Skip to content
@FogSecurity

Fog Security

Fog Security

Welcome to Fog Security, where we're working to bring clarity to cloud encryption and build better data perimeters.

Check out our resources:

Encryption and Data Perimeters in AWS Tooling

We've created the following resources to help with understanding encryption and improving cloud security by building data perimeters.

AWS Default Encryption Tracker

This repository tracks default encryption settings across AWS resources. In our research of 50+ resources across 40+ AWS services, resources were found to either be unencrypted, default encrypted with AWS owned keys, or default encrypted with AWS managed keys.

Read more in our blog post here: https://www.fogsecurity.io/blog/are-my-aws-resources-encrypted-or-unencrypted-by-default
Repository: https://github.com/FogSecurity/aws-default-encryption-tracker

Finders Keypers (AWS KMS Key Usage Finder)

This open source CLI python tool helps determine blast radius and usage of AWS KMS Keys. Currently, this is difficult to do and requires custom tooling or incomplete searches through CloudTrail and IAM references in KMS key policies and KMS key grants. Finders Keypers is a tool built that checks service resources via boto3 API calls to better understand current usage of KMS keys for encryption.

Read more in our blog post here: https://www.fogsecurity.io/blog/introducing-finders-keypers-a-tool-to-discover-usage-and-blast-radius-of-encryption-keys-in-aws
Repository: https://github.com/FogSecurity/finders-keypers

IAM References for AWS Data Perimeters

This repository contains multiple IAM references including:

Organizational Resource Control Policies (RCPs) and Service Control Policies (SCPs) for AWS

These reference policies help with creating data perimeters and improving cloud security within your AWS Organization at scale. These policies protect resources and can also limit potential actions taken by IAM principals within your AWS Organization and AWS accounts within.

IAM Actions to update encryption for existing AWS resources

This is helpful to help prevent against ransomware, as a cloud ransomware technique is to hold data hostage by changing encryption keys. This also aids in teams who need to update or manage encryption for existing AWS resources. This repository details the IAM actions required to update encryption for cloud resources that support encryption update and details which cloud resources do not support updating in place and thus need to be recreated.

Read more in our blog posts here:

Repository: https://github.com/FogSecurity/aws-data-perimeter-iam

AWS Managed Keys Tracker

This tool checks which AWS Services support AWS Managed Keys, a type of KMS Encryption Key where the encryption key is managed by AWS, but exists only within the customer AWS Account. Additionally, the tool pulls the managed key policies and uploads them to a repository for reference.

Read more in our blog post here: https://www.fogsecurity.io/blog/encryption-aws-managed-kms-keys
Repository: https://github.com/FogSecurity/aws-managed-kms-keys

Popular repositories Loading

  1. aws-default-encryption-tracker aws-default-encryption-tracker Public

    Tracker for Encryption by Default for AWS Resources

    11 1

  2. aws-managed-kms-keys aws-managed-kms-keys Public

    AWS Managed KMS Keys and their Key Policies

    10

  3. aws-data-perimeter-iam aws-data-perimeter-iam Public

    Helpful IAM References for AWS Encryption Management and Data Perimeters

    2

  4. finders-keypers finders-keypers Public

    Finders Keypers: AWS KMS Key Usage Finder

    Python 1

  5. .github .github Public

    Fog Security

Repositories

Showing 5 of 5 repositories
  • aws-default-encryption-tracker Public

    Tracker for Encryption by Default for AWS Resources

    FogSecurity/aws-default-encryption-tracker’s past year of commit activity
    11 1 0 0 Updated Dec 20, 2024
  • .github Public

    Fog Security

    FogSecurity/.github’s past year of commit activity
    0 0 0 0 Updated Nov 26, 2024
  • finders-keypers Public

    Finders Keypers: AWS KMS Key Usage Finder

    FogSecurity/finders-keypers’s past year of commit activity
    Python 1 AGPL-3.0 0 0 0 Updated Nov 26, 2024
  • aws-data-perimeter-iam Public

    Helpful IAM References for AWS Encryption Management and Data Perimeters

    FogSecurity/aws-data-perimeter-iam’s past year of commit activity
    2 GPL-3.0 0 0 0 Updated Nov 21, 2024
  • aws-managed-kms-keys Public

    AWS Managed KMS Keys and their Key Policies

    FogSecurity/aws-managed-kms-keys’s past year of commit activity
    10 Apache-2.0 0 0 0 Updated Sep 12, 2024

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…

Most used topics

Loading…