AWS 179: AWS Security Hub and Amazon Detective
Why this lesson matters
Aggregate and normalize security findings, evaluate controls, correlate resources, and investigate relationships without confusing aggregation with detection or response.
What you will be able to do
By the end, you can:
- explain aws security hub and amazon detective in plain language;
- locate the current service controls in the AWS Management Console;
- run the matching CloudShell or AWS CLI queries and explain every important field;
- draw the identity, network, data, failure, and monitoring path;
- choose the service from requirements and reject it when those requirements are absent;
- diagnose a failed or misleading result from evidence;
- state the cost owner and prove cleanup or a no-create result.
Before you start
- Use a personal AWS account only when its owner has approved the lesson. Do not use the root user for daily work.
- CloudShell is the default command environment. AWS028 explains CloudShell; AWS029 and AWS030 explain local AWS CLI installation and profiles.
- The course example Region is
ap-south-1. Global services and services with a required control Region are called out in their commands. - Run
aws sts get-caller-identityprivately. Redact the account number before sharing evidence. - Never paste access keys, passwords, secret values, private object data, presigned URLs, or full account-specific ARNs into a submission.
- This is a no-create lesson. Every Console action and AWS CLI command is read-only. Create the practical artifact locally.
- Console wording can change. Use the Console service search if a menu label has moved, then confirm the current field in the official documentation.
The core model
| Question | What it means in this lesson |
|---|---|
| Purpose | Aggregate and normalize security findings, evaluate controls, correlate resources, and investigate relationships without confusing aggregation with detection or response. |
| Scope and boundary | The learner must identify the account and Region scope, resource boundary, identity path, data or network path, failure behavior, observability, and cleanup ownership for AWS Security Hub and Amazon Detective. |
| Evidence of success | Success means the Console fields, CLI result, workload behavior, monitoring evidence, and architecture claim agree. An available state alone is not enough for AWS Security Hub and Amazon Detective. |
| Cost model | Requests, running capacity, storage, logs, data transfer, retained state, and optional features must be priced for the exact design. |
| Safe rejection rule | Avoid enabling every standard without ownership or treating workflow RESOLVED as proof the underlying cause is fixed. |
How the request flows
+-------------------------------+
| Detector or control finding |
+-------------------------------+
|
v
+------------------------------+
| Security Hub normalization |
+------------------------------+
|
v
+----------------------------------------+
| Detective relationship investigation |
+----------------------------------------+
|
v
+---------------------------------------+
| Response owner and closure evidence |
+---------------------------------------+
Security Hub CSPM provides security-posture controls and a normalized findings plane. Detective builds a behavior graph and investigation context from supported telemetry. Neither replaces the detector that originated a threat finding, the engineer who repairs a resource, or the incident workflow that contains an attacker.
Follow a finding through the complete system
- A provider such as GuardDuty, Inspector, Macie, Firewall Manager, a partner product or Security Hub CSPM control creates or updates a finding.
- Security Hub receives it in AWS Security Finding Format (ASFF), preserving provider identity, product ARN, finding ID, resource, timestamps, severity, record state and workflow state.
- Aggregation can copy findings from linked Regions to a home/aggregation Region; the finding still describes its original account and Region.
- Insights and automation rules prioritize or update fields. EventBridge routes matched events to ticketing or response automation.
- An analyst pivots to Detective for supported entities, relationships and time-bounded activity, then corroborates with CloudTrail, VPC flow, DNS, application and identity evidence.
- The resource owner contains/remediates the cause. The workflow closes only after fresh provider evidence verifies the correction.
Findings and controls are different records
| Field or concept | Correct interpretation |
|---|---|
RecordState | ACTIVE versus ARCHIVED describes provider record lifecycle, not whether a human fixed the risk. |
Workflow.Status | Analyst workflow such as NEW, NOTIFIED, RESOLVED or SUPPRESSED; changing it does not change the resource. |
| Severity | Provider-normalized priority input. Security Hub or automation can update normalized/user severity without repairing anything. |
| Compliance status | Result for a security control evaluation; FAILED points to control evidence and affected resources. |
| Product/Generator/Finding ID | Composite identity needed to update the correct finding without creating duplicates. |
| Updated/Processed timestamps | Provider change time and Security Hub processing time; use both when checking stale data. |
Security standards are collections of controls. One control can appear in multiple standards while Security Hub uses consolidated control findings to reduce duplication. Disable a control only with reason, compensating control, risk owner and expiry. Suppressing generated findings is not equivalent to disabling unnecessary checks and can continue cost/noise.
Multi-account and multi-Region design
Use an AWS Organizations delegated administrator outside the management account. Current central configuration uses a home Region, linked Regions and configuration policies assigned to accounts or OUs. Policies can enable the service, standards, controls and supported parameters consistently. Self-managed accounts remain deliberate exceptions. The home Region also acts as aggregation Region, but opt-in and disabled Regions need explicit design.
