AWS Security Hub
| eventName | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all entry for AWS Security Hub rules that match the service but not a specific eventName. | N | N |
| Batch | Updates one or more findings in AWS Security Hub with customer-defined fields such as severity, criticality, and workflow status. | Y | Y |
| Delete | Deletes a Security Hub insight identified by the specified ARN. | Y | Y |
| Update | Updates the Note and RecordState of one or more Security Hub findings. | Y | Y |
| Update | Updates a Security Hub insight identified by the specified ARN. | Y | Y |
| Accept | We recommend using Organizations instead of Security Hub CSPM invitations to manage your member accounts. | N | N |
| Accept | This method is deprecated. | N | N |
| Batch | Deletes one or more automation rules. | Y | N |
| Batch | Disables the standards specified by the provided StandardsSubscriptionArns. | Y | N |
| Batch | Enables the standards specified by the provided StandardsArn. | Y | N |
| Batch | Retrieves a list of details for automation rules based on rule Amazon Resource Names (ARNs). | Y | N |
| Batch | Returns associations between an Security Hub CSPM configuration and a batch of target accounts, organizational units, or the root. | Y | N |
| Batch | Provides details about a batch of security controls for the current Amazon Web Services account and Amazon Web Services Region. | Y | N |
| Batch | For a batch of security controls and standards, identifies whether each control is currently enabled or disabled in a standard. | Y | N |
| Batch | Imports security findings generated by a finding provider into Security Hub CSPM. | Y | N |
| Batch | Updates one or more automation rules based on rule Amazon Resource Names (ARNs) and input parameters. | Y | N |
| Batch | Updates information about a customer's investigation into a finding. | Y | N |
| Batch | For a batch of security controls and standards, this operation updates the enablement status of a control in a standard. | Y | N |
| Create | Creates a custom action target in Security Hub CSPM. | Y | N |
| Create | Enables aggregation across Amazon Web Services Regions. | Y | N |
| Create | Creates an automation rule based on input parameters. | Y | N |
| Create | Creates a V2 automation rule. | Y | N |
| Create | Creates a configuration policy with the defined configuration. | N | N |
| Create | Grants permission to create a connectorV2 based on input parameters. | Y | N |
| Create | The aggregation Region is now called the home Region. | Y | N |
| Create | Creates a custom insight in Security Hub CSPM. | Y | N |
| Create | Creates a member association in Security Hub CSPM between the specified accounts and the account used to make the request, which is the administrator account. | N | N |
| Create | Grants permission to create a ticket in the chosen ITSM based on finding information for the provided finding metadata UID. | N | N |
| Decline | We recommend using Organizations instead of Security Hub CSPM invitations to manage your member accounts. | N | N |
| Delete | Deletes a custom action target from Security Hub CSPM. | Y | N |
| Delete | Deletes the Aggregator V2. | Y | N |
| Delete | Deletes a V2 automation rule. | Y | N |
| Delete | Deletes a configuration policy. | Y | N |
| Delete | Grants permission to delete a connectorV2. | Y | N |
| Delete | The aggregation Region is now called the home Region. | Y | N |
| Delete | We recommend using Organizations instead of Security Hub CSPM invitations to manage your member accounts. | Y | N |
| Delete | Deletes the specified member accounts from Security Hub CSPM. | Y | N |
| Describe | Returns a list of the custom action targets in Security Hub CSPM in your account. | Y | N |
| Describe | Returns details about the Hub resource in your account, including the HubArn and the time when you enabled Security Hub CSPM. | Y | N |
| Describe | Returns information about the way your organization is configured in Security Hub CSPM. | Y | N |
| Describe | Returns information about product integrations in Security Hub CSPM. | Y | Y |
| Describe | Gets information about the product integration. | Y | N |
| Describe | Returns details about the service resource in your account. | Y | N |
| Describe | Returns a list of the available standards in Security Hub CSPM. | Y | Y |
| Describe | Returns a list of security standards controls. | Y | Y |
| Disable | Disables the integration of the specified product with Security Hub CSPM. | Y | N |
| Disable | Disables a Security Hub CSPM administrator account. | Y | N |
| Disable | Disables Security Hub CSPM in your account only in the current Amazon Web Services Region. | Y | N |
| Disable | Disable the service for the current Amazon Web Services Region or specified Amazon Web Services Region. | Y | N |
| Disassociate | Disassociates the current Security Hub CSPM member account from the associated administrator account. | Y | N |
| Disassociate | This method is deprecated. | Y | N |
| Disassociate | Disassociates the specified member accounts from the associated administrator account. | Y | N |
| Enable | Enables the integration of a partner product with Security Hub CSPM. | Y | N |
| Enable | Designates the Security Hub CSPM administrator account for an organization. | N | N |
| Enable | Enables Security Hub CSPM for your account in the current Region or the Region you specify in the request. | Y | N |
| Enable | Enables the service in account for the current Amazon Web Services Region or specified Amazon Web Services Region. | Y | N |
| Generate | Begins the recommended policy generation to remediate a Security Hub finding. | N | N |
| Get | Provides the details for the Security Hub CSPM administrator account for the current member account. | Y | N |
| Get | Returns the configuration of the specified Aggregator V2. | Y | N |
| Get | Returns an automation rule for the V2 service. | Y | N |
| Get | Provides information about a configuration policy. | Y | N |
| Get | Returns the association between a configuration and a target account, organizational unit, or the root. | Y | N |
| Get | Grants permission to retrieve details for a connectorV2 based on connector id. | Y | N |
| Get | Returns a list of the standards that are currently enabled. | Y | N |
| Get | The aggregation Region is now called the home Region. | Y | N |
| Get | Returns the history of a Security Hub CSPM finding. | Y | N |
| Get | Returns a list of findings that match the specified criteria. | Y | N |
| Get | Returns aggregated statistical data about findings. | Y | N |
| Get | Returns findings trend data based on the specified criteria. | Y | N |
| Get | Returns a list of findings that match the specified criteria. | Y | N |
| Get | Lists the results of the Security Hub CSPM insight specified by the insight ARN. | Y | N |
| Get | Lists and describes insights for the specified insight ARNs. | Y | N |
| Get | We recommend using Organizations instead of Security Hub CSPM invitations to manage your member accounts. | Y | N |
| Get | This method is deprecated. | Y | N |
| Get | Returns the details for the Security Hub CSPM member accounts for the specified account IDs. | Y | N |
| Get | Retrieves the recommended policy to remediate a Security Hub finding. | Y | N |
| Get | Retrieves statistical information about Amazon Web Services resources and their associated security findings. | Y | N |
| Get | Returns resource trend data based on the specified criteria. | Y | N |
| Get | Returns a list of resources. | Y | N |
| Get | Retrieves the definition of a security control. | Y | N |
| Invite | We recommend using Organizations instead of Security Hub CSPM invitations to manage your member accounts. | N | N |
| List | Retrieves a list of V2 aggregators. | Y | N |
| List | A list of automation rules and their metadata for the calling account. | Y | N |
| List | Returns a list of automation rules and metadata for the calling account. | Y | N |
| List | Lists the configuration policies that the Security Hub CSPM delegated administrator has created for your organization. | Y | N |
| List | Provides information about the associations for your configuration policies and self-managed behavior. | Y | N |
| List | Grants permission to retrieve a list of connectorsV2 and their metadata for the calling account. | Y | N |
| List | Lists all findings-generating solutions (products) that you are subscribed to receive findings from in Security Hub CSPM. | Y | N |
| List | If cross-Region aggregation is enabled, then ListFindingAggregators returns the Amazon Resource Name (ARN) of the finding aggregator. | Y | N |
| List | We recommend using Organizations instead of Security Hub CSPM invitations to manage your member accounts. | Y | N |
| List | Lists details about all member accounts for the current Security Hub CSPM administrator account. | Y | N |
| List | Lists the Security Hub CSPM administrator accounts. | Y | N |
| List | Lists all of the security controls that apply to a specified standard. | Y | N |
| List | Specifies whether a control is currently enabled or disabled in each enabled standard in the calling account. | Y | N |
| List | Returns a list of tags associated with a resource. | Y | N |
| Register | Grants permission to complete the authorization based on input parameters. | N | N |
| Start | Associates a target account, organizational unit, or the root with a specified configuration. | N | N |
| Start | Disassociates a target account, organizational unit, or the root from a specified configuration. | N | N |
| Tag | Adds one or more tags to a resource. | Y | N |
| Untag | Removes one or more tags from a resource. | Y | N |
| Update | Updates the name and description of a custom action target in Security Hub CSPM. | Y | N |
| Update | Udpates the configuration for the Aggregator V2. | Y | N |
| Update | Updates a V2 automation rule. | Y | N |
| Update | Updates a configuration policy. | Y | N |
| Update | Grants permission to update a connectorV2 based on its id and input parameters. | Y | N |
| Update | The aggregation Region is now called the home Region. | Y | N |
| Update | Updates the configuration of your organization in Security Hub CSPM. | Y | N |
| Update | Updates the properties of a security control. | Y | N |
| Update | Updates configuration options for Security Hub CSPM. | Y | N |
| Update | Used to control whether an individual security standard control is enabled or disabled. | Y | N |
| Get | GetControlFindingSummary recorded by CloudTrail for AWS Security Hub. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Create | Creates a connector to a third-party cloud provider in Security Hub CSPM. | N | N |
| Delete | Deletes a CSPM connector. | N | N |
| Disable | Disables an opt-in feature for the calling account in the current Amazon Web Services Region. | N | N |
| Enable | Enables an opt-in feature for the calling account in the current Amazon Web Services Region. | N | N |
| Get | Retrieves details for a CSPM connector based on the connector ID. | N | N |
| List | Lists the CSPM connectors and their metadata for the calling account. | N | N |
| List | Lists the free trial status of Security Hub features. | N | N |
| Update | Updates a CSPM connector's configuration, such as the scope or regions for the connected cloud provider. | N | N |
any: AWS Security Hub (catch-all)
#Description
Catch-all entry for AWS Security Hub rules that match the service but not a specific eventName.
