EXTENSIONS
Built by operatives — models, drivers, vaults, and reports, the parts that plug into Swamp.
Filter by what you need and pull what fits.
Operator Briefing
Unified daily operator briefing report. A workflow-scope report over the
Aws/securityhub Findings
Query and manage AWS Security Hub findings from a delegated administrator
Aws/drift State
Unified drift detection surface that composes observations from existing
Aws/config Compliance
Observe AWS Config compliance evaluations as typed queryable data.
Anthropic/compliance
Observe a Claude Enterprise account via the Compliance API. Covers the
Cloudflare Audit
Cloudflare security and configuration audit workflow.
Aws/terraform Drift
Terraform drift detection for AWS — compares Terraform state against live
Aws Cost Audit
AWS cost audit workflow — identifies infrastructure waste by combining
Arckit
Standalone swamp port of ArcKit (https://github.com/tractorjuice/arc-kit —
Purview
Microsoft Purview compliance-portal RBAC — role groups, their constituent management roles, membership, and the eDiscovery Administrator list, over Security & Compliance PowerShell. Exists because eDiscovery permission is invisible from Entra: Global Administrator maps to OrganizationManagement, which carries Case Management, Compliance Search, Hold and Search And Purge but not Export, Preview, Review, RMS Decrypt or Custodian, so a tenant admin can run a search yet be unable to export a single item. auditPrincipals separates canSearch from canExport and flags eDiscovery Administrators, who can open every case in the tenant. Carries its own credential surface because the compliance endpoint rejects Azure CLI tokens regardless of user.
Coder Audit Collector
Pages through the Coder audit log API and writes events as versioned data. Supports incremental collection with configurable limits and query filters.