AWS Security Hub integration
Get exploitability verdicts for the AWS Inspector container findings in Security Hub, read directly from Inspector.
Integration details
Primary category
Cloud Security
Sync direction
AWS Security Hub → Konvu
Konvu reads the Inspector findings behind Security Hub once a day through a read-only IAM role. Verdicts go out through Slack and the Konvu API.
Status
Available
Triage the container findings Security Hub collects
Security Hub gathers findings from AWS services and partner tools in one place. For container vulnerabilities, those findings come from AWS Inspector. Konvu reads the Inspector findings for your ECR images directly from Inspector through a read-only IAM role, checks each one for exploitability, and returns a verdict with evidence. Verdicts reach your team through Slack and the Konvu API.
AWS Security Hub findings Konvu analyzes
Container
AWS Inspector findings in Security Hub
Active Inspector findings for container images in Amazon ECR, read from Inspector rather than from Security Hub.
Not imported today
- Findings from other Security Hub sources, such as GuardDuty, AWS Config, or partner products
Access and setup
Set up the AWS connection in Konvu. Konvu assumes a read-only IAM role in your account with an external ID, one account and region per connection, and Inspector must be enabled in that region. No Security Hub permissions are needed.
To read findings
inspector2:ListFindingsinspector2:ListCoverageinspector2:BatchGetFindingDetails- The ECR read permissions in the policy Konvu generates
To write back
No write access is needed.
How Konvu investigates AWS Security Hub findings
What Konvu receives
The Inspector finding: the ECR image, the vulnerable package and version, and the CVE.
What Konvu checks
- Whether the vulnerable package is used by the software that runs in the image, or only installed.
- The conditions the CVE needs, such as a running daemon, agent forwarding, or a specific configuration.
- Whether input an attacker controls can reach the vulnerable code.
What decides the verdict
Konvu returns exploitable or false positive, with the reasoning behind it: what runs in the image, the conditions it tested, and what settled the call. When the evidence does not settle it, the finding is left without a verdict rather than guessed.
Illustrative example
An OpenSSH client finding from Security Hub
A made-up service, written to show how an investigation reads. Not a customer result.
- 1
Scanner finding
Security Hub shows an Inspector finding for CVE-2023-38408 in the openssh-client package of an ECR image. Before OpenSSH 9.3p2, a forwarded ssh-agent can be made to load and run code from system libraries.
- 2
Application context
The image runs a Python worker that pulls jobs from a queue. openssh-client came in with the base image.
- 3
Investigation
Konvu checks the entrypoint and every script in the image. Nothing starts ssh-agent or runs ssh with agent forwarding, and the worker makes no SSH connections.
- 4
Verdict
False positive. The attack needs a forwarded ssh-agent, and none ever runs in this container.
- 5
Evidence
The entrypoint, the search for ssh and ssh-agent calls, and the outbound connections the worker makes in code.
- 6
Where it ends up
The verdict and evidence stay in Konvu. The finding stays open in Security Hub and Inspector unless your team suppresses it there. Dropping openssh-client from the image is a sensible cleanup.
Writeback and controls
Where results go
- Exploitable findings can be posted to Slack, so the team hears about them without opening Konvu.
- Every verdict and its evidence can be pulled into your own tools through the Konvu API or CLI.
Who triggers it
Konvu imports findings on its daily schedule. What to do with a verdict is up to your team.
What stays with your team
- Workflow status and suppression rules in Security Hub.
- Rebuilding and pushing a patched image. Konvu does not open fix pull requests for container findings.
The technical detail
More integrations
View allAWS Inspector
Check whether the vulnerabilities AWS Inspector finds in your ECR container images are exploitable.
- Cloud Security
Wiz
Get an exploitability verdict for Wiz container image vulnerabilities, and optionally add it to the finding in Wiz as a note.
- Cloud Security
Check Point CloudGuard
Filter CloudGuard posture findings to focus on exploitable security gaps.
- Cloud Security
Datadog Cloud Security
Prioritize Datadog CSM findings with environment-specific exploitability analysis.
- Cloud Security
Google Cloud Security Command Center
Triage SCC findings with exploit data across GCP assets and vulnerabilities.
- Cloud Security
Lacework
Focus Lacework anomaly alerts on hosts with exploitable vulnerabilities.
- Cloud Security