This project contains nested state machines for OpenSecOps SOAR. Together, they constitute the central processors of security data:
SOARSecHubFindingsProcessor: The main state machine triggered on ASFF data from Security Hub.SOARAttemptAutoRemediation: Invoked bySOARSecHubFindingsProcessorto handle autoremediation of failed controls.SOARIncidents: Invoked bySOARSecHubFindingsProcessorto handle incidents.SOARWeeklyAIReport: Invoked bycronevery Monday morning to create the weekly security report.
First make sure that your SSO setup is configured with a default profile giving you AWSAdministratorAccess to your AWS Organizations administrative account. This is necessary as the AWS cross-account role used during deployment only can be assumed from that account.
aws sso loginThen type:
./deploy