Our continuous efforts to improve our monitoring and threathunting capabilities in the AWS cloud
Each folder/sub-project contains its own Readme.md
- Sends alarms from Cloudwatch to Slack via Lambda function
- Monitors role credentials leakage from:
- CloudTrail logs in ELK stack
- Account ENIs and EIPs
- Lambda function that periodically checks if AWS API calls have been made from honey tokens/fake users and alerts on Slack
- Gathers threat intelligence for bad reputed IPs from VPC flow logs