easttimor / aws-incident-responseView external linksLinks
☆374Feb 23, 2024Updated last year
Alternatives and similar repositories for aws-incident-response
Users that are interested in aws-incident-response are comparing it to the libraries listed below
Sorting:
- ☆157Jul 8, 2023Updated 2 years ago
- ☆1,049Aug 22, 2025Updated 5 months ago
- Convert cloudtrail data to MITRE ATT&CK Sightings☆82Jul 25, 2022Updated 3 years ago
- This repository contains the research and components of our research into using Sigma for AWS Incident Response.☆31Jul 12, 2023Updated 2 years ago
- An evolving repository of CloudTrail events with detailed descriptions, MITRE ATT&CK insights, real-world incidents, references and secur…☆172Feb 8, 2026Updated last week
- CloudTracker helps you find over-privileged IAM users and roles by comparing CloudTrail logs with current IAM policies.☆907Dec 17, 2021Updated 4 years ago
- Resource types that can be publicly exposed on AWS☆329Feb 23, 2022Updated 3 years ago
- Automated Attack Simulation in the Cloud, complete with detection use cases.☆603Nov 28, 2024Updated last year
- Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized repo…☆2,180Feb 8, 2026Updated last week
- Multi-threaded AWS inventory collection tool with a focus on security-relevant resources and metadata.☆554Jul 13, 2025Updated 7 months ago
- Access Undenied parses AWS AccessDenied CloudTrail events, explains the reasons for them, and offers actionable remediation steps. Open-s…☆266Jan 26, 2023Updated 3 years ago
- A MITRE ATT&CK Navigator export for AWS GuardDuty Findings☆139Jul 23, 2021Updated 4 years ago
- A tool for quickly evaluating IAM permissions in AWS.☆1,539Aug 2, 2024Updated last year
- Blazing CloudTrail since 2018☆138Jan 27, 2019Updated 7 years ago
- Example detection of compromise credentials in AWS☆122Aug 6, 2018Updated 7 years ago
- A command-line tool to get valuable information out of AWS CloudTrail☆830Updated this week
- A repository of breaches of AWS customers☆794Jan 24, 2026Updated 3 weeks ago
- Python library to carry out DFIR analysis on the Cloud☆499Oct 8, 2025Updated 4 months ago
- ☆83Dec 5, 2019Updated 6 years ago
- AWS Security Analytics Bootstrap enables customers to perform security investigations on AWS service logs by providing an Amazon Athena a…☆270Updated this week
- ☆401Sep 25, 2023Updated 2 years ago
- Automatically compile an AWS Service Control Policy that ONLY allows AWS services that are compliant with your preferred compliance frame…☆224Aug 11, 2023Updated 2 years ago
- Granular, Actionable Adversary Emulation for the Cloud☆2,252Feb 6, 2026Updated last week
- AWS IAM linting library☆1,109Jan 7, 2026Updated last month
- A graph-based tool for visualizing effective access and resource relationships in AWS environments.☆994Oct 4, 2022Updated 3 years ago
- Monitor AWS Managed IAM Policies Changes☆493Feb 9, 2026Updated last week
- ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring su…☆1,034Feb 9, 2026Updated last week
- Python installable command line utiltity for mitigation of host and key compromises.☆347Jul 23, 2021Updated 4 years ago
- Proof of concept incident response demo using SSM and AWS Fargate.☆14Dec 5, 2019Updated 6 years ago
- A catalog of services that can be publicly exposed within different cloud providers.☆14Aug 30, 2024Updated last year
- Collection of scripts and resources for DevSecOps and Automated Incident Response Security☆635Jan 14, 2026Updated last month
- AWS CloudSaga - Simulate security events in AWS☆472Updated this week
- IAM Least Privilege Policy Generator☆2,138Feb 8, 2026Updated last week
- ☆228Jan 29, 2026Updated 2 weeks ago
- Glue workflow to convert CloudTrail logs to Athena-friendly Parquet format☆48Apr 25, 2024Updated last year
- Built-in Panther detection rules and policies☆439Updated this week
- Crowdsourced list of sensitive IAM Actions☆159Oct 29, 2024Updated last year
- This command line tool counts the number of resources in different categories across Amazon regions.☆59Dec 17, 2019Updated 6 years ago
- Supplemental templates for securing the cloud.☆37Apr 1, 2025Updated 10 months ago