Skip to content

Automated Workflows

Automating Security Hub Workflows

Automating workflows in AWS Security Hub enables proactive enforcement of security policies, real-time response to threats, and consistent compliance across cloud environments. By integrating Security Hub with AWS services like CloudFormation (Infrastructure as Code) and Lambda (serverless functions), you can create self-healing architectures and automate remediation actions. This section demonstrates how to design and implement these workflows.


## Automating with CloudFormation

CloudFormation allows you to define and deploy infrastructure as code, ensuring Security Hub configurations are version-controlled and repeatable. You can use it to create Security Hub rules, custom actions, and integrations with other AWS services.

Example: CloudFormation Template for Security Hub Rule

# securityhub-rule.yaml
AWSTemplateFormatVersion: '2010-09-09'
Resources:
  MySecurityHubRule:
    Type: AWS::SecurityHub::Rule
    Properties:
      Name: "UnrestrictedS3Bucket"
      Description: "Detects S3 buckets without encryption or public access."
      Scope:
        Resources:
          - Type: "AWS::S3::Bucket"
      Criteria:
        Resource: 
          Type: "AWS
        Configuration:
          PublicAccessBlockConfiguration:
            BlockPublicAcls: false
            BlockPublicPolicyAcls: false
            IgnorePublicAcls: false
            RestrictPublicBuckets: false

Commands:

# Deploy the template
aws cloudformation create-stack \
  --stack-name securityhub-rule-stack \
  --template-body file://securityhub-rule.yaml \
  --capabilities CAPABILITY_NAMED_IAM

This rule detects S3 buckets with public access and triggers alerts in Security Hub.


## Automating with Lambda

Lambda functions can automate responses to Security Hub findings, such as tagging resources, updating configurations, or triggering notifications. Pair Lambda with EventBridge to listen for Security Hub findings and execute actions in real time.

Example: Lambda Function for Finding Remediation

# remediate_finding.py
import json
import boto3

def lambda_handler(event, context):
    client = boto3.client('ec2')
    findings = json.loads(event['body'])['findings']

    for finding in findings:
        resource_arn = finding['resources'][0]['resourceId']
        if 'ec2:SecurityGroup' in resource_arn:
            # Example: Add a rule to a security group
            client.authorize_security_group_ingress(
                GroupId=resource_arn.split('/')[-1],
                IpPermissions=[
                    {
                        'IpProtocol': '-1',
                        'IpRanges': [{'CidrIp': '0.0.0.0/0'}],
                        'UserIdGroupPairs': []
                    }
                ]
            )
    return {'statusCode': 200, 'body': 'Remediation completed'}

Commands:

# Create Lambda function
aws lambda create-function \
  --function-name SecurityHubRemediation \
  --runtime python3.9 \
  --role arn:aws:iam::123456789012:role/lambda-role \
  --handler remediate_finding.lambda_handler \
  --zip-file fileb://remediate_finding.zip

Note: This example demonstrates a simplified remediation scenario. In production, ensure ingress rules are restricted to trusted IP ranges to avoid security risks.


## Integrating with EventBridge

Use EventBridge to route Security Hub findings to Lambda or other services. For example, create a rule that triggers a Lambda function when a new finding is published.

Example EventBridge Rule:

{
  "name": "SecurityHubFindingsRule",
  "source": "aws.securityhub",
  "detail-type": ["Security Finding"],
  "targets": [
    {
      "arn": "arn:aws:lambda:region:account-id:function:SecurityHubRemediation",
      "id": "RemediationTarget"
    }
  ]
}


## Diagram of Workflow

graph TD
    A[Security Hub Findings] --> B[EventBridge]
    B --> C[Lambda Function]
    C --> D[Remediation Action (e.g., tagging, configuration update)]
    C --> E[CloudFormation Stack Update]

This workflow demonstrates how Security Hub findings trigger automated remediation via Lambda and infrastructure updates via CloudFormation.


Key takeaways

  • CloudFormation ensures Security Hub configurations are version-controlled and repeatable.
  • Lambda enables real-time remediation of findings, such as updating security groups or tagging resources.
  • EventBridge acts as the glue between Security Hub and automation services, enabling scalable, event-driven workflows.
  • Combine these tools to enforce security policies consistently within AWS environments.