# P12 cross-service security finding triage workbook

Use with AWS239. This is a read-only supplied-evidence exercise. Never retrieve a
sensitive object, run malware, exploit a vulnerability, or contain a live resource
without separate incident authority.

## 1. Coverage before findings

| Service | Administrator/member model | Accounts/OUs | Regions | Enabled telemetry/scanning/discovery | Exclusions/gaps | Cost owner | Last health/coverage proof |
|---|---|---|---|---|---|---|---|
| GuardDuty |  |  |  | foundational + protection plans |  |  |  |
| Inspector |  |  |  | EC2/ECR/Lambda/code repositories |  |  |  |
| Security Hub CSPM |  |  |  | standards/controls/products/aggregation |  |  |  |
| Macie |  |  |  | S3 inventory/automated discovery/jobs |  |  |  |

A zero finding count proves nothing until enabled accounts, Regions, resource
coverage, telemetry freshness, permissions and service health are proved.

## 2. Canonical case record

- Internal case ID:
- Detection service and native finding ID/ARN:
- Security Hub product ARN + ASFF ID, if imported:
- Account, Region and first/last observed UTC:
- Affected resource and business/data owner:
- Finding type/title/category:
- Native severity/score and calculation source:
- Security Hub normalized severity:
- Current native status:
- ASFF `RecordState` and `Workflow.Status`:
- Suppression/archive rule that matched, if any:
- Handling classification and redactions:

## 3. Service-specific evidence

### GuardDuty

- Detector ID and status:
- Foundational source/protection plan that produced the finding:
- Resource, actor, action, service and network details:
- Finding count/updated time and archived state:
- Extended Threat Detection sequence membership:
- Malware/runtime scan evidence and coverage status:
- Related CloudTrail, DNS, flow, runtime and workload evidence:

### Amazon Inspector

- Scan type/resource coverage and last scanned time:
- Package/layer/image/repository and vulnerable version:
- CVE/CVSS source and Inspector score/vector:
- EPSS/exploit-available/fix-available evidence:
- Network reachability/path and runtime exposure:
- Image in-use/age and application criticality:
- Rescan/closure condition:

### Security Hub CSPM

- Finding provider/product and ASFF schema fields:
- Control ID/standard or integration source:
- `Compliance.Status`, related requirements and resource details:
- Aggregation Region/linkage and original finding Region:
- Automation rule updates applied before EventBridge:
- Workflow: NEW/NOTIFIED/RESOLVED/SUPPRESSED and owner rationale:
- Record state: ACTIVE/ARCHIVED and provider reason:

### Amazon Macie

- Policy or sensitive-data finding:
- Bucket/object ownership, public/external sharing and encryption:
- Discovery source: automated sampling or named job:
- Managed/custom data identifier and occurrence evidence:
- Discovery-result S3 repository and access authority:
- Sampling, unsupported object/type/size, permission or job gaps:
- Privacy/legal owner and safe validation method:

## 4. Risk triage (do not copy severity)

| Factor | Evidence | Rating/rationale |
|---|---|---|
| asset and business criticality |  |  |
| internet/cross-account/reachable exposure |  |  |
| credential privilege and blast radius |  |  |
| active behavior or exploitation |  |  |
| exploit maturity/EPSS/fix availability |  |  |
| sensitive-data type/volume/regulatory duty |  |  |
| persistence/lateral movement/data loss |  |  |
| confidence/false-positive alternatives |  |  |
| compensating controls |  |  |
| required response SLA |  |  |

- Final priority and why it differs from/native severity:
- Incident versus vulnerability/privacy backlog decision:
- Evidence preservation required before containment:

## 5. Correlation timeline

| UTC | Native finding/update | CloudTrail/network/runtime/scan/data evidence | ASFF/automation change | Analyst interpretation |
|---|---|---|---|---|
|  |  |  |  |  |

Deduplicate by provider product ARN + finding ID, resource, type and time. Do not
merge separate occurrences merely because titles are similar.

## 6. Response plan

| Phase | Exact action | Owner/approval | Expected evidence | Rollback/business impact |
|---|---|---|---|---|
| preserve |  |  |  |  |
| contain |  |  |  |  |
| eradicate/remediate |  |  |  |  |
| recover |  |  |  |  |
| verify/rescan |  |  |  |  |

- Credentials/keys/sessions to revoke or rotate:
- Network/isolation and evidence-access boundary:
- Patch/package/image/function deployment path:
- S3 access/data handling correction:
- Root cause/control correction:
- Customer/legal/privacy notification decision owner:

## 7. Suppression, exception and closure

| Mechanism | Exact filter/scope | Why not remediation | Owner | Expiry/review | Downstream visibility effect |
|---|---|---|---|---|---|
| GuardDuty archive |  |  |  |  |  |
| Inspector suppression |  |  |  |  |  |
| Security Hub workflow suppression |  |  |  |  |  |
| Macie suppression rule |  |  |  |  | EventBridge/Security Hub publishing can stop |

Closure requires:

- source configuration/package/data exposure corrected;
- new scan/detection/service evidence rather than only analyst status;
- no continuing indicators across the complete time window;
- related findings/cases reconciled;
- `Workflow.Status=RESOLVED` used only for completed investigation;
- suppression/exception removed or time-bounded with accepted-risk owner;
- lessons learned and preventive control assigned;
- retained evidence and temporary investigation access cleaned up.

## 8. Cost and no-create evidence

- GuardDuty data-source/protection-plan units and trial status:
- Inspector scanned EC2/image/function/repository units:
- Security Hub checks/findings/automation and Config dependencies:
- Macie bucket inventory, automated discovery and job data volume:
- EventBridge, Lambda, Step Functions, logs, S3, KMS and SIEM costs:
- Before/after detector/scanner/hub/Macie and finding inventories:
- No finding status, suppression rule, resource or service setting changed:
