Skip to content

OpenSecOps - AWS Security Automation Platform

Welcome to OpenSecOps! This platform provides enterprise-grade security automation for AWS environments through two main products: Foundation and SOAR. Some components have been open-source for a long time and can be used stand-alone.

All products have passed stringent AWS Foundational Technical Reviews and are battle-tested and in active use in the industry.

Products

Foundation

Cloud infrastructure foundation implementing AWS best practices with features including:

  • AWS Control Tower integration
  • Centralized logging and archival
  • Text-based AWS configuration management
  • Single Sign-On (SSO) with multi-factor authentication
  • Just-In-Time (JIT) elevated access management

SOAR (Security Orchestration, Automation, and Response)

Security automation platform with serverless architecture including:

  • AWS Security Hub integration
  • Automated incident response with predefined playbooks
  • Forensic analysis capabilities
  • Ticketing system integration (Jira, ServiceNow)
  • AI-powered security reporting

Getting Started

To install OpenSecOps, clone the Installer repository and follow the instructions in its README.

Documentation

Comprehensive documentation is available in the Documentation repository, including:

Foundation Documentation

SOAR Documentation

Community Resources

Website

Visit our website at https://opensecops.org for additional information, including technical details and stakeholder-focused material.

Mailing List

The OpenSecOps newsletter provides updates on our open-source AWS security and operations platform. Subscribe to receive announcements about new features, security best practices, implementation tips, and community contributions. We'll share insights about both our Foundation (AWS infrastructure best practices) and SOAR (security automation) components, along with practical guidance for deploying and managing secure cloud environments. This low-volume newsletter helps you stay informed about this project that reduces AWS setup from person-years to just days.

https://buttondown.com/opensecops

Pinned Loading

  1. Foundation-control-tower-log-aggregator Foundation-control-tower-log-aggregator Public

    SAM project to combine small daily log files into larger daily log files, to make it possible to store them in Glacier without extra overhead and avoiding prohibitive costs. AWS Control Tower is re…

    Python 1

  2. Foundation-CloudWatch2S3 Foundation-CloudWatch2S3 Public

    Logging infrastructure for exporting all CloudWatch logs from multiple accounts to single regional buckets in the Log Archive account.

    Python 2

  3. SOAR-SAM-Automating-Forensic-Disk-Collection SOAR-SAM-Automating-Forensic-Disk-Collection Public

    This is a SAM repackaging of Logan Bair's forensic disk collection automation as implemented for Goldman Sachs.

    Python 1

  4. Foundation-AWS-Core-SSO-Configuration Foundation-AWS-Core-SSO-Configuration Public

    Utility to manage AWS SSO Permission Sets, SSO Groups, and their assignments to AWS accounts from declarative YAML configuration files.

    Python 1

  5. AFT-SSO-account-configuration AFT-SSO-account-configuration Public

    Forked from PeterBengtson/AFT-SSO-account-configuration

    Allows you to use AFT (Account Factory for Terraform) to declaratively specify SSO Group and SSO User access to an account.

    Python 1

  6. AFT-DNS-subdomain-delegation AFT-DNS-subdomain-delegation Public

    Forked from PeterBengtson/AFT-DNS-subdomain-delegation

    Allows you to use AFT (Account Factory for Terraform) to declaratively specify subdomain delegations from a central networking account to individual member accounts in a declarative way.

    Python 2

Repositories

Showing 10 of 33 repositories

Top languages

Loading…

Most used topics

Loading…