Integrations / AWS

    Junglewise for AWS

    Connect an AWS account with a role you create, read access to start. Junglewise watches its security findings and activity around the clock, explains what matters, and drafts the fix. Nothing changes in your account until you approve it, or until a rule you set in auto mode allows it.

    Cross-account role. Read access to start. About 3 min to set up.

    Connecting AWS

    How you connect it

    1. Step 1

      Pick the account and the regions to watch. Junglewise shows you the trust policy and the IAM policy before you create anything.

    2. Step 2

      Create the cross-account role in your account. It carries an external ID unique to your workspace, so no one else can assume it.

    3. Step 3

      Junglewise verifies the role and starts reading. Setup takes about three minutes.

    What Junglewise reads

    Watched around the clock

    • GuardDuty

      Threat findings, every five minutes, including credential findings that start an incident response.

    • CloudTrail

      Account activity every five minutes, with routine read events filtered out.

    • Security Hub

      Aggregated security findings every fifteen minutes.

    • Investigate, if you allow it

      Attach AWS's ReadOnlyAccess policy to the role and the agent can look up configuration while it investigates a finding. Off unless you turn it on.

    What it can change

    Only with your approval

    • Deactivate a leaked access key

      Sets the key to inactive, which you can reverse, and records when it was last used.

    • Close an open security group rule

      Revokes the ingress rule that exposes a service.

    • Block public access to an S3 bucket

      Turns on the bucket's public access block.

    Each change waits for you unless you set an auto mode rule for that kind of fix, and every applied change is logged with what it changed.

    AWS questions

    Can Junglewise change my AWS account without asking?
    Only if you allow it. Every change is drafted and waits for your approval unless you set an auto mode rule for that kind of fix. Auto mode has an hourly cap per account, one switch pauses it everywhere, and every applied change is logged with its before and after state.
    What does Junglewise never touch?
    The contents of your data. It reads configuration, IAM policies, network rules and storage settings.
    How do I disconnect?
    Delete the role in your AWS account. Junglewise loses access immediately.
    Also connects toGitHubAll integrations

    See what's lurking out there. It takes a minute.

    Start with a free scan of your domain. When you're ready for the inside view, try Team free for 14 days.

    Start 14-day free trial