cwe-monitor-secgrp

Permission checker

A CloudWatch Events rule Lambda function that checks security group permissions against a pre-configured policy and logs non-compliant changes.

This CloudWatch Events rule Lambda function evaluates AWS API calls that change Amazon EC2 security group ingress rules. The function flags rules that violate a preconfigured policy.

GitHub

25 stars
58 watching
30 forks
Language: Python
last commit: almost 7 years ago
Linked from 1 awesome list


Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
awslabs/amazon-inspector-auto-remediateAutomatically patches vulnerable EC2 instances after receiving an Inspector assessment notification58
awslabs/amazon-inspector-agent-autodeployAutomates deployment of security agent to newly launched EC2 instances using AWS Lambda and SSM28
awslabs/amazon-inspector-finding-forwarderScript to process and forward Amazon Inspector findings via SNS to a specified email address.39
salesforce/aws-allowlisterAutomatically generates AWS Service Control Policies based on compliance frameworks and custom service inclusions/exclusions224
rafalwilinski/cloudwatch-public-metricsExposes AWS Cloudwatch Metrics as a public HTML page using AWS Lambda and server-side rendering28
nccgroup/s3_objects_checkIdentifies publicly accessible objects in an AWS S3 bucket based on effective permissions75
aws-samples/lambda-ecs-worker-patternThis code example illustrates how to extend AWS Lambda functionality using Amazon SQS and the Amazon EC2 Container Service (ECS) to process large tasks outside of Lambda's execution time limit.290
awslabs/aws-security-automationAutomated incident response and security remediation tools for AWS services620
awslabs/aws-lambda-redshift-loaderAn AWS Lambda function that automates data loading from Amazon S3 into an Amazon Redshift database cluster597
cyberark/skywrapperDetects suspicious temporary token usage in an AWS account to identify potential security threats.104
shimat/opencvsharp_awslambdasampleA proof-of-concept project demonstrating the use of OpenCvSharp in an AWS Lambda function.3
portswigger/aws-security-checksA set of automated security checks for AWS services written in Python to identify potential vulnerabilities and configuration issues.36
salesforce/cloudsplainingA tool that scans AWS IAM policies to identify security vulnerabilities and generates a report with recommendations for remediation2,009
aws-solutions/aws-waf-security-automationsAutomates deployment of AWS WAF security rules to protect against common web-based attacks863
aws-cloudformation/cloudformation-guardAn evaluation tool for policy-as-code in infrastructure configuration files1,309