Cloud Sniper is a platform designed to manage Cloud Security Operations, intended to respond to security incidents by accurately analyzing and correlating cloud artifacts. It is meant to be used as a Cloud Security Operations platform to detect and remediate security incidents by showing a complete visibility of the company's cloud security posture.
We are presenting a centralized Incident and Response platform, which executes automatic actions, by learning from the analysts' expert knowledge. To do it, only native cloud artifacts and open source technologies are implemented. In this way, the community can extend the project with different security use cases.
Cloud Sniper receives and processes security feeds, providing an automatic response mechanism to protect the cloud infrastructure. To detect attackers' advanced TTPs, Cloud Sniper Analytics module correlates IOCs providing enhanced security findings to the security analyst.
With this platform, you get a complete and comprehensive management system of the security incidents. At the same time, an advanced security analyst can integrate Cloud Sniper with external forensic or incident-and-response tools to ingest new security feeds. The platform automatically deploys and provides cloud-based integration with all native resources, in a fully modularized manner, making it very easy to extend for the community.
The system is currently available for AWS, but it is to be extended to others cloud platforms.
- Security automation (multi-account|multi-region)
- Incident and Response automation
- IAM activity
- Cloud Sniper Analytics
- Enhanced lambda for C2 detection
- ELK
- Incident and Response pipeline
- Incident and Response dashboard templates
- Messaging|Alerts
- Slack
- Security automation
- Dangling DNS records automation
- Open|orphans security groups automation
- Cloud Sniper Analytics
- CloudTrail IAM analytics
- ELK
- Cloud Sniper Kibana application
- New security dashboards
- Open Distro alerting
Authors:
Nicolás Rivero Corvalán - Security Automation
Matías Marenchino - Security Analytics
Authors:
Nicolás Rivero Corvalán - Security Automation
Matías Marenchino - Security Analytics
Santiago Friquet - Security Automation
If you wish to support this project you can donate bitcoins (BTC) here: 14WRfmMhQS5auzFAhzfaBW9niqy1QF3Pdw
This project is licensed under the terms of the MIT license.