{"id":13625154,"url":"https://github.com/zoph-io/aws-security-survival-kit","last_synced_at":"2026-04-09T03:36:24.512Z","repository":{"id":59873507,"uuid":"538983541","full_name":"zoph-io/aws-security-survival-kit","owner":"zoph-io","description":"Bare minimum AWS Security Alerting and Secure by default Configuration","archived":false,"fork":false,"pushed_at":"2025-05-15T08:53:35.000Z","size":773,"stargazers_count":491,"open_issues_count":9,"forks_count":41,"subscribers_count":19,"default_branch":"main","last_synced_at":"2025-05-15T09:41:48.602Z","etag":null,"topics":["alerting","aws","observability","security"],"latest_commit_sha":null,"homepage":"https://bio.link/zoph","language":"Makefile","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/zoph-io.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2022-09-20T12:43:15.000Z","updated_at":"2025-05-15T08:53:39.000Z","dependencies_parsed_at":"2023-02-14T14:46:28.863Z","dependency_job_id":"7da2204b-afdf-4bb7-b0a7-b081a0deef4a","html_url":"https://github.com/zoph-io/aws-security-survival-kit","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/zoph-io/aws-security-survival-kit","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/zoph-io%2Faws-security-survival-kit","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/zoph-io%2Faws-security-survival-kit/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/zoph-io%2Faws-security-survival-kit/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/zoph-io%2Faws-security-survival-kit/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/zoph-io","download_url":"https://codeload.github.com/zoph-io/aws-security-survival-kit/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/zoph-io%2Faws-security-survival-kit/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":31584809,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-04-08T14:31:17.711Z","status":"online","status_checked_at":"2026-04-09T02:00:06.848Z","response_time":112,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["alerting","aws","observability","security"],"created_at":"2024-08-01T21:01:51.424Z","updated_at":"2026-04-09T03:36:24.507Z","avatar_url":"https://github.com/zoph-io.png","language":"Makefile","funding_links":[],"categories":["Makefile"],"sub_categories":[],"readme":"# 🚑 AWS Security Survival Kit\n\n## :brain: Rationale\n\nThe AWS Security Survival Kit (ASSK) helps you monitor and get alerts about suspicious activities in your AWS account.\n\nWhile [CloudTrail](https://aws.amazon.com/cloudtrail/) is essential for tracking AWS account activities, it doesn't provide automatic alerts. you need to manually check logs across multiple services and the console to spot issues.\n\nThis kit uses CloudFormation templates to set up proactive security monitoring and alerting. it works alongside GuardDuty to fill the gap of missing built-in alerts.\n\n## ✅ Secure by default\n\nThis kit enables several important security configurations in your aws account by default:\n\n1. Automatic encryption for all ebs volumes (per region)\n2. Account-wide s3 block public access\n3. Prevention of public ami sharing (per region) - [Annoncement](https://aws.amazon.com/about-aws/whats-new/2023/10/ami-block-public-enabled-aws-accounts-no-public-amis/)\n4. Prevention of public snapshot sharing (per region) - [Blogpost](https://aws.amazon.com/blogs/aws/new-block-public-sharing-of-amazon-ebs-snapshots/)\n5. IMDSv2 requirement for new instances (per region) - [Annoncement](https://aws.amazon.com/about-aws/whats-new/2024/03/set-imdsv2-default-new-instance-launches/)\n\n## 💾 Suspicious Activities\n\nUsing this kit, you will deploy EventBridge (CloudWatch Event) Rules and CloudWatch Metric Filters and Alarms on following suspicious activities. It comes with CloudWatch Dashboards to give you more insights about what is ringing 🔔\n\nThe following suspicious activities are currently supported:\n\n1. Root User activities\n2. CloudTrail changes (`StopLogging`, `DeleteTrail`, `UpdateTrail`)\n3. AWS Personal Health Dashboard Events\n4. IAM Users Changes (`Create`, `Delete`, `Update`, `CreateAccessKey`, `UpdateLoginProfile`, etc..)