BatchUpdateFindings
#Description
Updates one or more findings in AWS Security Hub with customer-defined fields such as severity, criticality, and workflow status.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "c41ebf76-6ace-4812-84e3-111dd45d6094",
"eventName": "BatchUpdateFindings",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T21:48:41Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "921aa830-1860-4ce0-a4a3-b47a183823dd",
"requestParameters": {
"FindingIdentifiers": [
{
"Id": "dwfix-capture-finding-001",
"ProductArn": "arn:aws:securityhub:us-west-1:123456789012:product/123456789012/default"
}
],
"Note": {
"Text": "DW capture test note",
"UpdatedBy": "dwfix"
},
"Workflow": {
"Status": "NEW"
}
},
"responseElements": {
"ProcessedFindings": [],
"UnprocessedFindings": [
{
"ErrorCode": "FindingNotFound",
"ErrorMessage": "Finding Not Found",
"FindingIdentifier": {
"Id": "dwfix-capture-finding-001",
"ProductArn": "arn:aws:securityhub:us-west-1:123456789012:product/123456789012/default"
}
}
]
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1685↳ also matches DeleteInsight, UpdateFindings, UpdateInsight Panther #
T1562↳ also matches DeleteInsight, UpdateFindings, UpdateInsight
DeleteInsight
#Description
Deletes a Security Hub insight identified by the specified ARN.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidAccessException",
"eventCategory": "Management",
"eventID": "ae3bf0ad-a576-4009-8495-e64afc6a67b9",
"eventName": "DeleteInsight",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T19:26:36Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "429c0531-f15e-4d70-bf9f-ba689da9d040",
"requestParameters": {
"InsightArn": "dw-probe"
},
"responseElements": {
"Code": "InvalidAccessException",
"Message": "Account 123456789012 is not subscribed to AWS Security Hub",
"RequestId": "1251c9e7-f9a2-44c4-81cf-983ed7e72a0a",
"Type": "InvalidAccessException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1685↳ also matches BatchUpdateFindings, UpdateFindings, UpdateInsight Panther #
T1562↳ also matches BatchUpdateFindings, UpdateFindings, UpdateInsight
UpdateFindings
#Description
Updates the Note and RecordState of one or more Security Hub findings.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidAccessException",
"eventCategory": "Management",
"eventID": "d145c888-466c-463f-8587-6fd978b22b95",
"eventName": "UpdateFindings",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T19:26:36Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "c481c0c5-5033-4de5-8aa7-5a6e38b76ac1",
"requestParameters": {
"Filters": {}
},
"responseElements": {
"Code": "InvalidAccessException",
"Message": "Account 123456789012 is not subscribed to AWS Security Hub",
"RequestId": "72efe093-a4b8-4cd9-a5f3-eea2c0261bf1",
"Type": "InvalidAccessException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1685↳ also matches BatchUpdateFindings, DeleteInsight, UpdateInsight Panther #
T1562↳ also matches BatchUpdateFindings, DeleteInsight, UpdateInsight
UpdateInsight
#Description
Updates a Security Hub insight identified by the specified ARN.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidAccessException",
"eventCategory": "Management",
"eventID": "75e65e36-d39c-4756-a6f0-11bc400bc4ce",
"eventName": "UpdateInsight",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T19:26:37Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "2929fc6a-4afa-4fa7-9d1d-da9adcf6f0c4",
"requestParameters": {
"InsightArn": "dw-probe"
},
"responseElements": {
"Code": "InvalidAccessException",
"Message": "Account 123456789012 is not subscribed to AWS Security Hub",
"RequestId": "a3a09f60-267a-49fb-bf54-f9ca3c9f1136",
"Type": "InvalidAccessException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1685↳ also matches BatchUpdateFindings, DeleteInsight, UpdateFindings Panther #
T1562↳ also matches BatchUpdateFindings, DeleteInsight, UpdateFindings
AcceptAdministratorInvitation
#Description
We recommend using Organizations instead of Security Hub CSPM invitations to manage your member accounts.
AcceptInvitation
#Description
This method is deprecated.
BatchDeleteAutomationRules
#Description
Deletes one or more automation rules.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "29348289-186c-404e-843f-caf855c840ed",
"eventName": "BatchDeleteAutomationRules",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T21:48:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "27063865-0e49-46dc-8875-25de89b2acc3",
"requestParameters": {
"AutomationRulesArns": [
"arn:aws:securityhub:us-west-1:123456789012:automation-rule/5b7689e4-2206-4cde-8f6b-48991b12b4a2"
]
},
"responseElements": {
"ProcessedAutomationRules": [
"arn:aws:securityhub:us-west-1:123456789012:automation-rule/5b7689e4-2206-4cde-8f6b-48991b12b4a2"
],
"UnprocessedAutomationRules": []
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
BatchDisableStandards
#Description
Disables the standards specified by the provided StandardsSubscriptionArns.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "01a0a21a-883c-43bb-97f6-c43a1393f373",
"eventName": "BatchDisableStandards",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T21:48:48Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "4a558898-2f6a-491e-a9d2-eb1352f2fa69",
"requestParameters": {
"StandardsSubscriptionArns": [
"arn:aws:securityhub:us-west-1:123456789012:subscription/aws-foundational-security-best-practices/v/1.0.0"
]
},
"responseElements": {
"StandardsSubscriptions": [
{
"StandardsArn": "arn:aws:securityhub:us-west-1::standards/aws-foundational-security-best-practices/v/1.0.0",
"StandardsControlsUpdatable": "NOT_READY_FOR_UPDATES",
"StandardsInput": {},
"StandardsStatus": "DELETING",
"StandardsSubscriptionArn": "arn:aws:securityhub:us-west-1:123456789012:subscription/aws-foundational-security-best-practices/v/1.0.0"
}
]
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
BatchEnableStandards
#Description
Enables the standards specified by the provided StandardsArn.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "1066dd24-86b9-4a03-a4cf-b488c74a5908",
"eventName": "BatchEnableStandards",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T21:48:34Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "6f1ef50e-cb42-42e5-ac8b-7aef54bb10db",
"requestParameters": {
"StandardsSubscriptionRequests": [
{
"StandardsArn": "arn:aws:securityhub:us-west-1::standards/aws-foundational-security-best-practices/v/1.0.0"
}
]
},
"responseElements": {
"StandardsSubscriptions": [
{
"StandardsArn": "arn:aws:securityhub:us-west-1::standards/aws-foundational-security-best-practices/v/1.0.0",
"StandardsControlsUpdatable": "NOT_READY_FOR_UPDATES",
"StandardsInput": {},
"StandardsStatus": "PENDING",
"StandardsSubscriptionArn": "arn:aws:securityhub:us-west-1:123456789012:subscription/aws-foundational-security-best-practices/v/1.0.0"
}
]
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
BatchGetAutomationRules
#Description
Retrieves a list of details for automation rules based on rule Amazon Resource Names (ARNs).
