Lesson 410 · AWS Learning Path

AWS 410: GuardDuty and Security Hub event-driven response

· Published · 5 min read

Labelled process diagram for AWS 410: Versioned intent to Automated validation to Controlled AWS change to Observed result and retained evidence, with decision, proof and rejection evidence.

Why this lesson matters

GuardDuty detects suspicious activity from AWS data sources and protection plans. Security Hub CSPM aggregates and normalizes security findings and workflow context. EventBridge routes events. None independently proves compromise or safely remediates it. Architects must preserve finding identity, enrich evidence, authorize containment, prevent loops and verify outcomes across accounts and Regions.

Detection and aggregation planes

Enable and govern GuardDuty through Organizations with a delegated administrator, deliberate auto-enable policy, all required Regions and protection-plan coverage. Findings are Regional. Severity indicates GuardDuty's assessment, not the final business priority. A medium finding on an internet-facing privileged resource can outrank a high finding in an isolated disposable lab after context is added.

Security Hub CSPM uses a delegated administrator and home/aggregation Region design to centralize findings and standards. Keep member-account/Regional survival paths because aggregation is not instant and central services can fail. Distinguish provider finding status, record state, compliance state and investigation workflow status; changing workflow to RESOLVED or SUPPRESSED does not prevent a provider from producing a new finding.

Field/evidenceOperational useDangerous assumption
Finding/provider ID and product ARNStable update/deduplication identityTitle alone is unique
Account, Region and resourceRoute to owner and response roleAggregator account owns resource
Created/updated/first/last observedBuild a timelineEvent delivery time is detection time
Severity/typeInitial prioritizationSeverity proves compromise
Record/compliance/workflow stateProvider and analyst lifecycleRESOLVED disables recurrence
Raw provider evidenceInvestigation and custodyNormalized record contains every detail

Event-driven response pipeline

Use precise EventBridge patterns for active findings, provider/product, type, severity and workflow state. Route to a durable queue or workflow with a DLQ, retry limits and archive where justified. Store event/finding IDs and update time in an idempotency ledger. Findings can be updated and redelivered; deduplicate actions while preserving meaningful evidence changes.

Enrichment must use read-only cross-account roles and time-bounded queries: account/OU/environment owner, resource tags and exposure, IAM relationships, configuration history, CloudTrail activity, network context, vulnerability/deployment state and threat intelligence. Record source, query time and confidence. Missing context increases uncertainty; it must not silently downgrade priority.

Classify response actions by reversibility and blast radius. Automatically tag/ticket/collect evidence at low risk. Quarantining an instance, revoking sessions, changing network access, disabling a key or isolating a workload may interrupt business and destroy evidence, so require preapproved scope, confidence, authorization, timeout and reversal. Verify both security outcome and customer impact after containment.

Workflow and suppression

Use workflow states consistently: NEW for unreviewed, NOTIFIED when the owner must act, SUPPRESSED only after justified no-action review, and RESOLVED after remediation and verification. Keep analyst notes, ticket/incident ID, owner, reason and evidence externally where needed for durable audit. Provider updates can reset some states and create new findings.

Automation rules can normalize severity, workflow, notes or routing according to criteria. Rule order matters when multiple rules update the same field, and rules act on new/updated provider findings rather than every analyst update. Preview criteria, test overlap/order, version policy and monitor match volume. Broad suppression by title/severity hides real incidents; use narrow resource/context criteria, owner, expiry and sampling review.

Prevent feedback loops. A workflow update can emit another finding event, and remediation can produce CloudTrail activity or new detections. Tag automation origin, ignore self-generated state-only updates when appropriate, retain idempotency, cap attempts and require a terminal/escalated outcome. Never suppress evidence simply to stop a loop.

~~~bash aws guardduty list-detectors aws guardduty list-findings --detector-id DETECTOR --finding-criteria file://criteria.json aws guardduty get-findings --detector-id DETECTOR --finding-ids FINDING_ID aws securityhub get-findings --filters file://filters.json aws events list-rules --event-bus-name default aws sqs get-queue-attributes --queue-url DLQ_URL --attribute-names All ~~~

Workshop and response proof

Given twenty GuardDuty/Security Hub events, correlate updates into incidents, retain distinct resources, calculate business priority, and identify missing Regions/plans. Design delegated administration, aggregation plus local routes, enrichment roles, queue/workflow and custody. For five findings, choose observe, collect, notify, contain with approval or automatic containment and state the reversal/verification proof.

Run a supplied event through duplicate delivery, provider update, analyst state update, target throttling, DLQ redrive and failed containment. Reconcile received, matched, queued, processed, updated, acted, verified and failed counts. Measure detection-to-route, route-to-acknowledgement, containment/verification time, false-positive/suppression age, recurrence, action failure and DLQ age.

Test 24 failures: Region disabled, new account not enabled, protection plan missing, central aggregation lag, account/Region confused, title used as identity, update treated new, duplicate containment, severity alone prioritizes, enrichment role mutates, missing context downgrades, queue unencrypted, DLQ unmonitored, rule too broad, rule order conflict, suppression has no expiry, workflow resolved without verification, provider recurrence ignored, self-update loop, retries repeat destructive action, approval stale, containment destroys evidence, customer impact unchecked, and no reversal.

Cost and acceptance

Price GuardDuty usage/protection plans, Security Hub CSPM, EventBridge, queue/workflow/Lambda, logs, archive/evidence and cross-Region transfer. This lesson creates nothing. Submit organization/Regional coverage, field map, routing/enrichment architecture, state/suppression policy, five response decisions, reconciliation/metrics, IAM boundaries and all diagnoses. Pass requires durable idempotent routing, narrow suppression, authorized reversible containment and verified security/customer outcomes.

Official sources

Advertisement