jonrau1 / AWS-DevSecOps-Factory
Sample DevSecOps pipelines (heavily biased on the "Sec") for various stacks and tools using open-source security tools and AWS native services
☆67Updated 3 years ago
Related projects ⓘ
Alternatives and complementary repositories for AWS-DevSecOps-Factory
- Code examples for the AWS Security Blog post: How to use CI/CD to deploy and configure AWS security services with Terraform☆95Updated 3 years ago
- AWS Certified Security Specialty (2020) course notes☆115Updated 4 years ago
- ThreatModel for Amazon S3 - Library of all the attack scenarios on Amazon S3, and how to mitigate them following a risk-based approach☆151Updated last year
- AWS Organizations Service Control Policies (SCPs) written in HashiCorp Terraform.☆232Updated last month
- Pre-configured response & remediation playbooks for AWS Security Hub☆65Updated 3 years ago
- Identify all permitted data paths originating from the Internet to Network Interfaces within AWS Accounts across the entire AWS Organizat…☆36Updated last year
- AWS Security Analytics Bootstrap enables customers to perform security investigations on AWS service logs by providing an Amazon Athena a…☆238Updated this week
- ☆17Updated last year
- This solutions facilitates rapid deployment of Prowler, full AWS Organization analysis, and finding processing as part of a security post…☆54Updated 3 months ago
- Safer AWS SCP deployments via real-time monitoring☆43Updated last year
- ☆109Updated this week
- A docker container to simplify and secure the use of Infrastructure as Code (IaC)☆68Updated this week
- Crowdsourced list of sensitive IAM Actions☆139Updated 3 weeks ago
- Example policies demonstrating how to implement a data perimeter on AWS.☆125Updated last week
- The Amazon Elastic Kubernetes Service (EKS) Creation Engine (ECE) is a Python command-line program created by the Lightspin Office of the…☆40Updated last year
- ☆26Updated 4 years ago
- A collection of 2020 artifacts describing the major pain points, vulnerabilities and concerns with Cloud Security.☆19Updated 3 years ago
- ☆84Updated 9 months ago
- Assisted Log Enabler for AWS - Find AWS resources that are not logging, and turn them on.☆225Updated this week
- Create custom auto-remediation solutions using serverless functions in the cloud.☆53Updated last year
- SCP management tool☆126Updated last year
- Scripts to quickly fix security and compliance issues☆104Updated 11 months ago
- ☆37Updated 10 months ago
- ☆133Updated last month
- Prevent SSRF attacks on AWS EC2 via automated upgrades to the more secure Instance Metadata Service v2 (IMDSv2).☆138Updated 8 months ago
- Convert cloudtrail data to MITRE ATT&CK Sightings☆79Updated 2 years ago
- Example AWS Service control policies to get started or mature your usage of AWS SCPs.☆223Updated 6 months ago
- CloudSplaining on AWS Managed Policies☆41Updated this week