[{"data":1,"prerenderedAt":86},["ShallowReactive",2],{"pattern-securityhub-finding-sfn-remediation-cdk":3,"pattern-group-securityhub-finding-sfn-remediation-cdk":85},{"id":4,"title":5,"architectureURL":6,"cleanup":7,"contributors":11,"deploy":13,"description":17,"extension":18,"framework":19,"gitHub":20,"highlight":6,"introBox":26,"language":32,"level":33,"meta":34,"patternArch":35,"patternGroup":6,"patternGroupLabel":6,"resources":69,"s3URL":6,"services":6,"stem":77,"testing":78,"videoId":6,"__hash__":84},"patterns\u002Fpatterns\u002Fsecurityhub-finding-sfn-remediation-cdk.json","AWS Security Hub Auto-Remediation with AWS Step Functions",null,{"text":8},[9,10],"\u003Ccode>cd securityhub-finding-sfn-remediation-cdk\u003C\u002Fcode>","\u003Ccode>cdk destroy\u003C\u002Fcode>",[12],"content\u002Fcontributors\u002Fnithin-chandran-r.json",{"text":14},[9,15,16],"\u003Ccode>npm install\u003C\u002Fcode>","\u003Ccode>cdk deploy\u003C\u002Fcode>","Auto-remediate HIGH\u002FCRITICAL Security Hub findings using AWS Step Functions and AWS Lambda to close open security groups and block public S3 access","json","AWS CDK",{"template":21},{"repoURL":22,"templateURL":23,"projectFolder":24,"templateFile":25},"https:\u002F\u002Fgithub.com\u002Faws-samples\u002Fserverless-patterns\u002Ftree\u002Fmain\u002Fsecurityhub-finding-sfn-remediation-cdk","serverless-patterns\u002Fsecurityhub-finding-sfn-remediation-cdk","securityhub-finding-sfn-remediation-cdk","lib\u002Fsecurityhub-finding-sfn-remediation-stack.ts",{"headline":27,"text":28},"How it works",[29,30,31],"AWS Security Hub detects HIGH or CRITICAL findings such as open security groups or public Amazon S3 buckets.","Amazon EventBridge captures the finding and triggers an AWS Step Functions workflow that classifies the finding type.","AWS Lambda executes targeted remediation (revoke open ingress rules, enable S3 public access block) and Amazon SNS notifies the security team.","TypeScript","300",{},{"icon1":36,"icon2":41,"icon3":44,"icon4":48,"icon5":53,"line1":57,"line2":61,"line3":63,"line4":66},{"x":37,"y":38,"service":39,"label":40},15,40,"security-hub","AWS Security Hub",{"x":38,"y":38,"service":42,"label":43},"sfn","AWS Step Functions",{"x":45,"y":38,"service":46,"label":47},62,"lambda","AWS Lambda",{"x":49,"y":50,"service":51,"label":52},88,18,"sns","Amazon SNS",{"x":49,"y":54,"service":55,"label":56},68,"ec2","Amazon EC2 \u002F S3",{"from":58,"to":59,"label":60},"icon1","icon2","",{"from":59,"to":62,"label":60},"icon3",{"from":62,"to":64,"label":65},"icon4","notify",{"from":62,"to":67,"label":68},"icon5","remediate",{"bullets":70},[71,74],{"text":72,"link":73},"AWS Security Hub automated response and remediation","https:\u002F\u002Fdocs.aws.amazon.com\u002Fsecurityhub\u002Flatest\u002Fuserguide\u002Fsecurityhub-cloudwatch-events.html",{"text":75,"link":76},"AWS Step Functions service integrations","https:\u002F\u002Fdocs.aws.amazon.com\u002Fstep-functions\u002Flatest\u002Fdg\u002Fconnect-supported-services.html","patterns\u002Fsecurityhub-finding-sfn-remediation-cdk",{"text":79},[80,81,82,83],"Create an intentionally open security group (0.0.0.0\u002F0 on port 22).","Wait for AWS Security Hub to detect the finding (~15 minutes).","Verify the AWS Step Functions execution completed and the security group was closed.","Subscribe to the Amazon SNS topic to receive remediation alerts.","0yl4vgdIbiTDuQMLlH8OvP5kly6u7WKVcC2jGTHO46Y",[],1790246099459]