternatives and similar repositories for aws_ir
Users that are interested in aws_ir are comparing it to the libraries listed below
Sorting:
- Remote Memory Acquisition Tool☆252Sep 22, 2020Updated 5 years ago
- Core incident handling plugins for aws_ir cli, incident pony, and more.☆21Jul 7, 2018Updated 7 years ago
- Python module for evaluation of AWS account best practices around incident handling readieness.☆55Jun 26, 2020Updated 5 years ago
- Web based analysis platform for use with the AWS_IR command line tool.☆17Aug 4, 2016Updated 9 years ago
- Collection of scripts and resources for DevSecOps and Automated Incident Response Security☆634Jan 14, 2026Updated last month
- A python module for orchestrating content acquisitions and analysis via amazon ssm.☆58Nov 2, 2023Updated 2 years ago
- Proof of Concept Zappa Based AWS Persistence and Attack Platform☆40Jun 26, 2020Updated 5 years ago
- ☆374Feb 23, 2024Updated last year
- Blazing CloudTrail since 2018☆138Jan 27, 2019Updated 7 years ago
- Automated Attack Simulation in the Cloud, complete with detection use cases.☆602Nov 28, 2024Updated last year
- ☆83Dec 5, 2019Updated 6 years ago
- A collection of AWS penetration testing junk☆1,217Aug 30, 2023Updated 2 years ago
- (DEPRECATED) Diffy is a triage tool used during cloud-centric security incidents, to help digital forensics and incident response (DFIR)…☆631Jan 11, 2024Updated 2 years ago
- WeirdAAL (AWS Attack Library)☆837Jan 13, 2025Updated last year
- Tools for the Computer Incident Response Team☆150Apr 17, 2017Updated 8 years ago
- ☆401Sep 25, 2023Updated 2 years ago
- Proof of concept incident response demo using SSM and AWS Fargate.☆14Dec 5, 2019Updated 6 years ago
- DPS' Lightweight Investigation Notebook☆433Dec 31, 2023Updated 2 years ago
- Configuration files for the SOF-ELK VM☆1,715Jan 21, 2026Updated 3 weeks ago
- A framework for developing alerting and detection strategies for incident response.☆837Sep 8, 2025Updated 5 months ago
- CloudTracker helps you find over-privileged IAM users and roles by comparing CloudTrail logs with current IAM policies.☆907Dec 17, 2021Updated 4 years ago
- Dow Jones Hammer : Protect the cloud with the power of the cloud(AWS)☆447Jul 17, 2023Updated 2 years ago
- Tools for AWS forensics☆65Mar 4, 2016Updated 9 years ago
- Fast Incident Response☆1,988Updated this week
- Security auditing tool for AWS environments☆1,725Nov 28, 2018Updated 7 years ago
- ☆157Jul 8, 2023Updated 2 years ago
- A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more e…☆4,475Jan 12, 2026Updated last month
- Security Monkey monitors AWS, GCP, OpenStack, and GitHub orgs for assets and their changes over time.☆4,373Feb 11, 2021Updated 5 years ago
- An informational repo about hunting for adversaries in your IT environment.☆1,846Nov 17, 2021Updated 4 years ago
- AWS CloudSaga - Simulate security events in AWS☆472Feb 7, 2026Updated last week
- AWS Least Privilege for Distributed, High-Velocity Deployment☆1,148Nov 24, 2025Updated 2 months ago
- AWS Identity and Access Management Visualizer and Anomaly Finder☆298Jan 23, 2026Updated 3 weeks ago
- AWS Metadata Proxy for protection against SSRF☆68Mar 3, 2020Updated 5 years ago
- Fetch all public IP addresses tied to your AWS account. Works with IPv4/IPv6, Classic/VPC networking, and across all AWS services☆641Apr 29, 2021Updated 4 years ago
- An information security preparedness tool to do adversarial simulation.☆1,142Apr 1, 2019Updated 6 years ago
- This repository can be used to generate and evaluate findings detected by Amazon GuardDuty☆419Jan 7, 2026Updated last month
- Cloud Security Suite - One stop tool for auditing the security posture of AWS/GCP/Azure infrastructure.☆1,165Dec 8, 2022Updated 3 years ago
- Cloud Container Attack Tool (CCAT) is a tool for testing security of container environments.☆647Nov 21, 2019Updated 6 years ago
- The Cold Disk Quick Response (CDQR) tool is a fast and easy to use forensic artifact parsing tool that works on disk images, mounted driv…☆345Jun 25, 2022Updated 3 years ago