// cat ./projects/aws-ir-automation.md
AWS Incident Response Automation
Event-Driven Containment with Lambda + CloudWatch
Serverless incident response workflows that enrich, classify, and contain cloud security events automatically — collapsing manual triage from minutes to seconds.
## Problem
Cloud security alerts arrived in chat with no context. Analysts spent the first ten minutes of every incident gathering the same enrichment from the console.
## Pipeline
CloudWatch and EventBridge route security events to Lambda enrichers that pull IAM context, network exposure, and tag metadata. High-confidence events trigger containment actions — SG isolation, key revocation, snapshot for forensics — before paging humans.
## Outcome
Materially lower MTTR, fewer late-night pages for noise, and a repeatable serverless pattern other teams reuse for their own event sources.
// ls ../
FLAGSHIP
Snock →
Autonomous Cloud Security AI Agent
RESEARCH
SpecterHeal →
AI-Assisted Self-Healing Infrastructure
PRODUCTION
Enterprise DDoS Defense →
AWS Shield Advanced & Firewall Manager Automation
PRODUCTION
Hardened GitLab DevSecOps Platform →
Secure CI/CD with Terraform, tfsec, Trivy, SonarQube
ENGAGEMENT
Trend Micro XDR Remediation →
Enterprise Endpoint Detection & Response Tuning
PRODUCTION
SOC Automation & Visualization →
TheHive + Elasticsearch + Grafana + n8n
PRODUCTION
Fortinet SD-WAN Deployment →
Resilient Multi-Site Connectivity
INTERNAL
CTF Training Platform →
Practical Cybersecurity Training Lab
PRODUCTION
Cloud Monitoring & Observability Platform →
Terraform, ECS Fargate, cross-account CloudWatch
DELIVERED
CIS Benchmark & Remediation Program →
Measured posture improvement across a DevOps platform
DELIVERED
Open Banking Auth Flow Load Testing →
k6, mTLS, FAPI/OAuth2 with PAR, browser-driven SCA