Asterrr's Handbook

Security findings hub

Which AWS security service finds what, how Security Hub and Security Hub CSPM aggregate findings in ASFF and OCSF, where Detective and Security Lake fit, and how to schedule recurring assessments.

Exam tasks: 1.1 (skills 1.1.3 to 1.1.5: aggregate security events, detect anomalies, automate recurring assessments), 1.2 (skills 1.2.3 and 1.2.4: security data lakes, analyzing findings)

The decision: which service produces the finding you need, where do all findings land so one team can prioritize them, and which tool do you open to investigate or hunt afterwards?

Which service finds what

ServiceLooks atProducesDoesn't
GuardDutyCloudTrail, flow logs, DNS, plus plan sourcesThreat findings: something is happeningCheck configuration or scan for CVEs
InspectorEC2 packages and network reachability, ECR images, Lambda code and dependencies, code repositoriesVulnerability findings with a risk scoreDetect live attacks
MacieS3 only: bucket settings and object contentsPolicy findings (bucket public, unencrypted, shared) and sensitive data findings (PII, credentials)Look at databases or EBS
Security Hub CSPMAWS Config-backed control checks against standards (FSBP, CIS, PCI DSS, NIST 800-53)Control findings and security scores, plus aggregated findings from other services in ASFFDetect threats itself
Security HubFindings from Security Hub CSPM, GuardDuty, Inspector, Macie and IAM Access AnalyzerExposure findings that correlate them, an attack path graph, and findings in OCSFReplace the detectors; they still have to be on
IAM Access AnalyzerResource policies and access activityExternal access and unused access findingsSee network paths
AWS ConfigResource configuration historyCompliance per rule and conformance packExplain who made a change (that's CloudTrail)
DetectiveCloudTrail, flow logs, EKS audit logs, GuardDuty findings, up to a yearBehaviour graph, finding groups, investigationsGenerate primary findings or alert
Security LakeRaw logs and findings from AWS, SaaS and custom sourcesAn OCSF, Parquet data lake in your accountDetect anything by itself

Exam signal

Map the verb in the question to the service. "Is being attacked / compromised" is GuardDuty. "Has a known CVE" is Inspector. "Contains credit card numbers" is Macie. "Is non-compliant with CIS" is Security Hub CSPM (on AWS Config). "Root cause, what else did this principal touch" is Detective. "Keep and query all security logs for years in an open schema" is Security Lake.

How findings flow

  • Every detector is Regional and has its own delegated administrator. Use the same security tooling account for all of them so one team sees everything.
  • Findings only reach Security Hub CSPM after you enable it, and only in the Region where it's enabled. Designate an aggregation Region to pull findings, insights and control status from linked Regions.
  • Central configuration lets the delegated admin push configuration policies (which standards and controls are on) to OUs and accounts, instead of configuring each account.

Security Hub and Security Hub CSPM

AWS now has two related services, and exam questions may use either name.

Security Hub CSPMSecurity Hub
JobPosture checks against standards, plus a single place for findingsPrioritise active risk by correlating signals across detectors
FormatAWS Security Finding Format (ASFF)Open Cybersecurity Schema Framework (OCSF)
Signature outputControl findings, security score per standardExposure findings and an attack path graph
Depends onAWS Config recording for most controlsSecurity Hub CSPM, Inspector, GuardDuty, Macie as signal sources
ExtrasAutomation rules, custom actions, insights, cross-Region aggregationUnused access analysis (90-day lookback), Jira Cloud and ServiceNow ticketing
  • An exposure finding combines, for example, "instance reachable from the internet" (CSPM), "critical CVE on it" (Inspector) and "instance role can read a sensitive bucket" into one prioritised item.
  • Automation rules (CSPM) update or suppress findings as they arrive: raise severity for production accounts, set workflow status to SUPPRESSED for a known exception. They run before EventBridge sees the finding.
  • Custom actions add a button in the console that sends the selected finding to EventBridge as Security Hub Findings - Custom Action. Every new or updated finding is sent as Security Hub Findings - Imported.

Legacy: use Security Hub CSPM instead

Before the new Security Hub arrived, the posture and aggregation service was simply called "AWS Security Hub". Study material that says "Security Hub" and talks about ASFF, standards and controls is describing what is now Security Hub CSPM.

Security Hub with AWS Config off

Enabling Security Hub CSPM standards in an account that doesn't record resources in AWS Config produces controls with no data. If a question says the security score is empty or controls show "no data", the fix is to enable AWS Config recording (organization-wide, through the delegated admin or a StackSet), not to re-enable the standard.

