Open-source CloudFormation templates for automated AWS security monitoring. Deploy in minutes and get email alerts for critical events:
One-click CloudFormation deployment. No complex setup, no external dependencies. Just deploy and start monitoring.
Built entirely on AWS services: CloudWatch, Lambda, and SNS. No data leaves your AWS account.
Open source and maintained by the community. Contribute, customize, and improve together.
Cloudwatcher is now completely free and open source. Deploy it in your AWS account, customize it to your needs, and contribute back to the community.
No subscription fees, no hidden costs
Modify templates to fit your needs
Contribute and improve together
Use it anywhere, commercially or personally
Cloudwatcher monitors your CloudTrail logs and triggers CloudWatch alarms for these critical security events:
Failed authorization attempts that could indicate unauthorized access attempts.
Identity verification calls often used by attackers to validate stolen credentials.
Policy attachments to users that could escalate privileges.
SSO authentication events to track login activity across your organization.
New IAM user creation that could indicate unauthorized account creation.
IAM user deletion events to track account removal.
General IAM user activity monitoring for comprehensive visibility.
Enable or disable any alarm based on your specific security requirements.
Launch the CloudFormation stack with pre-configured parameters. Deployment takes about 5 minutes.
Check your inbox for the SNS confirmation email and click the confirmation link.
Start receiving formatted email notifications whenever a security event is detected in your AWS Organization.
Click the button below to deploy the CloudFormation stack directly to your AWS account. The template will create all necessary CloudWatch alarms, metric filters, and Lambda functions.
⚠️ Important: After deployment, you'll receive an SNS confirmation email. You must click the confirmation link to start receiving alerts. Check your spam folder if you don't see it!
Cloudwatcher is open source and community-driven. Whether you want to contribute code, report issues, or just stay updated – we'd love to have you involved!
Submit issues, pull requests, or star the repository to show your support.
View RepositoryCheck out the README for detailed deployment instructions and architecture details.
View DocumentationHave an idea for a new alarm or feature? We'd love to hear from you! Open an issue on GitHub or reach out.
Together, we can make AWS security monitoring accessible to everyone.
Get clear answers about Cloudwatcher – the open-source AWS security monitoring solution. Have more questions? Feel free to reach out.
Get in touch