Security findings hub
Which AWS security service finds what, how Security Hub and Security Hub CSPM aggregate findings in ASFF and OCSF, where Detective and Security Lake fit, and how to schedule recurring assessments.
Exam tasks: 1.1 (skills 1.1.3 to 1.1.5: aggregate security events, detect anomalies, automate recurring assessments), 1.2 (skills 1.2.3 and 1.2.4: security data lakes, analyzing findings)
The decision: which service produces the finding you need, where do all findings land so one team can prioritize them, and which tool do you open to investigate or hunt afterwards?
Which service finds what
| Service | Looks at | Produces | Doesn't |
|---|---|---|---|
| GuardDuty | CloudTrail, flow logs, DNS, plus plan sources | Threat findings: something is happening | Check configuration or scan for CVEs |
| Inspector | EC2 packages and network reachability, ECR images, Lambda code and dependencies, code repositories | Vulnerability findings with a risk score | Detect live attacks |
| Macie | S3 only: bucket settings and object contents | Policy findings (bucket public, unencrypted, shared) and sensitive data findings (PII, credentials) | Look at databases or EBS |
| Security Hub CSPM | AWS Config-backed control checks against standards (FSBP, CIS, PCI DSS, NIST 800-53) | Control findings and security scores, plus aggregated findings from other services in ASFF | Detect threats itself |
| Security Hub | Findings from Security Hub CSPM, GuardDuty, Inspector, Macie and IAM Access Analyzer | Exposure findings that correlate them, an attack path graph, and findings in OCSF | Replace the detectors; they still have to be on |
| IAM Access Analyzer | Resource policies and access activity | External access and unused access findings | See network paths |
| AWS Config | Resource configuration history | Compliance per rule and conformance pack | Explain who made a change (that's CloudTrail) |
| Detective | CloudTrail, flow logs, EKS audit logs, GuardDuty findings, up to a year | Behaviour graph, finding groups, investigations | Generate primary findings or alert |
| Security Lake | Raw logs and findings from AWS, SaaS and custom sources | An OCSF, Parquet data lake in your account | Detect anything by itself |
Exam signal
Map the verb in the question to the service. "Is being attacked / compromised" is GuardDuty. "Has a known CVE" is Inspector. "Contains credit card numbers" is Macie. "Is non-compliant with CIS" is Security Hub CSPM (on AWS Config). "Root cause, what else did this principal touch" is Detective. "Keep and query all security logs for years in an open schema" is Security Lake.
How findings flow
- Every detector is Regional and has its own delegated administrator. Use the same security tooling account for all of them so one team sees everything.
- Findings only reach Security Hub CSPM after you enable it, and only in the Region where it's enabled. Designate an aggregation Region to pull findings, insights and control status from linked Regions.
- Central configuration lets the delegated admin push configuration policies (which standards and controls are on) to OUs and accounts, instead of configuring each account.
Security Hub and Security Hub CSPM
AWS now has two related services, and exam questions may use either name.
| Security Hub CSPM | Security Hub | |
|---|---|---|
| Job | Posture checks against standards, plus a single place for findings | Prioritise active risk by correlating signals across detectors |
| Format | AWS Security Finding Format (ASFF) | Open Cybersecurity Schema Framework (OCSF) |
| Signature output | Control findings, security score per standard | Exposure findings and an attack path graph |
| Depends on | AWS Config recording for most controls | Security Hub CSPM, Inspector, GuardDuty, Macie as signal sources |
| Extras | Automation rules, custom actions, insights, cross-Region aggregation | Unused access analysis (90-day lookback), Jira Cloud and ServiceNow ticketing |
- An exposure finding combines, for example, "instance reachable from the internet" (CSPM), "critical CVE on it" (Inspector) and "instance role can read a sensitive bucket" into one prioritised item.
- Automation rules (CSPM) update or suppress findings as they arrive: raise severity for production accounts, set workflow status to SUPPRESSED for a known exception. They run before EventBridge sees the finding.
- Custom actions add a button in the console that sends the selected finding to EventBridge as
Security Hub Findings - Custom Action. Every new or updated finding is sent asSecurity Hub Findings - Imported.
Legacy: use Security Hub CSPM instead
Before the new Security Hub arrived, the posture and aggregation service was simply called "AWS Security Hub". Study material that says "Security Hub" and talks about ASFF, standards and controls is describing what is now Security Hub CSPM.
Security Hub with AWS Config off
Enabling Security Hub CSPM standards in an account that doesn't record resources in AWS Config produces controls with no data. If a question says the security score is empty or controls show "no data", the fix is to enable AWS Config recording (organization-wide, through the delegated admin or a StackSet), not to re-enable the standard.
Inspector and Macie in more detail
Inspector
- Activate it org-wide through a delegated admin; it then scans continuously, re-scanning when a new CVE is published or the resource changes. No scheduled assessment runs to manage.
