- AWS Security Hub Partners
- AWS Security Hub Security Blogs
- AWS re:Post questions for AWS Security Hub
- AWS Security Hub FAQs
- AWS Security Hub Pricing
- Free Cybersecurity Training
-
Automated
response &
remediation
-
EventBridge
(Enrichment, Actions, Notifications)
- AWS Solutions
- Lambda
- AWS Systems Manager Automation
- Amazon Kinesis Data Streams
- AWS Step Functions
- Amazon SNS
- Amazon SQS queue
-
Integration with 3rd party platform
-
Sample security partners (Dec 2021)
- SIEM
- SOAR
- Instant messaging (Slack, PagerDuty, etc.)
- Ticketing systems
- Pivot to Amazon Detective
-
Audit Manager
- Audit Reports
- AWS Chatbot
- AWS Trusted Advisor
-
Sources
-
3rd party AWS Partner Network (APN) - some bi-directional
- Anti-Malware
- Compliance solutions
- Firewalls
- Vulnerability managers
-
Security Hub Integrated Standards (via AWS Config)
- CIS AWS Foundations Benchmark
- PCI DSS
- AWS Foundational Security Best Practices standard
-
AWS internal sources
-
IAM Access Analizer
- External Access Granted
-
System Manager Patch Manager
- Inventory
- Compliance
-
AWS Firewall Manager
- WAF Policy
- ACL Rules
- AWS Shield
- DNS Firewall
- AWS Network Firewall
-
Amazon Inspector
- Amazon EC2
- Containers in ECR
-
Macie
-
Amazon S3
- Publicly accessible buckets
- Unencrypted buckets
- Buckets shared with AWS accounts / Organizations
- Identify & Alert on personally identifiable information (PII)
- AWS Health
-
GuardDuty
- CloudTrail Event Logs
- CloudTrail Management Events
- CloudTrail S3 Data Events
- VPC Flow Logs
- DNS logs
- GuardDuty for EKS
-
Threat intelligence (IP and domains)
- AWS Security
- 3rd party providers
- Proofpoint
- CrowdStrike
- Custom threat lists