Provenience

An Alternative Console for AWS Config with CloudTrail and SecurityHub Context

AWS Config is a rich data source, often enabled for compliance yet underutilized in organizations. If you have ever had to pivot from account to account and region to region using the Config console or custom scripting you will understand. Config Aggregator solves some of the region and account pivot problems, but requires SQL knowledge, additional setup, and doesn’t include deleted items.

If you have AWS CLI access and can assume a role with SecurityAuditRole privileges, give Provenience a free try!

Selecting a profile and specifying a role will populate AWS account IDs using AWS Organizations API or the account to which your profile is currently authenticated. Provenience will identify the regions and resource types available and provide a simple interface for generating reports for export or analyzing specific resources, relationships, SecurityHub findings and Cloudtrail activity.

Dynamically analyze relationships and derive resource context using the Plotly Dash Cytoscape visualization to expand the diagram as you interact with resources…

Assess resource security and compliance status via SecurityHub and Config Rules…

Provenience currently supports MacOS and installs locally, leveraging your existing AWS CLI credentials. If you struggle with AWS inventory management, identifying security issues or waste and you have AWS Config enabled give it a try for free today at https://store.cloudarchaeologist.com!