- EC2 scanning uses the SSM Agent, or agentless scanning of EBS snapshots for instances without it. Hybrid mode does both.
- ECR enhanced scanning is Inspector. ECR's basic scanning is a separate, simpler on-push scan.
- Findings carry an Inspector score adjusted for your environment, for example lowered when the vulnerable port isn't reachable.
Macie
- Automated sensitive data discovery samples objects across all buckets continuously and keeps a sensitivity score per bucket. Good for "find where sensitive data lives across the estate".
- Sensitive data discovery jobs scan chosen buckets fully, once or on a schedule. Good for "prove this bucket holds no card numbers each week".
- Detection uses managed data identifiers, your own custom data identifiers (regex plus keywords) and allow lists for known-safe values.
- Jobs must store discovery results in an S3 bucket encrypted with a KMS key Macie can use.
Macie for RDS
Macie only reads S3. To classify data in a database, export it to S3 first (for example an RDS snapshot export to Parquet) and point Macie at the export.
Detective and Security Lake
Detective answers "what happened around this finding?"
- Builds a behaviour graph from CloudTrail, VPC flow logs, EKS audit logs and GuardDuty findings, with up to a year of history, without you building queries.
- Finding groups cluster related findings and entities into one incident. Investigations check an IAM user or role against indicators of compromise.
- Pivot into Detective straight from a GuardDuty or Security Hub finding.
Security Lake answers "where do all raw security logs live, for years, in one schema?"
- Collects CloudTrail management and data events, VPC Flow Logs, Route 53 Resolver query logs, Security Hub CSPM findings, EKS audit logs and AWS WAF logs, and converts them to OCSF in Apache Parquet.
- Data lives in your S3 buckets (
aws-security-data-lake-*), catalogued in AWS Glue and governed by AWS Lake Formation. Set a rollup Region to consolidate Regions, and lifecycle rules for retention. - Custom sources (on-premises firewalls, SaaS) must write OCSF Parquet themselves.
- Subscribers: data access subscribers get notified of new objects and read them from S3 (typical for a third-party SIEM); query access subscribers query the tables in place through Lake Formation, for example with Athena in their own account.
Exam signal
"Normalize logs from AWS and on-premises tools into one schema and let a third-party SIEM consume them" is Security Lake with a data access subscriber. "Analysts need SQL over the same data without copying it" is a query access subscriber.
Recurring assessments and automation
Skill 1.1.5 asks you to keep assessments running without people remembering to run them.
| Need | Mechanism |
|---|---|
| Continuous configuration compliance across the organization | AWS Config rules and conformance packs deployed org-wide from a delegated admin |
| Benchmark against CIS, PCI DSS, NIST, FSBP | Security Hub CSPM standards via central configuration |
| Keep the SSM Agent, CloudWatch agent or a hardening baseline in place on every instance | Systems Manager State Manager associations on a schedule |
| Continuous vulnerability scanning | Inspector, activated org-wide |
| Weekly proof that buckets hold no sensitive data | Macie scheduled discovery job |
| Evidence collection for auditors | AWS Audit Manager (see Compliance evaluation) |
- Conformance packs bundle Config rules (and optional remediation actions) into one deployable unit, and give a compliance score per pack.
- A State Manager association re-applies its document on a schedule, so drift gets corrected rather than just reported. Pair it with Config for the reporting side.
Scenarios
Security Hub correlates signals from Inspector, GuardDuty, Macie and Security Hub CSPM into exposure findings, which is exactly "vulnerability plus reachability plus sensitive data" in one prioritised item. Detective helps investigate after you pick a finding but doesn't prioritise the estate. An SNS firehose adds noise. Hand-written Athena joins could work but are the high-effort, non-managed answer.
Most Security Hub CSPM controls are evaluated by service-linked AWS Config rules, so without Config recording they have nothing to evaluate. Central configuration policies do apply to new accounts in the targeted OUs. There is no 30-day evaluation delay, and the free trial doesn't hold findings back.
A scheduled Macie job gives the weekly evidence, and a custom data identifier catches the startup's own patient ID format that managed identifiers might miss. Macie publishes findings to EventBridge, so a rule to SNS delivers the alert. GuardDuty S3 Protection detects suspicious access, not content. Inspector doesn't scan S3 objects. Access logs show who read objects, not what they contain.
Further reading
Threat detection with GuardDuty
GuardDuty foundational sources and protection plans, Extended Threat Detection attack sequences, finding types and severity, suppression rules, threat lists and organization-wide rollout.
Alerting and dashboards
Turning logs, metrics and findings into alerts with CloudWatch metric filters and alarms, EventBridge rules and AWS User Notifications, plus health checks, AWS Health, Trusted Advisor and Managed Grafana dashboards.