This repository provides sample templates for security playbooks against various scenarios when using Amazon Web Services.
☆649Feb 28, 2026Updated this week
Alternatives and similar repositories for aws-customer-playbook-framework
Users that are interested in aws-customer-playbook-framework are comparing it to the libraries listed below
Sorting:
- ☆1,050Aug 22, 2025Updated 6 months ago
- ☆97Feb 19, 2024Updated 2 years ago
- A simple threat modeling tool to help humans to reduce time-to-value when threat modeling☆680Updated this week
- AWS CloudSaga - Simulate security events in AWS☆473Updated this week
- AWS Security Analytics Bootstrap enables customers to perform security investigations on AWS service logs by providing an Amazon Athena a…☆272Updated this week
- Example solutions demonstrating how to implement patterns within the AWS Security Reference Architecture guide using CloudFormation (incl…☆1,119Dec 12, 2025Updated 2 months ago
- An AWS tool to help you create a point in time assessment of your AWS account using Prowler.☆592Nov 12, 2025Updated 3 months ago
- Assisted Log Enabler for AWS - Find AWS resources that are not logging, and turn them on.☆273Updated this week
- Example AWS Service control policies to get started or mature your usage of AWS SCPs.☆285Updated this week
- Bare minimum AWS Security Alerting and Secure by default Configuration☆513May 15, 2025Updated 9 months ago
- Automated Security Response on AWS is an add-on solution that works with AWS Security Hub to provide a ready-to-deploy architecture and a…☆464Updated this week
- Generates runbooks for GuardDuty findings☆38Jun 24, 2024Updated last year
- ☆401Sep 25, 2023Updated 2 years ago
- SCP management tool☆135Oct 23, 2023Updated 2 years ago
- Convert cloudtrail data to MITRE ATT&CK Sightings☆82Jul 25, 2022Updated 3 years ago
- Crowdsourced list of sensitive IAM Actions☆159Oct 29, 2024Updated last year
- A repository of breaches of AWS customers☆795Jan 24, 2026Updated last month
- List of known AWS accounts☆254Feb 6, 2026Updated 3 weeks ago
- A tool for AWS incident response, that allows for enumeration, acquisition and analysis of data from AWS environments for the purpose of …☆198Jan 6, 2026Updated last month
- ASEA developer support has ended, and the ASEA github repo will be marked Archived (read-only) by the end of 2025.☆758Nov 17, 2025Updated 3 months ago
- ☆168Feb 24, 2026Updated last week
- An evolving repository of CloudTrail events with detailed descriptions, MITRE ATT&CK insights, real-world incidents, references and secur…☆174Feb 22, 2026Updated last week
- This repository can be used to generate and evaluate findings detected by Amazon GuardDuty☆420Jan 7, 2026Updated last month
- Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized repo…☆2,185Updated this week
- Granular, Actionable Adversary Emulation for the Cloud☆2,267Updated this week
- Example policies demonstrating how to implement a data perimeter on AWS.☆193Updated this week
- Lambda function that streamlines containment of an AWS account compromise☆344Dec 1, 2023Updated 2 years ago
- A cheatsheet containing AWS CloudTrail events that can be used for Incident Response purposes or Detection Engineering.☆80Jan 6, 2026Updated last month
- A tool for quickly evaluating IAM permissions in AWS.☆1,541Aug 2, 2024Updated last year
- Enhance the security of your web applications effortlessly with AWS Firewall Factory. Safeguard your valuable assets through seamless WAF…☆254Nov 17, 2025Updated 3 months ago
- ☆375Feb 23, 2024Updated 2 years ago
- cloudgrep is grep for cloud storage☆326Feb 26, 2025Updated last year
- An AWS IAM policy statement parser and query tool.☆198Feb 10, 2026Updated 3 weeks ago
- [Node, Python, Java] Repository of sample Custom Rules for AWS Config.☆1,727Jan 16, 2026Updated last month
- Create a break glass role for emergency use in order to limit AWS production account access. Configure automatic alerts and logging of ac…☆180Nov 13, 2023Updated 2 years ago
- Analyzes CloudTrail data of a given AWS account and generates a summary of recently active IAM principals, API calls they made, as well a…☆165Dec 21, 2025Updated 2 months ago
- ☆34May 24, 2022Updated 3 years ago
- ☆18Jul 30, 2024Updated last year
- ASH is an extensible, open source SAST, SCA, and IaC security scanner orchestration engine.☆611Feb 25, 2026Updated last week