AWS 410: GuardDuty and Security Hub event-driven response
Why this lesson matters
GuardDuty detects suspicious activity from AWS data sources and protection plans. Security Hub CSPM aggregates and normalizes security findings and workflow context. EventBridge routes events. None independently proves compromise or safely remediates it. Architects must preserve finding identity, enrich evidence, authorize containment, prevent loops and verify outcomes across accounts and Regions.
Detection and aggregation planes
Enable and govern GuardDuty through Organizations with a delegated administrator, deliberate auto-enable policy, all required Regions and protection-plan coverage. Findings are Regional. Severity indicates GuardDuty's assessment, not the final business priority. A medium finding on an internet-facing privileged resource can outrank a high finding in an isolated disposable lab after context is added.
Security Hub CSPM uses a delegated administrator and home/aggregation Region design to centralize findings and standards. Keep member-account/Regional survival paths because aggregation is not instant and central services can fail. Distinguish provider finding status, record state, compliance state and investigation workflow status; changing workflow to RESOLVED or SUPPRESSED does not prevent a provider from producing a new finding.
| Field/evidence | Operational use | Dangerous assumption |
|---|---|---|
| Finding/provider ID and product ARN | Stable update/deduplication identity | Title alone is unique |
| Account, Region and resource | Route to owner and response role | Aggregator account owns resource |
| Created/updated/first/last observed | Build a timeline | Event delivery time is detection time |
| Severity/type | Initial prioritization | Severity proves compromise |
| Record/compliance/workflow state | Provider and analyst lifecycle | RESOLVED disables recurrence |
| Raw provider evidence | Investigation and custody | Normalized record contains every detail |
Event-driven response pipeline
Use precise EventBridge patterns for active findings, provider/product, type, severity and workflow state. Route to a durable queue or workflow with a DLQ, retry limits and archive where justified. Store event/finding IDs and update time in an idempotency ledger. Findings can be updated and redelivered; deduplicate actions while preserving meaningful evidence changes.
Enrichment must use read-only cross-account roles and time-bounded queries: account/OU/environment owner, resource tags and exposure, IAM relationships, configuration history, CloudTrail activity, network context, vulnerability/deployment state and threat intelligence. Record source, query time and confidence. Missing context increases uncertainty; it must not silently downgrade priority.
Classify response actions by reversibility and blast radius. Automatically tag/ticket/collect evidence at low risk. Quarantining an instance, revoking sessions, changing network access, disabling a key or isolating a workload may interrupt business and destroy evidence, so require preapproved scope, confidence, authorization, timeout and reversal. Verify both security outcome and customer impact after containment.
Workflow and suppression
Use workflow states consistently: NEW for unreviewed, NOTIFIED when the owner must act, SUPPRESSED only after justified no-action review, and RESOLVED after remediation and verification. Keep analyst notes, ticket/incident ID, owner, reason and evidence externally where needed for durable audit. Provider updates can reset some states and create new findings.
Automation rules can normalize severity, workflow, notes or routing according to criteria. Rule order matters when multiple rules update the same field, and rules act on new/updated provider findings rather than every analyst update. Preview criteria, test overlap/order, version policy and monitor match volume. Broad suppression by title/severity hides real incidents; use narrow resource/context criteria, owner, expiry and sampling review.
Prevent feedback loops. A workflow update can emit another finding event, and remediation can produce CloudTrail activity or new detections. Tag automation origin, ignore self-generated state-only updates when appropriate, retain idempotency, cap attempts and require a terminal/escalated outcome. Never suppress evidence simply to stop a loop.
~~~bash aws guardduty list-detectors aws guardduty list-findings --detector-id DETECTOR --finding-criteria file://criteria.json aws guardduty get-findings --detector-id DETECTOR --finding-ids FINDING_ID aws securityhub get-findings --filters file://filters.json aws events list-rules --event-bus-name default aws sqs get-queue-attributes --queue-url DLQ_URL --attribute-names All ~~~
Workshop and response proof
Given twenty GuardDuty/Security Hub events, correlate updates into incidents, retain distinct resources, calculate business priority, and identify missing Regions/plans. Design delegated administration, aggregation plus local routes, enrichment roles, queue/workflow and custody. For five findings, choose observe, collect, notify, contain with approval or automatic containment and state the reversal/verification proof.
Run a supplied event through duplicate delivery, provider update, analyst state update, target throttling, DLQ redrive and failed containment. Reconcile received, matched, queued, processed, updated, acted, verified and failed counts. Measure detection-to-route, route-to-acknowledgement, containment/verification time, false-positive/suppression age, recurrence, action failure and DLQ age.
Test 24 failures: Region disabled, new account not enabled, protection plan missing, central aggregation lag, account/Region confused, title used as identity, update treated new, duplicate containment, severity alone prioritizes, enrichment role mutates, missing context downgrades, queue unencrypted, DLQ unmonitored, rule too broad, rule order conflict, suppression has no expiry, workflow resolved without verification, provider recurrence ignored, self-update loop, retries repeat destructive action, approval stale, containment destroys evidence, customer impact unchecked, and no reversal.
Cost and acceptance
Price GuardDuty usage/protection plans, Security Hub CSPM, EventBridge, queue/workflow/Lambda, logs, archive/evidence and cross-Region transfer. This lesson creates nothing. Submit organization/Regional coverage, field map, routing/enrichment architecture, state/suppression policy, five response decisions, reconciliation/metrics, IAM boundaries and all diagnoses. Pass requires durable idempotent routing, narrow suppression, authorized reversible containment and verified security/customer outcomes.