Tools for performing forensics in AWS
Name | URL | Description | Popularity | Metadata |
---|---|---|---|---|
AWS IR | https://github.com/ThreatResponse/aws_ir | ThreatResponse tools to run TimeSketch against EC2 Instances | ||
Margaritashotgun | https://github.com/ThreatResponse/margaritashotgun | CollectsMemory over SSH | ||
AWS_Responder | https://github.com/prolsen/aws_responder | Disables EC2 instances, gets profile data etc. | ||
SSM-Acquire | https://github.com/mozilla/ssm-acquire | Gets memory and other via AWS's SSM Agent | ||
cloud-forensics-utils | https://github.com/google/cloud-forensics-utils | A Python library to e.g. snapshot cloud systems |