AWS IReveal is a Model Context Protocol (MCP) server that empowers security teams and incident responders with a centralized interface to various AWS services crucial for investigation. By integrating with an MCP client like Claude Desktop, it facilitates seamless querying and analysis across CloudTrail, Amazon Athena, CloudWatch, Amazon GuardDuty, AWS Config, VPC Flow Logs, Network Access Analyzer, and IAM Access Analyzer, all within your LLM-driven workspace. This consolidation streamlines incident response workflows and enables faster, more comprehensive analysis of security events within your AWS infrastructure.
主要功能
01Integrates with CloudTrail for API activity logging analysis.
02Enables SQL queries over CloudTrail logs via Amazon Athena.
03Supports operational log search and visualization through CloudWatch and VPC Flow Logs.
04Surfaces security alerts from Amazon GuardDuty and IAM Access Analyzer.
05Allows verification of network reachability and configuration using Network Access Analyzer.
062 GitHub stars