Amazon Security Lake icon

Amazon Security Lake

Provides structured access to OCSF-normalized security data in Amazon Security Lake for querying via AWS Athena.

About

The Amazon Security Lake tool acts as a Model Context Protocol (MCP) server, enabling powerful queries against your AWS Security Lake data using Athena. It transforms raw security logs into an OCSF-normalized format, making it easy for AI assistants and applications to search for critical information like IP addresses, GuardDuty findings, and to discover available data sources. This seamless integration with AWS services provides a secure and efficient way to analyze your cybersecurity posture, ensuring input validation, query sanitization, and least-privilege access.

Key Features

  • Built-in OCSF (Open Cybersecurity Schema Framework) schema validation
  • Query GuardDuty security findings with filtering by ID, severity, and type
  • Seamless integration with AWS Athena, S3, and IAM
  • List and analyze available Security Lake data sources and tables
  • Search for IP addresses across Security Lake data sources
  • 0 GitHub stars

Use Cases

  • Enabling AI assistants and applications to query and analyze security data
  • Investigating security incidents by searching for specific IP addresses or findings
  • Discovering and understanding the available security log sources within Amazon Security Lake
Amazon Security Lake: AI-Powered Security Data Query via Athena