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "94b79659-2f92-45e2-96b4-2c4e22ce3ddc",
"eventName": "BatchGetAutomationRules",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:46:08Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "f08e27e7-af88-493f-bc5f-7282e5658c0c",
"requestParameters": {
"AutomationRulesArns": [
"dw-probe"
]
},
"responseElements": {
"message": "User: arn:aws:iam::123456789012:user/sample-user is not authorized to perform: securityhub:BatchGetAutomationRules on resource: * with an explicit deny in a resource-based policy"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
BatchGetConfigurationPolicyAssociations
#Description
Returns associations between an Security Hub CSPM configuration and a batch of target accounts, organizational units, or the root.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "a4eb36d1-039f-46c6-82a4-e293efc4ae34",
"eventName": "BatchGetConfigurationPolicyAssociations",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:46:08Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "504b6a19-c108-4cdb-894f-c90ca7286525",
"requestParameters": {
"ConfigurationPolicyAssociationIdentifiers": [
{}
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
BatchGetSecurityControls
#Description
Provides details about a batch of security controls for the current Amazon Web Services account and Amazon Web Services Region.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidAccessException",
"eventCategory": "Management",
"eventID": "c00cee83-117f-47d4-acf5-38cb7f22e026",
"eventName": "BatchGetSecurityControls",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:46:08Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "a34cae3b-6c70-4065-8129-5e25fae9d89d",
"requestParameters": {
"SecurityControlIds": [
"dw-probe"
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
BatchGetStandardsControlAssociations
#Description
For a batch of security controls and standards, identifies whether each control is currently enabled or disabled in a standard.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidAccessException",
"eventCategory": "Management",
"eventID": "440c7019-5e10-423c-8619-006c1e49879c",
"eventName": "BatchGetStandardsControlAssociations",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:46:08Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "ce2ed90e-44c9-4e64-ae8c-c34648068ca3",
"requestParameters": {
"StandardsControlAssociationIds": [
{
"SecurityControlId": "dw-probe",
"StandardsArn": "dw-probe"
}
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
BatchImportFindings
#Description
Imports security findings generated by a finding provider into Security Hub CSPM.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "78f20a8b-4b51-4b78-96fe-38c5b8656d46",
"eventName": "BatchImportFindings",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T21:48:41Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "db35031c-4afc-4acb-a489-fd7e6220ecb2",
"requestParameters": {
"Findings": "***"
},
"responseElements": {
"FailedCount": 0,
"FailedFindings": [],
"SuccessCount": 1
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
BatchUpdateAutomationRules
#Description
Updates one or more automation rules based on rule Amazon Resource Names (ARNs) and input parameters.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "aaafe5f6-d254-4aa7-bf56-3e026b545f39",
"eventName": "BatchUpdateAutomationRules",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T21:48:34Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "f95d2110-b5c1-42e3-87e5-4c40a11ee4a9",
"requestParameters": {
"UpdateAutomationRulesRequestItems": [
{
"Description": "DW capture test automation rule (updated)",
"RuleArn": "arn:aws:securityhub:us-west-1:123456789012:automation-rule/5b7689e4-2206-4cde-8f6b-48991b12b4a2",
"RuleStatus": "DISABLED"
}
]
},
"responseElements": {
"ProcessedAutomationRules": [
"arn:aws:securityhub:us-west-1:123456789012:automation-rule/5b7689e4-2206-4cde-8f6b-48991b12b4a2"
],
"UnprocessedAutomationRules": []
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
BatchUpdateFindingsV2
#Description
Updates information about a customer's investigation into a finding.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "e54d9a4c-5a8f-4610-9818-df6cbd7ffaf7",
"eventName": "BatchUpdateFindingsV2",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T21:48:45Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "b5d0226d-5e4a-48e1-97df-d2722182bb98",
"requestParameters": {
"Comment": "DW capture test V2 update",
"FindingIdentifiers": [
{
"CloudAccountUid": "123456789012",
"FindingInfoUid": "dwfix-capture-finding-v2-001",
"MetadataProductUid": "arn:aws:securityhub:us-west-1:123456789012:product/123456789012/default"
}
],
"StatusId": 3
},
"responseElements": {
"ProcessedFindings": [],
"UnprocessedFindings": [
{
"ErrorCode": "ResourceNotFoundException",
"ErrorMessage": "Finding not found",
"FindingIdentifier": {
"CloudAccountUid": "123456789012",
"FindingInfoUid": "dwfix-capture-finding-v2-001",
"MetadataProductUid": "arn:aws:securityhub:us-west-1:123456789012:product/123456789012/default"
}
}
]
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
BatchUpdateStandardsControlAssociations
#Description
For a batch of security controls and standards, this operation updates the enablement status of a control in a standard.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "d6f25e6c-a1ef-4add-a32e-a14a3b51dfa9",
"eventName": "BatchUpdateStandardsControlAssociations",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T21:48:40Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "5940c5bb-7684-4fce-a386-054cb3dd49b3",
"requestParameters": {
"StandardsControlAssociationUpdates": [
{
"AssociationStatus": "DISABLED",
"SecurityControlId": "IAM.1",
"StandardsArn": "arn:aws:securityhub:us-west-1::standards/aws-foundational-security-best-practices/v/1.0.0",
"UpdatedReason": "DW capture test"
}
]
},
"responseElements": {
"UnprocessedAssociationUpdates": [
{
"ErrorCode": "RESOURCE_NOT_FOUND",
"ErrorReason": "The standard subscription associated with this control currently has StandardsControlsUpdatable: NOT_READY_FOR_UPDATES. Please try again later.",
"StandardsControlAssociationUpdate": {
"AssociationStatus": "DISABLED",
"SecurityControlId": "IAM.1",
"StandardsArn": "arn:aws:securityhub:us-west-1::standards/aws-foundational-security-best-practices/v/1.0.0",
"UpdatedReason": "DW capture test"
}
}
]
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateActionTarget
#Description
Creates a custom action target in Security Hub CSPM.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "61d90a2c-886a-4312-877c-75f9253e1253",
"eventName": "CreateActionTarget",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T21:48:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "ef1e4141-49cd-4bb0-a10c-8a1cbf762dfa",
"requestParameters": {
"Description": "DW capture test custom action",
"Id": "dwfixCapture",
"Name": "dwfixCapture"
},
"responseElements": {
"ActionTargetArn": "arn:aws:securityhub:us-west-1:123456789012:action/custom/dwfixCapture"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateAggregatorV2
#Description
Enables aggregation across Amazon Web Services Regions.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "5a51893a-785c-43de-b6b9-d8f834b427af",
"eventName": "CreateAggregatorV2",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T21:48:43Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "c4e109ed-46a6-45fc-bd19-d2bf2e03764e",
"requestParameters": {
"ClientToken": "e8d7dc65-c336-4be0-a5c5-e31494d4646e",
"LinkedRegions": [
"us-east-2"
],
"RegionLinkingMode": "SPECIFIED_REGIONS",
"Tags": {
"dwfix": "capture"
}
},
"responseElements": {
"AggregationRegion": "us-west-1",
"AggregatorV2Arn": "arn:aws:securityhub:us-west-1:123456789012:aggregatorv2/c94697bf-40c7-4446-bc93-92915d332b9b",
"LinkedRegions": [
"us-east-2"
],
"RegionLinkingMode": "SPECIFIED_REGIONS"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateAutomationRule
#Description
Creates an automation rule based on input parameters.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "b0506d40-a0e1-42c8-82d8-300c6e13823d",
"eventName": "CreateAutomationRule",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T21:48:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "c6f22984-4aea-4926-ab84-64d26cd3ceb7",
"requestParameters": {
"Actions": [
{
"FindingFieldsUpdate": {
"VerificationState": "BENIGN_POSITIVE",
"Workflow": {
"Status": "SUPPRESSED"
}
},
"Type": "FINDING_FIELDS_UPDATE"
}
],
"Criteria": {
"AwsAccountId": [
{
"Comparison": "EQUALS",
"Value": "123456789012"
}
],
"SeverityLabel": [
{
"Comparison": "EQUALS",
"Value": "INFORMATIONAL"
}
]
},
"Description": "DW capture test automation rule",
"IsTerminal": false,
"RuleName": "dwfix-capture-rule",
"RuleOrder": 99,
"RuleStatus": "DISABLED",
"Tags": {
"dwfix": "capture"
}
},
"responseElements": {
"RuleArn": "arn:aws:securityhub:us-west-1:123456789012:automation-rule/5b7689e4-2206-4cde-8f6b-48991b12b4a2"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateAutomationRuleV2
#Description
Creates a V2 automation rule.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"eventCategory": "Management",
"eventID": "ff817b28-95dd-455c-97e2-ca5489680efe",
"eventName": "CreateAutomationRuleV2",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T21:48:45Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "ec0af0b5-ea2e-4162-8db2-237ff0d8fb46",
"requestParameters": {
"Actions": [
{
"FindingFieldsUpdate": {
"Comment": "DW capture test",
"StatusId": 0
},
"Type": "FINDING_FIELDS_UPDATE"
}
],
"ClientToken": "1cf31e47-0dca-45f0-b4ef-d0c09835372d",
"Criteria": {
"OcsfFindingCriteria": {
"CompositeFilters": [
{
"Operator": "AND",
"StringFilters": [
{
"FieldName": "severity",
"Filter": {
"Comparison": "EQUALS",
"Value": "Informational"
}
}
]
}
],
"CompositeOperator": "AND"
}
},
"Description": "DW capture test V2 automation rule",
"RuleName": "dwfix-capture-rule-v2",
"RuleOrder": 99.0,
"RuleStatus": "DISABLED"
},
"responseElements": {
"Code": "ValidationException",
"Message": "Invalid parameter CriteriaConfiguration: data StringFields metadata.uid, severity, status, comment are not supported",
"RequestId": "751271c1-a8c3-4298-9962-5be573d7b4b8",
"Type": "ValidationException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateConfigurationPolicy
#Description
Creates a configuration policy with the defined configuration.
