Skip to content

OpenSecOps - AWS Security Automation Platform

OpenSSF Best Practices

Welcome to OpenSecOps! This platform provides enterprise-grade security automation for AWS environments through two main products: Foundation and SOAR. Some components have been open-source for a long time and can be used stand-alone.

All products have passed stringent AWS Foundational Technical Reviews and are battle-tested and in active use in the industry.

Products

Foundation

Cloud infrastructure foundation implementing AWS best practices with features including:

  • AWS Control Tower integration
  • Centralized logging and archival
  • Text-based AWS configuration management
  • Single Sign-On (SSO) with multi-factor authentication
  • Just-In-Time (JIT) elevated access management

SOAR (Security Orchestration, Automation, and Response)

Security automation platform with serverless architecture including:

  • AWS Security Hub integration
  • Automated incident response with predefined playbooks
  • Forensic analysis capabilities
  • Ticketing system integration (Jira, ServiceNow)
  • AI-powered security reporting

Getting Started

To install OpenSecOps, clone the Installer repository and follow the instructions in its README.

Documentation

Comprehensive documentation is available in the Documentation repository, including:

Foundation Documentation

SOAR Documentation

Governance and contribution

OpenSecOps is open source under MPL-2.0. The contribution model is a cathedral, not a bazaar: a small core team curates the codebase, and external pull requests are not accepted on any repository. The Trust page explains why; CONTRIBUTING.md covers the operational details.

What is welcomed:

  • Bug reports for non-security defects — public, accepted, and acknowledged. Use the bug report template on the affected component repository.
  • Vulnerability reports — via the GitHub Security Advisory flow ("Report a vulnerability") on the affected repository. Fallback channel: security@opensecops.org. Reporters receive named credit per the coordinated-disclosure timeline in each component's SECURITY.md.
  • Forking under MPL-2.0 — permitted by the licence; no coordination needed.

Reference documents (all in the OpenSecOps-Org/.github special repository):

Website

Visit our website at https://opensecops.org for product information and stakeholder-focused material. The Trust page is the entry point to the supply-chain posture, governance model, and verification artefacts attached to every release.

Mailing List

The OpenSecOps newsletter provides updates on our open-source AWS security and operations platform. Subscribe to receive announcements about new features, security best practices, implementation tips, and community contributions. We'll share insights about both our Foundation (AWS infrastructure best practices) and SOAR (security automation) components, along with practical guidance for deploying and managing secure cloud environments. This low-volume newsletter helps you stay informed about this project that reduces AWS setup from person-years to just days.

https://buttondown.com/opensecops

Pinned Loading

  1. Foundation-control-tower-log-aggregator Foundation-control-tower-log-aggregator Public

    SAM project to combine small daily log files into larger daily log files, to make it possible to store them in Glacier without extra overhead and avoiding prohibitive costs. AWS Control Tower is re…

    Shell 1

  2. Foundation-CloudWatch2S3 Foundation-CloudWatch2S3 Public

    Logging infrastructure for exporting all CloudWatch logs from multiple accounts to single regional buckets in the Log Archive account.

    Shell 2

  3. SOAR-SAM-Automating-Forensic-Disk-Collection SOAR-SAM-Automating-Forensic-Disk-Collection Public

    This is a SAM repackaging of Logan Bair's forensic disk collection automation as implemented for Goldman Sachs.

    Shell 1

  4. Foundation-AWS-Core-SSO-Configuration Foundation-AWS-Core-SSO-Configuration Public

    Utility to manage AWS SSO Permission Sets, SSO Groups, and their assignments to AWS accounts from declarative YAML configuration files.

    Shell 1

  5. AFT-SSO-account-configuration AFT-SSO-account-configuration Public

    Forked from PeterBengtson/AFT-SSO-account-configuration

    Allows you to use AFT (Account Factory for Terraform) to declaratively specify SSO Group and SSO User access to an account.

    Python 1

  6. AFT-DNS-subdomain-delegation AFT-DNS-subdomain-delegation Public

    Forked from PeterBengtson/AFT-DNS-subdomain-delegation

    Allows you to use AFT (Account Factory for Terraform) to declaratively specify subdomain delegations from a central networking account to individual member accounts in a declarative way.

    Python 2

Repositories

Showing 10 of 33 repositories
  • SOAR Public

    Security Orchestration, Automation, and Response platform for AWS with security findings processing and incident management.

    OpenSecOps-Org/SOAR's past year of commit activity
    Python 6 MPL-2.0 0 0 0 Updated Sep 8, 2026
  • Installer Public

    This is the installer for Foundation and SOAR. It is used to prepare your workspace, check that you have installed all prerequisites, download all repos required, and then build, install, and/or update them.

    OpenSecOps-Org/Installer's past year of commit activity
    Shell 2 MPL-2.0 1 0 0 Updated Sep 8, 2026
  • SOAR-soc-incident-when-s3-tag-applied Public

    Creates security incidents when specific tags are missing from S3 buckets.

    OpenSecOps-Org/SOAR-soc-incident-when-s3-tag-applied's past year of commit activity
    Shell 1 MPL-2.0 0 0 0 Updated May 13, 2026
  • SOAR-sec-hub-role Public

    Establishes cross-account access roles for Security Hub management.

    OpenSecOps-Org/SOAR-sec-hub-role's past year of commit activity
    Shell 1 MPL-2.0 0 0 0 Updated May 13, 2026
  • SOAR-sec-hub-configuration Public

    Configures AWS Security Hub with customized event handling for optimal security monitoring.

    OpenSecOps-Org/SOAR-sec-hub-configuration's past year of commit activity
    Shell 1 MPL-2.0 0 0 0 Updated May 13, 2026
  • SOAR-SAM-Automating-Forensic-Disk-Collection Public

    This is a SAM repackaging of Logan Bair's forensic disk collection automation as implemented for Goldman Sachs.

    OpenSecOps-Org/SOAR-SAM-Automating-Forensic-Disk-Collection's past year of commit activity
    Shell 1 MPL-2.0 0 0 0 Updated May 13, 2026
  • SOAR-detect-stack-drift Public

    Detects and reports drift in CloudFormation stacks for infrastructure governance.

    OpenSecOps-Org/SOAR-detect-stack-drift's past year of commit activity
    Shell 1 MPL-2.0 0 0 0 Updated May 13, 2026
  • SOAR-detect-log-buckets Public

    Identifies S3 buckets containing application, load-balancer, or CloudFront log files and replicates them to the Log Archive account.

    OpenSecOps-Org/SOAR-detect-log-buckets's past year of commit activity
    Shell 1 MPL-2.0 0 0 0 Updated May 13, 2026
  • SOAR-all-alarms-to-sec-hub Public

    Forwards CloudWatch alarms to Security Hub for centralized security monitoring.

    OpenSecOps-Org/SOAR-all-alarms-to-sec-hub's past year of commit activity
    Python 1 MPL-2.0 0 0 0 Updated May 13, 2026
  • Foundation-service-control-policies Public

    Manages Service Control Policies (SCPs) for AWS Organizations.

    OpenSecOps-Org/Foundation-service-control-policies's past year of commit activity
    Shell 1 MPL-2.0 0 0 0 Updated May 13, 2026

Top languages

Loading…

Most used topics

Loading…