Skip to main content

Tool to assess the state of security infrastructure in Mozilla's AWS accounts

Project description

assess-mozilla-aws-security-infrastructure

This tool scans Mozilla AWS accounts checking for security infrastructure. It reports accounts which are missing elements of that infrastructure.

This includes any accounts either missing or with misconfigured

  • GuardDuty IAM Roles that the GuardDuty Multi Account Master uses to accept invitations
  • GuardDuty relationships between member and parent
  • CloudTrail
  • Security Audit IAM Roles and Incident Response IAM Roles
  • Mozilla Single Sign On (SSO)

Usage

Run assess-mozilla-aws-security-infrastructure

Future Work

Currently, the tool just prints out information. This could be improved or turned into machine-readable structured data

The tool does not assess whether there are any IAM users with passwords defined in an account that has SSO enabled (these IAM users should be removed in favor of SSO)

Project details


Release history Release notifications | RSS feed

This version

1.0

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

Built Distribution

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page