CreateConnectorV2
#Description
Grants permission to create a connectorV2 based on input parameters.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "2fa77337-c7ca-44b5-99fa-bfee4071f962",
"eventName": "CreateConnectorV2",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T21:48:46Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "76f94d27-5458-4239-a759-49e96a0fc3cb",
"requestParameters": {
"ClientToken": "2687f41f-3fbc-4322-abdd-8317773fcdfb",
"Description": "DW capture test connector",
"Name": "dwfix-capture-connector",
"Provider": {
"JiraCloud": {
"ProjectKey": "DWFIX"
}
}
},
"responseElements": {
"AuthUrl": "https://us-west-1.console.aws.amazon.com/securityhub/v2/home?region=us-west-1&redirectUri=https%3A%2F%2F3rdp.oauth.console.api.aws&audience=api.atlassian.com&responseType=code&authState=8f6c45af-732b-464f-ac0d-fee3520434f8&clientId=nia84Xp57298JuUtRZPEVCH6ID7dryzB&connectorId=8acf8aad-999a-630e-8d46-cb4e34e90203&oauthOrigin=https%3A%2F%2Fauth.atlassian.com%2Fauthorize&scope=read%3Ajira-work+manage%3Ajira-project+write%3Ajira-work+offline_access&prompt=consent#/integrations/jira/oauth",
"ConnectorArn": "arn:aws:securityhub:us-west-1:123456789012:connectorv2/8acf8aad-999a-630e-8d46-cb4e34e90203",
"ConnectorId": "8acf8aad-999a-630e-8d46-cb4e34e90203"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateFindingAggregator
#Description
The aggregation Region is now called the home Region.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "063c5853-b9ba-4811-93ad-d43550acf6b5",
"eventName": "CreateFindingAggregator",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T21:48:41Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "33b4f72c-2e19-48f2-abdc-ad30c5d208de",
"requestParameters": {
"RegionLinkingMode": "SPECIFIED_REGIONS",
"Regions": [
"us-east-2"
]
},
"responseElements": {
"FindingAggregationRegion": "us-west-1",
"FindingAggregatorArn": "arn:aws:securityhub:us-west-1:123456789012:finding-aggregator/bccf8aad-90fb-253f-757b-44ccf4cd8c29",
"RegionLinkingMode": "SPECIFIED_REGIONS",
"Regions": [
"us-east-2"
]
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateInsight
#Description
Creates a custom insight in Security Hub CSPM.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "652af486-24b9-4920-8059-ff8c982aa3de",
"eventName": "CreateInsight",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T21:48:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "30a3be71-99ea-4559-b46a-380069c0bfae",
"requestParameters": {
"Filters": {
"AwsAccountId": [
{
"Comparison": "EQUALS",
"Value": "123456789012"
}
],
"SeverityLabel": [
{
"Comparison": "EQUALS",
"Value": "HIGH"
}
]
},
"GroupByAttribute": "SeverityLabel",
"Name": "dwfix-capture-insight"
},
"responseElements": {
"InsightArn": "arn:aws:securityhub:us-west-1:123456789012:insight/123456789012/custom/23b9c117-037a-46ee-b97c-0de9b568917f"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateMembers
#Description
Creates a member association in Security Hub CSPM between the specified accounts and the account used to make the request, which is the administrator account.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "c092d75c-2d3a-456a-aa33-6e7ba351269d",
"eventSource": "securityhub.amazonaws.com",
"eventName": "CreateMembers",
"awsRegion": "ap-northeast-2",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "5efebe93-e5af-4e8c-a9b7-c5bd7dbb3820",
"userAgent": "securityhub.amazonaws.com"
}
CreateTicketV2
#Description
Grants permission to create a ticket in the chosen ITSM based on finding information for the provided finding metadata UID.
DeclineInvitations
#Description
We recommend using Organizations instead of Security Hub CSPM invitations to manage your member accounts.
DeleteActionTarget
#Description
Deletes a custom action target from Security Hub CSPM.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidAccessException",
"eventCategory": "Management",
"eventID": "8175d1e6-92a3-4d48-a18f-19d2f9737f74",
"eventName": "DeleteActionTarget",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T19:26:37Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "4a4af575-c77f-4b41-a48c-66d1d7ab29ec",
"requestParameters": {
"ActionTargetArn": "dw-probe"
},
"responseElements": {
"Code": "InvalidAccessException",
"Message": "Account 123456789012 is not subscribed to AWS Security Hub",
"RequestId": "bf9f1c3f-179d-47bb-90c8-16a1db671ef9",
"Type": "InvalidAccessException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteAggregatorV2
#Description
Deletes the Aggregator V2.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ConflictException",
"eventCategory": "Management",
"eventID": "81d29bb4-c3f4-4aaa-891e-00965d17ffd3",
"eventName": "DeleteAggregatorV2",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T19:26:37Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "5a3af0be-e8c9-4a68-a7b3-750815441dba",
"requestParameters": {
"AggregatorV2Arn": "dw-probe"
},
"responseElements": {
"Code": "ConflictException",
"Message": "Security Hub V2 is not enabled for 123456789012",
"RequestId": "66e7e096-0be3-4969-ac4a-1e28c9bbec61",
"Type": "ConflictException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteAutomationRuleV2
#Description
Deletes a V2 automation rule.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"eventCategory": "Management",
"eventID": "07f2b5af-4c45-4d60-b5ee-2bb3a446ad80",
"eventName": "DeleteAutomationRuleV2",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T19:26:37Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "d0187304-a5ce-400f-9283-77194a79cac8",
"requestParameters": {
"Identifier": "dw-probe"
},
"responseElements": {
"Code": "ValidationException",
"Message": "Invalid format in Identifier",
"RequestId": "5224f3b9-4391-4a51-bf6c-76b8d442ef76",
"Type": "ValidationException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteConfigurationPolicy
#Description
Deletes a configuration policy.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "75d4aefb-2604-4ee4-a71d-b595cd64634d",
"eventName": "DeleteConfigurationPolicy",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T19:26:37Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "6b47a6b9-dc21-4910-9e1c-2623a204fe60",
"requestParameters": {
"Identifier": "dw-probe"
},
"responseElements": {
"message": "User: arn:aws:iam::123456789012:user/sample-user is not authorized to perform: securityhub:DeleteConfigurationPolicy on resource: * with an explicit deny in a resource-based policy"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteConnectorV2
#Description
Grants permission to delete a connectorV2.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"eventCategory": "Management",
"eventID": "337f0857-d73f-4998-89d8-a7d33bcdc0a7",
"eventName": "DeleteConnectorV2",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T19:26:37Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "66bcf46b-fed3-4380-8420-58b43d370f44",
"requestParameters": {
"ConnectorId": "dw-probe"
},
"responseElements": {
"Code": "ValidationException",
"Message": "Invalid parameter 'ConnectorId'. 'dw-probe' is shorter than minimum length: '36'.",
"RequestId": "f00680a0-b7d0-46b2-ac44-aff23d8b67a4",
"Type": "ValidationException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteFindingAggregator
#Description
The aggregation Region is now called the home Region.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "c65f6d15-f3cb-4a1f-8c92-5fffe428b47f",
"eventName": "DeleteFindingAggregator",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T19:26:37Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "64c5751b-e6b1-4d15-9b46-41ef89f25fc9",
"requestParameters": {
"FindingAggregatorArn": "dw-probe"
},
"responseElements": {
"message": "User: arn:aws:iam::123456789012:user/sample-user is not authorized to perform: securityhub:DeleteFindingAggregator on resource: arn:aws:securityhub:us-west-1:123456789012:hub/default with an explicit deny in a resource-based policy"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteInvitations
#Description
We recommend using Organizations instead of Security Hub CSPM invitations to manage your member accounts.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InternalServerErrorException",
"eventCategory": "Management",
"eventID": "10fc9ff6-3b41-4379-a4df-592d370c8bf7",
"eventName": "DeleteInvitations",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T19:26:37Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "5d8951d6-b591-43f6-874a-c0348a8b1507",
"requestParameters": {
"AccountIds": [
"dw-probe"
]
},
"responseElements": {
"__type": "InvalidInputException",
"message": "The request is rejected because an invalid or out-of-range value is specified as an input parameter."
