#RSAC26CISO SafeSpace at RSAC26
Integrations/AWS Security Hub
AWS Security Hub
Cloud Platforms

AWS Security Hub

AWS Security Hub findings, autonomously investigated and resolved by Alaris.

Better Together

Alaris + AWS Security Hub

AWS Security Hub aggregates findings from GuardDuty, Inspector, Macie, and dozens of third-party tools. Alaris subscribes to Security Hub events and autonomously investigates every finding, enriching with CloudTrail, VPC Flow Logs, and AWS Config, then executes response actions across your AWS environment.

Integration Details

Category

Cloud Platforms

Built by

Alaris Security

Compatible with

Alaris CDRSecurity WorkbenchAI Agents

Key Capabilities

What you get with this integration

01

Multi-service finding ingestion

GuardDuty, Inspector, Macie, and partner findings all flow into Alaris automatically.

02

CloudTrail enrichment

Every finding is enriched with CloudTrail events to build a complete attack narrative.

03

Automated AWS remediation

Alaris can revoke IAM credentials, modify security groups, and quarantine instances automatically.

04

Multi-account support

Manage Security Hub findings across hundreds of AWS accounts from a single Alaris workspace.

Setup

How it works

1

Connect

Grant Alaris an IAM role with read access to Security Hub, CloudTrail, and your response targets.

2

Subscribe

Alaris subscribes to Security Hub findings via EventBridge for real-time ingestion.

3

Enrich

Each finding is enriched with CloudTrail, Config, and VPC Flow Log context.

4

Remediate

Alaris executes AWS API calls to contain and remediate threats automatically.

Related integrations

Azure Security

Azure Security

Cloud security posture management for Azure

Okta

Okta

Identity and access management platform

Microsoft Sentinel

Microsoft Sentinel

Cloud-native SIEM and SOAR platform

Your stack, connected. Your threats, eliminated.