Sentinel Forge
2026AWS Cloud Detection & Response Lab
Result
Unifies CloudTrail, GuardDuty, and Security Hub findings into a single event model with playbook-driven incident summaries.
Problem
Cloud security teams often have the telemetry they need, but not the connective tissue that turns raw events into a usable incident story. The hard part is not collecting data. It is normalizing it, correlating it, explaining why a detection fired, and giving an analyst a next step that does not waste time.
Approach
Ingests CloudTrail, GuardDuty, and Security Hub samples, normalizes them into a common event model, runs defensive detections, correlates suspicious activity, and generates analyst-ready findings, timelines, and manager summaries.
Highlights
- Root account usage
- Console login without MFA
- Privileged AssumeRole
- CloudTrail tampering
- Public sensitive port exposure
- GuardDuty plus CloudTrail corroboration
$ sentinel-forge replay-findings