This project sets up partitioned Athena tables for your CloudTrail logs and updates the partitions nightly. As new AWS accounts begin sending you logs or new AWS regions come online, your paritions will always be up-to-date. It is based on work by Alex Smolen in his post Partitioning CloudTrail…
The main features of duo-labs/cloudtrail-partitioner are: Incident Response Tools.
Open-source alternatives to duo-labs/cloudtrail-partitioner include: ansorren/gdpatrol — A Lambda-powered Security Orchestration framework for AWS GuardDuty. awslabs/aws-security-automation — Collection of scripts and resources for DevSecOps and Automated Incident Response Security. damienjburks/datacop — Protect your data in AWS S3 with DataCop! easttimor/aws-incident-response — Investigation of API activity using Athena and notification of actions using EventBridge. endgameinc/aws-logsearch — Search AWS CloudWatch logs all at once on the command line. This uses the aws sdk-for-go. See Configuring Credentials… andrewkrug/fargate-ir — Proof of concept incident response demo using SSM and AWS Fargate.
A Lambda-powered Security Orchestration framework for AWS GuardDuty
Collection of scripts and resources for DevSecOps and Automated Incident Response Security
Proof of concept incident response demo using SSM and AWS Fargate.