\n5. IAM Suspicious Activities (`Attach*Policy`) with `AdministratorAccess` Managed IAM Policy\n6. MFA Monitoring (`CreateVirtualMFADevice` `DeactivateMFADevice` `DeleteVirtualMFADevice`, etc..)\n7. Unauthorized Operations (`Access Denied`, `UnauthorizedOperation`)\n8. Failed AWS Console login authentication (`ConsoleLoginFailures`)\n9. EBS Snapshots Exfiltration (`ModifySnapshotAttribute`, `SharedSnapshotCopyInitiated` `SharedSnapshotVolumeCreated`)\n10. AMI Exfiltration (`ModifyImageAttribute`)\n11. Who Am I Calls (`GetCallerIdentity`)\n12. IMDSv1 RunInstances (`RunInstances` \u0026\u0026 `optional` http tokens)\n13. CloudShell Exfiltration (`GetFileDownloadUrls`)\n14. KMS Key Changes (`DisableKey`, `ScheduleKeyDeletion`, `DeleteAlias`, `DisableKeyRotation`)\n15. Security Group Changes (`AuthorizeSecurityGroupIngress`, `RevokeSecurityGroupIngress`, `AuthorizeSecurityGroupEgress`, `RevokeSecurityGroupEgress`)\n16. AWS Config Changes (`StopConfigurationRecorder`, `DeleteConfigurationRecorder`, `DeleteConfigRule`, `DeleteEvaluationResults`)\n17. EC2 Password Data Retrieval (`GetPasswordData`)\n18. Secrets Manager Batch Retrieval (`BatchGetSecretValue`)\n19. Route53 DNS Logging Changes (`DeleteResolverQueryLogConfig`)\n20. VPC Flow Logs Changes (`DeleteFlowLogs`, `ModifyFlowLogs`)\n21. Security Group Admin Ports Exposure (`AuthorizeSecurityGroupIngress` with ports 22/3389 from 0.0.0.0/0)\n22. IAM Roles Anywhere Changes (`CreateProfile`, `CreateTrustAnchor`)\n23. STS Federation Token Creation (`GetFederationToken`)\n\n## :keyboard: Usage\n\n### Parameters\n\n- `AlarmRecipient`: Recipient for the alerts (e.g.: hello@zoph.io)\n- `Project`: Name of the Project (e.g.: aws-security-survival-kit)\n- `Description`: Description of the Project (e.g.: Bare minimum ...)\n- `LocalAWSRegion`: Region where your workloads and CloudTrail are located (e.g.: `eu-west-1`)\n- `CTLogGroupName`: Cloudtrail CloudWatch LogGroup name (**Required**)\n\nSetup the correct parameters in the `Makefile`, then run the following command:\n\n    $ make deploy\n\n### 📫 Notifications\n\n\u003e You will receive alerts by emails sent by SNS Topic\n\n![Email Notification](./assets/notification.png)\n\n### :robot: ChatOps\n\nSetup [AWS Chatbot](https://aws.amazon.com/chatbot/) for best experience to get notified directly on Slack.\n\n### 📈 Dashboards\n\nASSK comes with two CloudWatch Dashboards (Local and Global) to bring better visibility on suspicious activities on your AWS Account.\n\n## :man_technologist: Credits\n\n- 🏴‍☠️ AWS Security Boutique: [zoph.io](https://zoph.io)\n- 🦋 BlueSky: [@zoph](https://bsky.app/zoph.me)\n- 🐦 X: [@zoph](https://x.com/zoph)\n\n## 🌧️ Other Initiatives\n\n- [Microsoft Azure](https://github.com/O3-Cyber/azure-security-survival-kit) from folks @[O3 Cyber](https://www.o3c.no/)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fzoph-io%2Faws-security-survival-kit","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fzoph-io%2Faws-security-survival-kit","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fzoph-io%2Faws-security-survival-kit/lists"}