Back to integrations
    Cloud Security

    AWS Security Hub integration

    Get exploitability verdicts for the AWS Inspector container findings in Security Hub, read directly from Inspector.

    Integration details

    Primary category

    Cloud Security

    Sync direction

    AWS Security Hub → Konvu

    Konvu reads the Inspector findings behind Security Hub once a day through a read-only IAM role. Verdicts go out through Slack and the Konvu API.

    Status

    Available

    Triage the container findings Security Hub collects

    Security Hub gathers findings from AWS services and partner tools in one place. For container vulnerabilities, those findings come from AWS Inspector. Konvu reads the Inspector findings for your ECR images directly from Inspector through a read-only IAM role, checks each one for exploitability, and returns a verdict with evidence. Verdicts reach your team through Slack and the Konvu API.

    AWS Security Hub findings Konvu analyzes

    Container

    AWS Inspector findings in Security Hub

    Active Inspector findings for container images in Amazon ECR, read from Inspector rather than from Security Hub.

    Not imported today

    • Findings from other Security Hub sources, such as GuardDuty, AWS Config, or partner products

    Access and setup

    Set up the AWS connection in Konvu. Konvu assumes a read-only IAM role in your account with an external ID, one account and region per connection, and Inspector must be enabled in that region. No Security Hub permissions are needed.

    To read findings

    • inspector2:ListFindings
    • inspector2:ListCoverage
    • inspector2:BatchGetFindingDetails
    • The ECR read permissions in the policy Konvu generates

    To write back

    No write access is needed.

    How Konvu investigates AWS Security Hub findings

    What Konvu receives

    The Inspector finding: the ECR image, the vulnerable package and version, and the CVE.

    What Konvu checks

    • Whether the vulnerable package is used by the software that runs in the image, or only installed.
    • The conditions the CVE needs, such as a running daemon, agent forwarding, or a specific configuration.
    • Whether input an attacker controls can reach the vulnerable code.

    What decides the verdict

    Konvu returns exploitable or false positive, with the reasoning behind it: what runs in the image, the conditions it tested, and what settled the call. When the evidence does not settle it, the finding is left without a verdict rather than guessed.

    Illustrative example

    An OpenSSH client finding from Security Hub

    A made-up service, written to show how an investigation reads. Not a customer result.

    1. 1

      Scanner finding

      Security Hub shows an Inspector finding for CVE-2023-38408 in the openssh-client package of an ECR image. Before OpenSSH 9.3p2, a forwarded ssh-agent can be made to load and run code from system libraries.

    2. 2

      Application context

      The image runs a Python worker that pulls jobs from a queue. openssh-client came in with the base image.

    3. 3

      Investigation

      Konvu checks the entrypoint and every script in the image. Nothing starts ssh-agent or runs ssh with agent forwarding, and the worker makes no SSH connections.

    4. 4

      Verdict

      False positive. The attack needs a forwarded ssh-agent, and none ever runs in this container.

    5. 5

      Evidence

      The entrypoint, the search for ssh and ssh-agent calls, and the outbound connections the worker makes in code.

    6. 6

      Where it ends up

      The verdict and evidence stay in Konvu. The finding stays open in Security Hub and Inspector unless your team suppresses it there. Dropping openssh-client from the image is a sensible cleanup.

    Writeback and controls

    Where results go

    • Exploitable findings can be posted to Slack, so the team hears about them without opening Konvu.
    • Every verdict and its evidence can be pulled into your own tools through the Konvu API or CLI.

    Who triggers it

    Konvu imports findings on its daily schedule. What to do with a verdict is up to your team.

    What stays with your team

    • Workflow status and suppression rules in Security Hub.
    • Rebuilding and pushing a patched image. Konvu does not open fix pull requests for container findings.