Automation rules run regionally and in administrator context. They can adjust severity, workflow, notes and other supported fields for matching incoming/updated findings. Rule order matters; later applied changes can override earlier changes. Keep terminal rules rare, version rules as code and test against sample findings. EventBridge response rules remain separate and need target permissions, retries, DLQs and idempotency.
Use Detective as an investigation tool
Detective organizes supported telemetry into entities and relationships over time: identities, roles, instances, IP addresses, API activity and finding-linked behavior. Set an investigation time window around first/last-seen events, compare baseline behavior, follow role assumption chains and remote endpoints, and export only redacted evidence. Absence from the graph can reflect unsupported resource/Region, delayed ingestion, membership or retention boundaries; it is not proof that activity did not occur.
An investigation should answer who acted, with which session and permissions, from where, against what resource, what changed, whether persistence or lateral movement exists, and what evidence proves containment. Detective accelerates that reasoning but CloudTrail and source logs remain authoritative for specific API events.
Architecture decision table
| Situation | Direction | Reason |
|---|---|---|
| Requirement matches | Use Security Hub as a central security posture and findings workflow and Detective to deepen supported investigations. | Select only after scope, behavior, security, recovery, operations, and price evidence agree. |
| Requirement does not match | Avoid enabling every standard without ownership or treating workflow RESOLVED as proof the underlying cause is fixed. | Rejecting an attractive service is a valid architecture result. |
| No create permission or cost approval | Use supplied evidence and local design work | Learning does not depend on creating an hourly resource. |
| Existing resource is unknown or unowned | Inspect only, then stop | Never change or delete a resource merely because it resembles a course example. |
AWS Management Console, step by step
Sign in with the normal non-root learning identity. Write the expected starting state before opening the service.
- Use the Console service search and open Security Hub CSPM, Findings and Controls, then Detective behavior graph; confirm the account and Region before reading the page.
- Inspect the supplied or owned resource's status, configuration, permissions, networking, encryption, monitoring, tags, and dependencies without changing it.
- Open the related metrics, logs, events, or history view and record one timestamped signal that would prove or disprove the expected behavior.
- Return to the resource list, clear filters, and record the final inventory. On the read-only track, do not choose Create, Save, or Delete.
CloudShell and AWS CLI, step by step
Start with a known caller and Region:
export AWS_DEFAULT_REGION="ap-south-1"
aws sts get-caller-identity --query Arn --output text
aws configure list
Redact the account part of the ARN in shared evidence. Now run the topic queries:
aws securityhub describe-hub --output json
aws securityhub get-findings --max-results 20 --query 'Findings[].{Title:Title,Severity:Severity.Label,Status:Workflow.Status,Product:ProductName,Resource:Resources[0].Id}' --output table
aws detective list-graphs --output table
Expected interpretation
Security Hub receives findings and evaluates controls; Detective builds investigation context from supported telemetry. Workflow status needs an accountable response process.
Practical work
Investigate a supplied high-severity finding. Trace product source, resource, account, control, related findings, Detective entities, CloudTrail and network evidence, containment, remediation, and closure.
Diagnose this topic from its own evidence
- Missing finding: confirm provider enabled state, source account/Region, integration/product subscription, record state, filters and aggregation links.
- Control remains failed: inspect control evaluation schedule, exact resource ID/Region and fresh Config/resource state; changing workflow status cannot pass it.
- Automation changed the wrong finding: inspect rule order, criteria, terminal behavior, administrator Region and original ASFF fields.
- Detective graph is empty: inspect graph/member status, supported entity and telemetry time window before claiming no activity.
- Closure package must include original finding identity, investigation timeline, containment, root fix, new provider/control result, owner and residual risk.
Cost and cleanup
Requests, running capacity, storage, logs, data transfer, retained state, and optional features must be priced for the exact design.
Knowledge check
- What operational purpose is this lesson solving?
Expected direction: Aggregate and normalize security findings, evaluate controls, correlate resources, and investigate relationships without confusing aggregation with detection or response.
- Which scope or ownership boundary must be proved first?
Expected direction: The learner must identify the account and Region scope, resource boundary, identity path, data or network path, failure behavior, observability, and cleanup ownership for AWS Security Hub and Amazon Detective.
- What evidence is strong enough to accept the result?
Expected direction: Success means the Console fields, CLI result, workload behavior, monitoring evidence, and architecture claim agree. An available state alone is not enough for AWS Security Hub and Amazon Detective.
- Which tempting design or shortcut must be rejected?
Expected direction: Avoid enabling every standard without ownership or treating workflow RESOLVED as proof the underlying cause is fixed.
- Which cost dimensions and retained resources need an owner?
Expected direction: Requests, running capacity, storage, logs, data transfer, retained state, and optional features must be priced for the exact design.
Lesson acceptance
- Distinguish provider detection, Security Hub CSPM controls/aggregation, Detective investigation, EventBridge response and resource remediation.
- Interpret ASFF identity, record state, workflow status, compliance and timestamps correctly.
- Design delegated administration, central configuration and cross-Region aggregation with stated gaps.
- Explain automation-rule order and safe response-target failure handling.
- Produce a redacted investigation timeline whose closure is supported by fresh source evidence.