forestmonster / AWSLeR
AWS Live Response
☆12Updated 7 years ago
Alternatives and similar repositories for AWSLeR:
Users that are interested in AWSLeR are comparing it to the libraries listed below
- Tools for AWS forensics☆64Updated 8 years ago
- Core incident handling plugins for aws_ir cli, incident pony, and more.☆21Updated 6 years ago
- Materials used and mentioned during my talk at SANS Cloud Security Summit 2018 in San Diego☆23Updated 6 years ago
- Python module for evaluation of AWS account best practices around incident handling readieness.☆55Updated 4 years ago
- Web based analysis platform for use with the AWS_IR command line tool.☆17Updated 8 years ago
- This repository contains the research and components of our research into using Sigma for AWS Incident Response.☆27Updated last year
- A few quick recipes for those that do not have much time during the day☆22Updated 3 months ago
- defendA Data Lake. A firehose pipeline to athena providing enrichment and normalization for security events☆16Updated last year
- first commit☆20Updated last year
- A packer utility to create and capture DFIR Image for use AWS & Azure☆15Updated 5 years ago
- Build Automated Machine Images for MISP☆28Updated last year
- Indices for courses in SANS' Network Security Operations curriculum☆15Updated 9 years ago
- Materials for the BSides NoVA/Charleston 2018 Bro Workshop☆14Updated last year
- Sharing Threat Hunting runbooks☆24Updated 5 years ago
- ☆33Updated 6 years ago
- A python script to shift the timestamp on syslog data. Useful for forensicators combating time skew.☆20Updated 2 years ago
- This script is used to generate some basic detections of the aws security services☆72Updated 2 years ago
- These are some of the commands which I use frequently during Malware Analysis and DFIR.☆24Updated last year
- ☆29Updated 6 years ago
- Python bindings for Yeti's API☆18Updated last year
- Updated incident response generator for training classes☆43Updated 3 years ago
- Slides and Other Resources from my latest Talks and Presentations☆24Updated 4 years ago
- TITO is a light framework for operationalizing threat intelligence that is platform and data agnostic.☆21Updated 4 years ago
- ☆11Updated 3 years ago
- Following repository contains source codes used in my two Books.☆11Updated 9 years ago
- Performs OCR on image files and scans them for matches to YARA rules☆40Updated 6 years ago
- Duo MFA auditing tool to test users' likelihood of approving unexpected push notifications☆13Updated 6 years ago
- Powershell Scripts to work on Crowdstrike Falcon that pull back raw data relevant to forensic investigation☆22Updated last month
- ☆18Updated 3 years ago
- A collection of typical false positive indicators☆55Updated 4 years ago