policy-reporter
policy-reporter copied to clipboard
Export policy violations to AWS Security Hub
Hi,
I am exploring ways to export policy violations to AWS Security Hub. Is this something you've considered as part of this project? Are you aware of any other approach to achieve that?
Thanks!
Hey, because I don't use AWS I am not aware of this tool. Do you have an API or something to consider? Then I am happy to have a look on it and how to implement it as new target.
Hey @fjogeleit, there's this link to Security Hub API reference: https://docs.aws.amazon.com/securityhub/1.0/APIReference/Welcome.html
I am not very familiar with it either myself. I've seen Trivy does support integration with Security Hub, and what they do is generating a report with format ASFF, which then can be pushed to Security Hub https://github.com/aquasecurity/trivy/blob/main/docs/tutorials/integrations/aws-security-hub.md
thanks, I will check it in the upcoming weeks and if there is a good way to integrate it
First draft of the AWS securityhub integration. Its a new target which pushes new results to the security hub via the AWS SDK
data:image/s3,"s3://crabby-images/0b18a/0b18a421b8c0dddbac8e78b51ba9f5d5a4529aa8" alt="Bildschirmfoto 2023-04-09 um 16 40 50"
data:image/s3,"s3://crabby-images/8cb52/8cb52a2576a2a03f1e3dfdca0eff52f855fb3283" alt="Bildschirmfoto 2023-04-09 um 16 41 04"
data:image/s3,"s3://crabby-images/0d3fe/0d3fed3c18b1faff59cc2670f37a5c9203d088bf" alt="Bildschirmfoto 2023-04-09 um 16 41 23"