Dow Jones Hammer is a multi-account cloud security tool for AWS. It identifies misconfigurations and insecure data exposures within most popular AWS resources, across all regions and accounts. It has near real-time reporting capabilities (e.g. JIRA, Slack) to provide quick feedback to engineers and can perform auto-remediation of some misconfigurations. This helps to protect products deployed on cloud by creating secure guardrails.
Dow Jones Hammer documentation is available via GitHub Pages at https://dowjones.github.io/hammer/.
- Insecure Services
- S3 ACL Public Access
- S3 Policy Public Access
- IAM User Inactive Keys
- IAM User Keys Rotation
- CloudTrail Logging Issues
- EBS Unencrypted Volumes
- EBS Public Snapshots
- RDS Public Snapshots
- Python 3.6
- AWS (Lambda, Dynamodb, EC2, SNS, CloudWatch, CloudFormation)
- Terraform
- JIRA
- Slack
Feel free to create issue report, pull request or just email us at [email protected] with any other questions or concerns you have.