Inspector and Macie in more detail

Inspector

  • Activate it org-wide through a delegated admin; it then scans continuously, re-scanning when a new CVE is published or the resource changes. No scheduled assessment runs to manage.
  • EC2 scanning uses the SSM Agent, or agentless scanning of EBS snapshots for instances without it. Hybrid mode does both.
  • ECR enhanced scanning is Inspector. ECR's basic scanning is a separate, simpler on-push scan.
  • Findings carry an Inspector score adjusted for your environment, for example lowered when the vulnerable port isn't reachable.

Macie

  • Automated sensitive data discovery samples objects across all buckets continuously and keeps a sensitivity score per bucket. Good for "find where sensitive data lives across the estate".
  • Sensitive data discovery jobs scan chosen buckets fully, once or on a schedule. Good for "prove this bucket holds no card numbers each week".
  • Detection uses managed data identifiers, your own custom data identifiers (regex plus keywords) and allow lists for known-safe values.
  • Jobs must store discovery results in an S3 bucket encrypted with a KMS key Macie can use.

Macie for RDS

Macie only reads S3. To classify data in a database, export it to S3 first (for example an RDS snapshot export to Parquet) and point Macie at the export.

Detective and Security Lake

Detective answers "what happened around this finding?"

  • Builds a behaviour graph from CloudTrail, VPC flow logs, EKS audit logs and GuardDuty findings, with up to a year of history, without you building queries.
  • Finding groups cluster related findings and entities into one incident. Investigations check an IAM user or role against indicators of compromise.
  • Pivot into Detective straight from a GuardDuty or Security Hub finding.

Security Lake answers "where do all raw security logs live, for years, in one schema?"

  • Collects CloudTrail management and data events, VPC Flow Logs, Route 53 Resolver query logs, Security Hub CSPM findings, EKS audit logs and AWS WAF logs, and converts them to OCSF in Apache Parquet.
  • Data lives in your S3 buckets (aws-security-data-lake-*), catalogued in AWS Glue and governed by AWS Lake Formation. Set a rollup Region to consolidate Regions, and lifecycle rules for retention.
  • Custom sources (on-premises firewalls, SaaS) must write OCSF Parquet themselves.
  • Subscribers: data access subscribers get notified of new objects and read them from S3 (typical for a third-party SIEM); query access subscribers query the tables in place through Lake Formation, for example with Athena in their own account.

Exam signal

"Normalize logs from AWS and on-premises tools into one schema and let a third-party SIEM consume them" is Security Lake with a data access subscriber. "Analysts need SQL over the same data without copying it" is a query access subscriber.

Recurring assessments and automation

Skill 1.1.5 asks you to keep assessments running without people remembering to run them.

NeedMechanism
Continuous configuration compliance across the organizationAWS Config rules and conformance packs deployed org-wide from a delegated admin
Benchmark against CIS, PCI DSS, NIST, FSBPSecurity Hub CSPM standards via central configuration
Keep the SSM Agent, CloudWatch agent or a hardening baseline in place on every instanceSystems Manager State Manager associations on a schedule
Continuous vulnerability scanningInspector, activated org-wide
Weekly proof that buckets hold no sensitive dataMacie scheduled discovery job
Evidence collection for auditorsAWS Audit Manager (see Compliance evaluation)
  • Conformance packs bundle Config rules (and optional remediation actions) into one deployable unit, and give a compliance score per pack.
  • A State Manager association re-applies its document on a schedule, so drift gets corrected rather than just reported. Pair it with Config for the reporting side.

Scenarios

Scenario
A logistics company has enabled GuardDuty, Inspector and Macie through a delegated administrator in the security account. The security team complains that it has to open three consoles in four Regions each morning and cannot tell which of 3,000 findings matter most. It wants one prioritised view that highlights resources where a vulnerability, public reachability and access to sensitive data combine. What should the security engineer do?
Scenario
An insurer enabled Security Hub CSPM with the CIS AWS Foundations Benchmark in all accounts using central configuration. Two weeks later, most controls in 30 newly created accounts show no data, while older accounts report normally. What is the MOST likely cause?
Scenario · choose 2
A healthcare startup must show auditors every Monday that none of its 60 production buckets contain unmasked patient identifiers, and it wants an alert within minutes if any job finds some. Which combination meets the requirement? (Choose TWO.)

Further reading

On this page