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteMembers
#Description
Deletes the specified member accounts from Security Hub CSPM.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InternalServerErrorException",
"eventCategory": "Management",
"eventID": "9c9b5743-76c8-4f41-9df7-e9f57fcc464f",
"eventName": "DeleteMembers",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T19:26:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "284a1624-7fda-49d7-8bea-b2b408d31fa5",
"requestParameters": {
"AccountIds": [
"dw-probe"
]
},
"responseElements": {
"__type": "InvalidInputException",
"message": "The request is rejected because an invalid or out-of-range value is specified as an input parameter."
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeActionTargets
#Description
Returns a list of the custom action targets in Security Hub CSPM in your account.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"eventID": "714f03c7-9f1a-4c85-9470-f7affdb0f43e",
"eventName": "DescribeActionTargets",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2020-06-10T05:30:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "9f7cbcae-ef3d-4255-a92c-b3937dffbcf0",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "251.105.254.1",
"userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeHub
#Description
Returns details about the Hub resource in your account, including the HubArn and the time when you enabled Security Hub CSPM.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "InvalidAccessException",
"eventCategory": "Management",
"eventID": "51bd81c8-fed2-4933-a3c0-8b533c24d414",
"eventName": "DescribeHub",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2023-07-10T12:13:21Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "2a113e2f-8cd8-4754-8c64-e6048599fe09",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "10.8.8.10",
"userAgent": "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:102.0) Gecko/20100101 Firefox/102.0",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCVTLW746I",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:13:16Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeOrganizationConfiguration
#Description
Returns information about the way your organization is configured in Security Hub CSPM.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidAccessException",
"eventCategory": "Management",
"eventID": "1c9297cc-87f7-4bdb-88e6-0e5679dd6f27",
"eventName": "DescribeOrganizationConfiguration",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:32:43Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "305eef0a-e81a-4366-b3a7-16f049ff6266",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeProducts
#Description
Returns information about product integrations in Security Hub CSPM.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"eventID": "774fcbd0-5ee5-4c1e-94a8-8b8d2a62b16f",
"eventName": "DescribeProducts",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2020-06-10T05:30:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "2e092cb0-ca4c-4dcf-8be3-65dad034a4da",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "251.105.254.1",
"userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1518↳ also matches DescribeStandards, DescribeStandardsControls
References #
DescribeProductsV2
#Description
Gets information about the product integration.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "36245545-b8e2-44d5-a381-e2777436707b",
"eventName": "DescribeProductsV2",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:32:43Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "eaa0a805-453d-4033-a956-fc0e7e2cb042",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeSecurityHubV2
#Description
Returns details about the service resource in your account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"eventCategory": "Management",
"eventID": "f494e858-a0a5-4e8e-aac2-849004adaff2",
"eventName": "DescribeSecurityHubV2",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:32:43Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "e07f777f-cc56-4375-bc22-2dcaa0f1cdc9",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeStandards
#Description
Returns a list of the available standards in Security Hub CSPM.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"eventID": "2d2082d8-f083-4871-8274-194a6170b138",
"eventName": "DescribeStandards",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2020-06-10T05:30:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "0f5ab61a-2a49-437a-b493-d2a31931d927",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "251.105.254.1",
"userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1518↳ also matches DescribeProducts, DescribeStandardsControls
References #
DescribeStandardsControls
#Description
Returns a list of security standards controls.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidAccessException",
"eventCategory": "Management",
"eventID": "5bc51925-2736-44da-9ab9-9f371f490024",
"eventName": "DescribeStandardsControls",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:46:08Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "0d218dd3-d11e-497b-9cd9-ef10dd1716df",
"requestParameters": {
"StandardsSubscriptionArn": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1518↳ also matches DescribeProducts, DescribeStandards
DisableImportFindingsForProduct
#Description
Disables the integration of the specified product with Security Hub CSPM.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidAccessException",
"eventCategory": "Management",
"eventID": "1b9e8659-6271-49e2-a2c0-54882968c2d2",
"eventName": "DisableImportFindingsForProduct",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T19:26:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "117bddd5-52c3-4018-8033-459e537965b4",
"requestParameters": {
"ProductSubscriptionArn": "dw-probe"
},
"responseElements": {
"Code": "InvalidAccessException",
"Message": "Account 123456789012 is not subscribed to AWS Security Hub",
"RequestId": "40dc3b45-f658-49c8-bb00-ad1c0ad4720e",
"Type": "InvalidAccessException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisableOrganizationAdminAccount
#Description
Disables a Security Hub CSPM administrator account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidInputException",
"eventCategory": "Management",
"eventID": "7a32970c-73c0-4616-98b9-3d98c1e31f73",
"eventName": "DisableOrganizationAdminAccount",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T19:26:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "ca12cf0b-4fc5-4915-b23e-2478a822e385",
"requestParameters": {
"AdminAccountId": "dw-probe"
},
"responseElements": {
"Code": "InvalidInputException",
"Message": "Invalid accountId: dw-probe",
"RequestId": "35b2c6ca-aef4-4f67-9d69-912676d0eed8",
"Type": "InvalidInputException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisableSecurityHub
#Description
Disables Security Hub CSPM in your account only in the current Amazon Web Services Region.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"eventCategory": "Management",
"eventID": "4ac2a615-4b19-43c4-bce6-103be12b9817",
"eventName": "DisableSecurityHub",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T19:45:32Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "1ec35429-ab91-4696-9586-7e3480262fd8",
"requestParameters": null,
"responseElements": {
"Code": "ResourceNotFoundException",
"Message": "Account is not subscribed to Security Hub",
"RequestId": "7df8d112-8261-4413-bc23-c003d87e8cdd",
"Type": "ResourceNotFoundException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisableSecurityHubV2
#Description
Disable the service for the current Amazon Web Services Region or specified Amazon Web Services Region.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "9696b35f-0a03-40db-9e45-9c301c32a07b",
"eventName": "DisableSecurityHubV2",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T19:45:32Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "6b6efb09-d6ad-4aa1-be48-20516c89d32d",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisassociateFromAdministratorAccount
#Description
Disassociates the current Security Hub CSPM member account from the associated administrator account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "489f5749-d0ae-45b9-90df-15b6099f576c",
"eventName": "DisassociateFromAdministratorAccount",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T19:45:32Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "9a789535-55ba-47df-98a0-30b4ff27da62",
"requestParameters": null,
"responseElements": {
"__type": "AccessDeniedException",
"message": "The request is rejected since no such resource found."
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisassociateFromMasterAccount
#Description
This method is deprecated.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "654354af-9dc1-4ae8-8587-90b591a6f733",
"eventName": "DisassociateFromMasterAccount",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T19:45:32Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "aa12b87f-f113-4ecc-9a92-d1edd5835b22",
"requestParameters": null,
"responseElements": {
"__type": "AccessDeniedException",
"message": "The request is rejected since no such resource found."
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisassociateMembers
#Description
Disassociates the specified member accounts from the associated administrator account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InternalServerErrorException",
"eventCategory": "Management",
"eventID": "60c81548-4f94-4238-8f8e-9a9aa5a70145",
"eventName": "DisassociateMembers",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T19:26:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "1493607a-7180-489f-ab2d-011e27f523e7",
"requestParameters": {
"AccountIds": [
"dw-probe"
]
},
"responseElements": {
"__type": "InvalidInputException",
"message": "The request is rejected because an invalid or out-of-range value is specified as an input parameter."
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
EnableImportFindingsForProduct
#Description
Enables the integration of a partner product with Security Hub CSPM.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "140017ec-feb8-4652-939a-baf61a4aa4ab",
"eventName": "EnableImportFindingsForProduct",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T21:48:41Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "b168c2fa-ff3d-4af9-b499-15c62af5354e",
"requestParameters": {
"ProductArn": "arn:aws:securityhub:us-west-1::product/aws/guardduty"
},
"responseElements": {
"ProductSubscriptionArn": "arn:aws:securityhub:us-west-1:123456789012:product-subscription/aws/guardduty"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
EnableOrganizationAdminAccount
#Description
Designates the Security Hub CSPM administrator account for an organization.
