├── CODE_OF_CONDUCT.md ├── CONTRIBUTING.md ├── LICENSE ├── Playbooks ├── IAM Credential Compromise │ ├── credential-compromise-analysis.ipynb │ └── credential-compromise-containment.ipynb └── README.md ├── README.md ├── SQL Query Library ├── README.md └── Security Lake Queries │ └── GuardDuty-findings.sql ├── Security Lake Playbooks ├── GuardDuty Findings Analysis │ └── guardduty-analysis.ipynb └── S3 Ransomware Response │ └── s3-ransomware-response.ipynb └── cfn-templates └── jupyter-analysis-instance.yml /CODE_OF_CONDUCT.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/aws-samples/jupyter-notebook-for-incident-response/HEAD/CODE_OF_CONDUCT.md -------------------------------------------------------------------------------- /CONTRIBUTING.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/aws-samples/jupyter-notebook-for-incident-response/HEAD/CONTRIBUTING.md -------------------------------------------------------------------------------- /LICENSE: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/aws-samples/jupyter-notebook-for-incident-response/HEAD/LICENSE -------------------------------------------------------------------------------- /Playbooks/IAM Credential Compromise/credential-compromise-analysis.ipynb: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/aws-samples/jupyter-notebook-for-incident-response/HEAD/Playbooks/IAM Credential Compromise/credential-compromise-analysis.ipynb -------------------------------------------------------------------------------- /Playbooks/IAM Credential Compromise/credential-compromise-containment.ipynb: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/aws-samples/jupyter-notebook-for-incident-response/HEAD/Playbooks/IAM Credential Compromise/credential-compromise-containment.ipynb -------------------------------------------------------------------------------- /Playbooks/README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/aws-samples/jupyter-notebook-for-incident-response/HEAD/Playbooks/README.md -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/aws-samples/jupyter-notebook-for-incident-response/HEAD/README.md -------------------------------------------------------------------------------- /SQL Query Library/README.md: -------------------------------------------------------------------------------- 1 | -------------------------------------------------------------------------------- /SQL Query Library/Security Lake Queries/GuardDuty-findings.sql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/aws-samples/jupyter-notebook-for-incident-response/HEAD/SQL Query Library/Security Lake Queries/GuardDuty-findings.sql -------------------------------------------------------------------------------- /Security Lake Playbooks/GuardDuty Findings Analysis/guardduty-analysis.ipynb: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/aws-samples/jupyter-notebook-for-incident-response/HEAD/Security Lake Playbooks/GuardDuty Findings Analysis/guardduty-analysis.ipynb -------------------------------------------------------------------------------- /Security Lake Playbooks/S3 Ransomware Response/s3-ransomware-response.ipynb: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/aws-samples/jupyter-notebook-for-incident-response/HEAD/Security Lake Playbooks/S3 Ransomware Response/s3-ransomware-response.ipynb -------------------------------------------------------------------------------- /cfn-templates/jupyter-analysis-instance.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/aws-samples/jupyter-notebook-for-incident-response/HEAD/cfn-templates/jupyter-analysis-instance.yml --------------------------------------------------------------------------------