Skip to content
View DustyStudy's full-sized avatar

Block or report DustyStudy

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
DustyStudy/README.md

Dustin Arrington

Senior Cloud Engineer focused on AWS multi-account governance and compliance-as-code: FedRAMP (Rev5 and 20x) and NIST 800-53 controls implemented as code on AWS, in both commercial regions and GovCloud.

I build multi-account guardrails, audit evidence pipelines, and remediation workflows that run on short-lived credentials only (OIDC and IAM Identity Center, zero long-lived keys).

Every repo below has automated tests (terraform test, pytest), is scanned in CI with Checkov, Trivy, and Gitleaks, and documents its coverage gaps. Where noted, it links to proof from a live deployment.

LinkedIn

Start here

How the repos fit together

flowchart LR
  subgraph prevent["Prevent"]
    org["aws-org-guardrails<br/>org SCPs, permissions boundary,<br/>Bedrock and SageMaker guardrails"]
    lib["fedramp-terraform-library<br/>account baselines and auditors"]
  end
  subgraph access["Access"]
    sso["aws-sso-broker<br/>short-lived Identity Center credentials"]
  end
  subgraph detect["Detect"]
    prowler["prowler-aws-template<br/>org-wide CSPM scans"]
    sh["Security Hub findings"]
  end
  subgraph respond["Respond"]
    rem["aws-remediation-orchestrator<br/>governed auto-remediation"]
  end
  subgraph prove["Prove"]
    grc["grc-evidence-automation<br/>tamper-evident control evidence"]
  end
  prevent --> detect --> respond
  sh --> rem
  prevent --> prove
  respond --> prove
Loading

Also here

Threat-informed hardening

I track AWS attack techniques in active use and update these repos as new ones are reported. Each entry in the threat response log names a technique, the control added for it, and public reporting of attackers using it. The most recent:

Tools and platforms

Cloud: AWS (including GovCloud)
Infrastructure as code: Terraform, GitHub Actions
Languages: Python, HCL, PowerShell, Bash
Security tooling: Checkov, Trivy, Gitleaks, Prowler, Security Hub, GuardDuty, AWS Config
Frameworks: FedRAMP Rev5 and 20x, NIST 800-53 Rev5, SOC 2, ISO 27001:2022
AI assistance: I use AI coding assistants (Claude Code) for drafting and review. I design each system, and I verify it with tests and, where noted, live deployments.

Pinned Loading

  1. fedramp-terraform-library fedramp-terraform-library Public

    Terraform modules implementing NIST 800-53 Rev5 Moderate/High controls and FedRAMP 20x Key Security Indicators for AWS.

    HCL 1

  2. aws-remediation-orchestrator aws-remediation-orchestrator Public

    Security Hub-driven remediation orchestration: policy-routed, guardrailed, auditable auto-remediation for AWS (Step Functions + Lambda + SSM Automation).

    Python

  3. aws-sso-broker aws-sso-broker Public

    Ephemeral AWS multi-account credential broker built on IAM Identity Center / SSO. No long-lived keys.

    Python

  4. ai-agent-security-toolkit ai-agent-security-toolkit Public

    Fuzz, contain, validate and audit LLM agents: prompt-injection fuzzer, tool-call allowlist/sandbox with taint tracking, output validation + tamper-evident audit log, and a STRIDE-for-agents threat …

    Python

  5. aws-org-guardrails aws-org-guardrails Public

    Terraform guardrails for AWS Organizations: SCP bundles, a permissions boundary and Identity Center permission sets, tested as policy behavior. Commercial & GovCloud.

    HCL

  6. grc-evidence-automation grc-evidence-automation Public

    Scheduled, tamper-evident AWS/GCP control evidence mapped to SOC 2, ISO 27001:2022, NIST 800-53 and FedRAMP 20x KSIs, delivered to S3 or a GRC ingestion API. Lambda + Terraform.

    Python