{"repo":"aws-solutions-library-samples/automated-forensic-orchestrator-for-amazon-ec2","free":true,"listed":false,"github":"https://github.com/aws-solutions-library-samples/automated-forensic-orchestrator-for-amazon-ec2","clone":"git clone https://github.com/aws-solutions-library-samples/automated-forensic-orchestrator-for-amazon-ec2.git","description":"Automated Forensics Orchestrator for Amazon EC2 and EKS is a self-service AWS Guidance implementation that enterprise customers can deploy to quickly set up and configure an automated orchestration workflow that enables their Security Operations Centre (SOC) to capture & examine forensic data from EKS & EC2 instances and attached volumes","language":"Python","stars":74,"topics":["automation","aws","ec2","eks","incident-response","security","forensics"],"license":"Apache-2.0","category":"workflow-automation","readme_excerpt":"Automated Forensics Orchestrator for Amazon EC2 and EKS AWS EC2 and EKS Forensics Orchestrator is a self-service Guidance implementation that enterprise customers can deploy to quickly set up and configure an automated orchestration workflow. The workflow enables the Security Operations Centre (SOC) to capture and examine data from EC2 instances or EKS Clusters, and attached volumes as evidence for forensic analysis, in the event of a potential security breach. Currently, the Guidance only supports EKS Clusters hosted on EC2 instances. Learn more about the differences for responding to EC2 and EKS security events here The Guidance orchestrates the forensics process from the point at which a threat is first detected, enable isolation of the affected EC2 instances, EKS clusters, data volumes, capture memory and disk images to secure storage, and trigger automated actions or tools for investigation and analysis of such artefacts. The Guidance notifies and reports on its progress, status, and findings, which enables SOCs to continuously discover and analyze patterns of fraudulent activities across multi-account and multi-region environments. The Guidance leverages native AWS services and is underpinned by a highly available, resilient, and serverless architecture, security, and operational monitoring features. Digital forensics is a four step process of triaging, acquisition, analysis and reporting. The automated Forensics framework provides enterprises the capability to act on a","default_branch":null,"files":null,"tree":[],"storefront":"/r/aws-solutions-library-samples","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/aws-solutions-library-samples/automated-forensic-orchestrator-for-amazon-ec2/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}