EnableSecurityHub
#Description
Enables Security Hub CSPM for your account in the current Region or the Region you specify in the request.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "efabfb6c-01c1-468e-89c8-dbedc66898e7",
"eventName": "EnableSecurityHub",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T21:48:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "504baa2f-527e-41a4-a3b7-b996e5e37b13",
"requestParameters": {
"ControlFindingGenerator": "SECURITY_CONTROL",
"EnableDefaultStandards": false,
"Tags": {
"dwfix": "capture"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
EnableSecurityHubV2
#Description
Enables the service in account for the current Amazon Web Services Region or specified Amazon Web Services Region.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "aa68e95e-2734-4325-bee1-46c64a58dc99",
"eventName": "EnableSecurityHubV2",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T21:48:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "ceec5435-6494-49f2-a136-747bc817ec10",
"requestParameters": {
"Tags": {
"dwfix": "capture"
}
},
"responseElements": {
"HubV2Arn": "arn:aws:securityhub:us-west-1:123456789012:hubv2/e9669e97-d3a1-4b1a-bac0-6f617a87a01b"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GenerateRecommendedPolicyV2
#Description
Begins the recommended policy generation to remediate a Security Hub finding.
GetAdministratorAccount
#Description
Provides the details for the Security Hub CSPM administrator account for the current member account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "311c3561-132e-46e3-9b28-d7824c94e700",
"eventName": "GetAdministratorAccount",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:32:43Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "7d9b1ed9-a66b-4cbe-8dfb-3bceca338e4c",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetAggregatorV2
#Description
Returns the configuration of the specified Aggregator V2.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ConflictException",
"eventCategory": "Management",
"eventID": "16d73aa7-05c3-4b23-bc14-c5454607ee17",
"eventName": "GetAggregatorV2",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:46:08Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "d97bf986-e320-4fe4-b57c-650cc44dc40c",
"requestParameters": {
"AggregatorV2Arn": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetAutomationRuleV2
#Description
Returns an automation rule for the V2 service.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"eventCategory": "Management",
"eventID": "2e42e828-3d1d-4385-b243-c1569f3d6d51",
"eventName": "GetAutomationRuleV2",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:46:08Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "d11dc613-c20c-40a4-9cef-991b860bcb7f",
"requestParameters": {
"Identifier": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetConfigurationPolicy
#Description
Provides information about a configuration policy.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "01c9df5f-3284-4638-82fa-16e01f44e60b",
"eventName": "GetConfigurationPolicy",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:46:08Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "7a020aaf-ffc4-4a2e-a321-d89f8ca34360",
"requestParameters": {
"Identifier": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetConfigurationPolicyAssociation
#Description
Returns the association between a configuration and a target account, organizational unit, or the root.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "159d066e-554a-4c27-bc03-782d3236a812",
"eventName": "GetConfigurationPolicyAssociation",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T21:48:41Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "c8245f83-559c-4ab0-859a-0c024a6eb99d",
"requestParameters": {
"Target": {
"AccountId": "123456789012"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetConnectorV2
#Description
Grants permission to retrieve details for a connectorV2 based on connector id.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"eventCategory": "Management",
"eventID": "3a60d2f2-7ae0-4257-b112-04b621af8d6d",
"eventName": "GetConnectorV2",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:46:08Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "7079e7fa-c04b-41f9-bf54-8663d0d9850c",
"requestParameters": {
"ConnectorId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetEnabledStandards
#Description
Returns a list of the standards that are currently enabled.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "InvalidAccessException",
"eventID": "8f08af82-269b-4ce7-a224-478502d72581e",
"eventName": "GetEnabledStandards",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2019-07-25T09:41:11Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": false,
"recipientAccountId": "811596193553",
"requestID": "39690ed-aec0-11e9-b559-6d9dfa3f32bc",
"requestParameters": null,
"responseElements": {
"Code": "InvalidAccessException",
"Message": "Account 811596193553 is not subscribed to AWS Security Hub",
"RequestId": "0b9a791d-e23e-4148-8503-efb605a58822",
"Type": "InvalidAccessException"
},
"sourceIPAddress": "248.251.245.4",
"userAgent": "Boto3/1.9.39 Python/2.7.16 Linux/4.19.0-kali5-amd64 Botocore/1.12.86",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
GetFindingAggregator
#Description
The aggregation Region is now called the home Region.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "404e4f09-66ed-41e4-88da-c8bd7f39386c",
"eventName": "GetFindingAggregator",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:46:09Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "48bff9a0-29fc-41a0-8576-247c7f60e803",
"requestParameters": {
"FindingAggregatorArn": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetFindingHistory
#Description
Returns the history of a Security Hub CSPM finding.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidAccessException",
"eventCategory": "Management",
"eventID": "1413630c-3782-4038-bd74-ebf3845c82c7",
"eventName": "GetFindingHistory",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:46:09Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "aadcb001-98cf-4684-a764-51c6a23df9f0",
"requestParameters": {
"FindingIdentifier": {
"Id": "dw-probe",
"ProductArn": "dw-probe"
}
},
"responseElements": {
"Code": "InvalidAccessException",
"Message": "Account 123456789012 is not subscribed to AWS Security Hub",
"RequestId": "d017aadc-c466-4aa6-9623-29a335bc1aa0",
"Type": "InvalidAccessException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetFindings
#Description
Returns a list of findings that match the specified criteria.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"errorCode": "InvalidAccessException",
"eventID": "3f32021c-1fcf-4907-acf2-e3c948c5cccd",
"eventName": "GetFindings",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2019-04-06T05:39:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "4f89c73a-582e-11e9-aebf-1493ee9d899c",
"requestParameters": null,
"responseElements": {
"Code": "InvalidAccessException",
"Message": "Account 811596193553 is not subscribed to AWS Security Hub",
"RequestId": "1502b4ee-2b78-4a92-9165-be40fc19677",
"Type": "InvalidAccessException"
},
"sourceIPAddress": "219.106.132.248",
"userAgent": "aws-cli/1.16.136 Python/3.7.3 Linux/5.0.5-100.fc28.x86_64 botocore/1.12.126",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
GetFindingStatisticsV2
#Description
Returns aggregated statistical data about findings.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "44656aca-b6fb-46fb-8858-fcce3d624989",
"eventName": "GetFindingStatisticsV2",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:46:09Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "da2f9418-3912-429e-b7a4-737fa7af506b",
"requestParameters": {
"GroupByRules": [
{
"GroupByField": "activity_name"
}
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetFindingsTrendsV2
#Description
Returns findings trend data based on the specified criteria.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "93713f7a-3bf0-42dc-9c1d-8db97e2c4166",
"eventName": "GetFindingsTrendsV2",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:46:09Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "b57d4ec5-79f7-4d87-af3b-8cc2ae7ce6d8",
"requestParameters": {
"EndTime": "2020-01-01T00:00:00Z",
"StartTime": "2020-01-01T00:00:00Z"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetFindingsV2
#Description
Returns a list of findings that match the specified criteria.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "59e17c54-eddd-484c-87cf-b4b8a6629bac",
"eventName": "GetFindingsV2",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:32:43Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "aadbca03-3d09-4e28-abb5-326aaa66913e",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetInsightResults
#Description
Lists the results of the Security Hub CSPM insight specified by the insight ARN.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidAccessException",
"eventCategory": "Management",
"eventID": "1873129a-8642-4656-bf4d-ea94eb2c9dfa",
"eventName": "GetInsightResults",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:46:09Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "a8060ebc-bb2a-4d07-b512-1ba9be86e7a9",
"requestParameters": {
"InsightArn": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetInsights
#Description
Lists and describes insights for the specified insight ARNs.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"errorCode": "InvalidAccessException",
"eventID": "8e19bab5-e3cd-4b23-a102-a6396fd18c15",
"eventName": "GetInsights",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2019-04-06T05:39:21Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "52765d01-582e-11e9-a12e-dfb409f29730",
"requestParameters": null,
"responseElements": {
"Code": "InvalidAccessException",
"Message": "Account 811596193553 is not subscribed to AWS Security Hub",
"RequestId": "0c0d2e57-4a4a-41c5-aa13-6ee85cd775311",
"Type": "InvalidAccessException"
},
"sourceIPAddress": "219.106.132.248",
"userAgent": "aws-cli/1.16.136 Python/3.7.3 Linux/5.0.5-100.fc28.x86_64 botocore/1.12.126",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
GetInvitationsCount
#Description
We recommend using Organizations instead of Security Hub CSPM invitations to manage your member accounts.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "1c2a48db-68dc-4274-a2d1-3061ef7abef1",
"eventName": "GetInvitationsCount",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2019-07-25T09:41:11Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "565d00b3-aec0-11e9-a624-4b2e25bff3ae",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "248.251.245.4",
"userAgent": "Boto3/1.9.39 Python/2.7.16 Linux/4.19.0-kali5-amd64 Botocore/1.12.86",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
GetMasterAccount
#Description
This method is deprecated.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "d66dfb4c-b593-4460-8dfc-c5f1dc118dc0",
