Cloud incident response at UNSW with digital forensics powered by AWS
Public Sector Blog
This article discusses how the University of New South Wales (UNSW) collaborated with AWS and CyberCX to implement the Automated Forensics Orchestrator for Amazon EC2 solution, enhancing it to meet UNSW's specific cybersecurity requirements.
Specifically, the article covers:
- The Forensics Orchestrator framework, which automates incident response and forensic analysis for potentially compromised Amazon EC2 instances.
- Enhancements made to the solution, including a graphical interface for investigations, just-in-time (JIT) access control, enhanced automation for simultaneous containment and analysis, and an improved deployment pipeline.
- Details on the implementation of each enhancement, such as using AWS Systems Manager for secure remote access, leveraging AWS Service Catalog and Lambda for JIT access control, and integrating with existing UNSW infrastructure like Amazon EC2 Image Builder and AWS Control Tower.
- The benefits achieved by UNSW, including streamlined deployment, improved visibility and incident response capabilities, enhanced security through least privilege access, and a simplified investigation process.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
Nov 21
2025
2025
Accelerate investigations with AWS Security Incident Response AI-powered capabilities
Jun 19
2026
2026
An incident response playbook for satellite operations on AWS (Part-1): Detection and forensic readiness
Nov 21
2025
2025
AWS Security Incident Response now provides agentic AI-powered investigation
Dec 2
2024
2024
New AWS Security Incident Response helps organizations respond to and recover from security events
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.