AboutDFIR.com – The Definitive Compendium Project
Digital Forensics & Incident Response

See below for a list of AWS Tools.

ToolDescription
Cado's Import UICado's Import UI - Cloud Data Importing Tool
cloudgrepcloudgrep is grep for cloud storage. It currently supports searching log files, optionally compressed with gzip (.gz) or zip (.zip), in AWS S3, Azure Storage or Google Cloud Storage.
Invictus-AWSInvictus-AWS is a python script that will help automatically enumerate and acquire relevant data from an AWS environment.

See below for a list of AWS Artifacts.

Artifact or ProcessResource
AWS Cloud ForensicsA New Perspective on Resource-Level Cloud Forensics
AWS Incident ResponseAutomated AWS Incident Response — The next episode
CloudTrailAWS CloudTrail Forensics - A SIEM Case Study