"eventName": "GetMasterAccount",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2019-07-25T09:41:08Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "5442abe0-aec0-11e9-87cc-f478dc98078a",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "248.251.245.4",
"userAgent": "Boto3/1.9.39 Python/2.7.16 Linux/4.19.0-kali5-amd64 Botocore/1.12.86",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
GetMembers
#Description
Returns the details for the Security Hub CSPM member accounts for the specified account IDs.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InternalServerErrorException",
"eventCategory": "Management",
"eventID": "b46eef4e-5784-4d8a-acbe-d46cf7dea5a8",
"eventName": "GetMembers",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:46:09Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "e75e61f0-28b4-4684-968b-502d03a23b25",
"requestParameters": {
"AccountIds": [
"dw-probe"
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetRecommendedPolicyV2
#Description
Retrieves the recommended policy to remediate a Security Hub finding.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "a47a43eb-9aa8-442f-88b7-9a190208d91b",
"eventName": "GetRecommendedPolicyV2",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:46:09Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "90dd57b0-7dfd-49aa-ac67-92a1ed42a8c1",
"requestParameters": {
"MetadataUid": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetResourcesStatisticsV2
#Description
Retrieves statistical information about Amazon Web Services resources and their associated security findings.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "76e8f44c-94bd-432a-92c8-a3453dfd9c2b",
"eventName": "GetResourcesStatisticsV2",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:46:09Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "5c10a941-7e86-4300-8ca3-17726770b6d1",
"requestParameters": {
"GroupByRules": [
{
"GroupByField": "AccountId"
}
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetResourcesTrendsV2
#Description
Returns resource trend data based on the specified criteria.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "ff6270d7-f422-4562-8def-80abd91b7669",
"eventName": "GetResourcesTrendsV2",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:46:09Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "9b951718-f150-408d-92b5-a83bf155190c",
"requestParameters": {
"EndTime": "2020-01-01T00:00:00Z",
"StartTime": "2020-01-01T00:00:00Z"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetResourcesV2
#Description
Returns a list of resources.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "c8a2831f-0bd3-4b69-8727-b0677ec7e45c",
"eventName": "GetResourcesV2",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:32:43Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "98e03224-eb14-441f-b264-11119257708a",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetSecurityControlDefinition
#Description
Retrieves the definition of a security control.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ResourceNotFoundException",
"eventCategory": "Management",
"eventID": "17e4bffb-f6c5-4b6b-910f-ea759d2862ea",
"eventName": "GetSecurityControlDefinition",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:46:10Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "3549ced1-11e4-409c-8e84-829871570e88",
"requestParameters": {
"SecurityControlId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
InviteMembers
#Description
We recommend using Organizations instead of Security Hub CSPM invitations to manage your member accounts.
ListAggregatorsV2
#Description
Retrieves a list of V2 aggregators.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ConflictException",
"eventCategory": "Management",
"eventID": "d4490eb3-5319-4870-957c-d043c46b047b",
"eventName": "ListAggregatorsV2",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:32:43Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "7c3ceeeb-df4c-4f9b-8480-bc1e9e2820f0",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListAutomationRules
#Description
A list of automation rules and their metadata for the calling account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidAccessException",
"eventCategory": "Management",
"eventID": "fb70cac6-b4d2-4108-a523-9f8361338f0d",
"eventName": "ListAutomationRules",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:32:43Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "87defb27-bc5b-4f8b-b632-26459b82a3f4",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListAutomationRulesV2
#Description
Returns a list of automation rules and metadata for the calling account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ConflictException",
"eventCategory": "Management",
"eventID": "200e3a5e-f1ee-49d4-bfd1-0ac4d73b340a",
"eventName": "ListAutomationRulesV2",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:32:43Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "69708790-2fcb-4ee3-88a6-cdf519dada4c",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListConfigurationPolicies
#Description
Lists the configuration policies that the Security Hub CSPM delegated administrator has created for your organization.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "8a3e308e-6c99-4e26-8410-2c796adf97c4",
"eventName": "ListConfigurationPolicies",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:32:43Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "efb17bf0-4ce8-4ea8-a415-c5812a98998e",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListConfigurationPolicyAssociations
#Description
Provides information about the associations for your configuration policies and self-managed behavior.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "5872de9a-7a59-4493-88b8-f9197e8f43ab",
"eventName": "ListConfigurationPolicyAssociations",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:32:43Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "95fba112-cbe0-4090-a7fd-009f9fa24397",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListConnectorsV2
#Description
Grants permission to retrieve a list of connectorsV2 and their metadata for the calling account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ConflictException",
"eventCategory": "Management",
"eventID": "4219c6c2-d31a-4adb-8196-67526da97540",
"eventName": "ListConnectorsV2",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:32:43Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "fa83562d-b9ad-4ec6-bfbb-305f44eee525",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListEnabledProductsForImport
#Description
Lists all findings-generating solutions (products) that you are subscribed to receive findings from in Security Hub CSPM.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "ac5c164a-73a7-444d-becb-5a97619780bf",
"eventName": "ListEnabledProductsForImport",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2019-07-25T09:41:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "56e5dfae-aec0-11e9-a34b-a811618e23cd",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "248.251.245.4",
"userAgent": "Boto3/1.9.39 Python/2.7.16 Linux/4.19.0-kali5-amd64 Botocore/1.12.86",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
ListFindingAggregators
#Description
If cross-Region aggregation is enabled, then ListFindingAggregators returns the Amazon Resource Name (ARN) of the finding aggregator.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidAccessException",
"eventCategory": "Management",
"eventID": "f306d349-9b31-406e-b3af-af1404fcdeab",
"eventName": "ListFindingAggregators",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:32:44Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "5ebc6164-d92d-497b-afe2-8caa7c4d6208",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListInvitations
#Description
We recommend using Organizations instead of Security Hub CSPM invitations to manage your member accounts.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "55074dfb-609f-49b0-b7ed-14f700b5548c",
"eventName": "ListInvitations",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2019-07-25T09:41:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "56be5a80-aec0-11e9-963e-fce456e94721",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "248.251.245.4",
"userAgent": "Boto3/1.9.39 Python/2.7.16 Linux/4.19.0-kali5-amd64 Botocore/1.12.86",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
ListMembers
#Description
Lists details about all member accounts for the current Security Hub CSPM administrator account.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "60c48403-ba16-4ebc-b029-83696f675a1f",
"eventName": "ListMembers",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2019-04-17T17:47:26Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "dce3cccd-6138-11e9-8996-0d275918f3e",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "86.1.86.209",
"userAgent": "aws-cli/1.16.130 Python/2.7.15rc1 Linux/4.15.0-47-generic botocore/1.12.120",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
ListOrganizationAdminAccounts
#Description
Lists the Security Hub CSPM administrator accounts.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "ac99545e-14e0-48cd-a48c-803a619b23a4",
"eventName": "ListOrganizationAdminAccounts",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:32:44Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "9ebe01e7-63ce-4984-b013-e660350833b6",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListSecurityControlDefinitions
#Description
Lists all of the security controls that apply to a specified standard.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "e16f4f2b-ba82-41c8-bdbd-8faa96edfab9",
"eventName": "ListSecurityControlDefinitions",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:32:44Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "6453dd15-1644-4947-9d40-da59ed722964",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListStandardsControlAssociations
#Description
Specifies whether a control is currently enabled or disabled in each enabled standard in the calling account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidAccessException",
"eventCategory": "Management",
"eventID": "56252f1c-b272-4c4e-8fd8-810ee199a37b",
"eventName": "ListStandardsControlAssociations",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T18:46:10Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "3ed03977-f75f-4f00-875b-4907c5fe72e7",
"requestParameters": {
"SecurityControlId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
RegisterConnectorV2
#Description
Grants permission to complete the authorization based on input parameters.
StartConfigurationPolicyAssociation
#Description
Associates a target account, organizational unit, or the root with a specified configuration.
StartConfigurationPolicyDisassociation
#Description
Disassociates a target account, organizational unit, or the root from a specified configuration.
TagResource
#Description
Adds one or more tags to a resource.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "b57bebaa-fe49-47f4-a7e7-90d958d98870",
"eventName": "TagResource",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T21:48:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "4433be12-dc2e-4001-b6d0-e045283ae33d",
"requestParameters": {
"ResourceArn": "arn:aws:securityhub:us-west-1:123456789012:hub/default",
"Tags": {
"dwfix-tag": "capture-test"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UntagResource
#Description
Removes one or more tags from a resource.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "51e3538c-154a-4d70-87df-18c3596d22dc",
"eventName": "UntagResource",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T19:26:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "bd1aec3b-d868-42f3-b70a-8fcc82de195b",
"requestParameters": {
"ResourceArn": "arn:aws:iam::123456789012:role/dw-probe",
"tagKeys": "ddddd"
},
"responseElements": {
"message": "User: arn:aws:iam::123456789012:user/sample-user is not authorized to access this resource"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateActionTarget
#Description
Updates the name and description of a custom action target in Security Hub CSPM.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidAccessException",
"eventCategory": "Management",
"eventID": "20852652-858b-4466-a2bb-a82e6232dcb8",
"eventName": "UpdateActionTarget",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T19:26:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "2e66c0d7-49e4-459e-86ff-e011600fd010",
"requestParameters": {
"ActionTargetArn": "dw-probe"
},
"responseElements": {
"Code": "InvalidAccessException",
"Message": "Account 123456789012 is not subscribed to AWS Security Hub",
"RequestId": "7e766d44-75be-4603-9c93-55a54e578a57",
"Type": "InvalidAccessException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateAggregatorV2
#Description
Udpates the configuration for the Aggregator V2.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ConflictException",
"eventCategory": "Management",
"eventID": "2c0ebb7f-444a-48b9-8c40-44a947165782",
"eventName": "UpdateAggregatorV2",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T19:26:39Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "469378f0-48c0-46ca-bc2b-7b9e9d956198",
"requestParameters": {
"AggregatorV2Arn": "dw-probe",
"RegionLinkingMode": "dw-probe"
},
"responseElements": {
"Code": "ConflictException",
"Message": "Security Hub V2 is not enabled for 123456789012",
"RequestId": "8f097bd5-5025-412f-8b2c-6f374f2c624f",
"Type": "ConflictException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateAutomationRuleV2
#Description
Updates a V2 automation rule.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"eventCategory": "Management",
"eventID": "bd1553e3-ce73-49c5-bb0e-d1a0b1aa2b9e",
"eventName": "UpdateAutomationRuleV2",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T19:26:40Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "9df14bdb-b22f-4a05-aa28-f0aa9437a44c",
"requestParameters": {
"Identifier": "dw-probe"
},
"responseElements": {
"Code": "ValidationException",
"Message": "Invalid format in Identifier",
"RequestId": "f6dd7120-4b94-4591-8c2b-619a29618d1e",
"Type": "ValidationException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateConfigurationPolicy
#Description
Updates a configuration policy.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "c34c2703-0761-4eb2-9ebf-6e54f2e9f775",
"eventName": "UpdateConfigurationPolicy",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T19:26:40Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "53b2de78-1776-4087-b776-9c885389f4b2",
"requestParameters": {
"Identifier": "dw-probe"
},
"responseElements": {
"message": "User: arn:aws:iam::123456789012:user/sample-user is not authorized to perform: securityhub:UpdateConfigurationPolicy on resource: * with an explicit deny in a resource-based policy"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateConnectorV2
#Description
Grants permission to update a connectorV2 based on its id and input parameters.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"eventCategory": "Management",
"eventID": "2dddfb50-b909-4f18-9d1b-a7c89a21c7e0",
"eventName": "UpdateConnectorV2",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T19:26:40Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "bfe1723f-2de5-4764-9de1-712cfab92679",
"requestParameters": {
"ConnectorId": "dw-probe"
},
"responseElements": {
"Code": "ValidationException",
"Message": "Invalid parameter 'ConnectorId'. 'dw-probe' is shorter than minimum length: '36'.",
"RequestId": "c31fbfb1-f343-4b91-b091-4e299bd200d4",
"Type": "ValidationException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateFindingAggregator
#Description
The aggregation Region is now called the home Region.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "AccessDenied",
"eventCategory": "Management",
"eventID": "7195f758-8b1c-48bf-bbd5-22c925d0e5af",
"eventName": "UpdateFindingAggregator",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T19:26:40Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "b3780969-692c-4917-a65c-4618acd49c83",
"requestParameters": {
"FindingAggregatorArn": "dw-probe",
"RegionLinkingMode": "dw-probe"
},
"responseElements": {
"message": "User: arn:aws:iam::123456789012:user/sample-user is not authorized to perform: securityhub:UpdateFindingAggregator on resource: arn:aws:securityhub:us-west-1:123456789012:hub/default with an explicit deny in a resource-based policy"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateOrganizationConfiguration
#Description
Updates the configuration of your organization in Security Hub CSPM.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidAccessException",
"eventCategory": "Management",
"eventID": "f028b063-853b-4cd2-888e-7e607e8d53b9",
"eventName": "UpdateOrganizationConfiguration",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T19:26:40Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "c1afb336-6e04-4530-bb24-660260e7f52b",
"requestParameters": {
"AutoEnable": false
},
"responseElements": {
"Code": "InvalidAccessException",
"Message": "Account 123456789012 is not subscribed to AWS Security Hub",
"RequestId": "00ac9370-699a-4d52-b38e-7abf82aeecb0",
"Type": "InvalidAccessException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateSecurityControl
#Description
Updates the properties of a security control.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidAccessException",
"eventCategory": "Management",
"eventID": "bfbe2078-4523-4c01-b16e-f46a6cbdb2ee",
"eventName": "UpdateSecurityControl",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T19:26:40Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "6eede259-a5d3-4c44-8bff-18b73f147f64",
"requestParameters": {
"Parameters": {},
"SecurityControlId": "dw-probe"
},
"responseElements": {
"Code": "InvalidAccessException",
"Message": "Account 123456789012 is not subscribed to AWS Security Hub",
"RequestId": "71b8d8dc-c4e6-43f7-9634-6bfbaa7f2422",
"Type": "InvalidAccessException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateSecurityHubConfiguration
#Description
Updates configuration options for Security Hub CSPM.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "9714eea5-8775-49bb-a4c0-f170784e9d4d",
"eventName": "UpdateSecurityHubConfiguration",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T21:48:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "214cc628-c725-4bd3-9c62-e0b820390ae9",
"requestParameters": {
"AutoEnableControls": false,
"ControlFindingGenerator": "SECURITY_CONTROL"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,n,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateStandardsControl
#Description
Used to control whether an individual security standard control is enabled or disabled.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidInputException",
"eventCategory": "Management",
"eventID": "7a9b4525-5c46-463b-92ba-f4eb15ffd952",
"eventName": "UpdateStandardsControl",
"eventSource": "securityhub.amazonaws.com",
"eventTime": "2026-06-29T19:26:40Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "9a867539-3086-4411-b109-57e0fc7ccad2",
"requestParameters": {
"StandardsControlArn": "dw-probe"
},
"responseElements": {
"Code": "InvalidInputException",
"Message": "Expected request to include ControlStatus.",
"RequestId": "c60b9717-bea7-427e-9907-026d1cdd01f5",
"Type": "InvalidInputException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetControlFindingSummary
#Description
GetControlFindingSummary recorded by CloudTrail for AWS Security Hub. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "05eb3047-9fa4-458b-8b5b-99ef60a411a8",
"eventSource": "securityhub.amazonaws.com",
"eventName": "GetControlFindingSummary",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "eba741dc-6adb-4eec-b629-d6e49fa28d0a",
"userAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36 Edg/150.0.0.0",
"errorCode": "ResourceNotFoundException"
}
CreateConnector
#Description
Creates a connector to a third-party cloud provider in Security Hub CSPM.
DeleteConnector
#Description
Deletes a CSPM connector.
DisableSecurityHubFeatureV2
#Description
Disables an opt-in feature for the calling account in the current Amazon Web Services Region.
EnableSecurityHubFeatureV2
#Description
Enables an opt-in feature for the calling account in the current Amazon Web Services Region.
GetConnector
#Description
Retrieves details for a CSPM connector based on the connector ID.
ListConnectors
#Description
Lists the CSPM connectors and their metadata for the calling account.
ListFreeTrialStatusesV2
#Description
Lists the free trial status of Security Hub features.
UpdateConnector
#Description
Updates a CSPM connector's configuration, such as the scope or regions for the connected cloud provider.