Agent skill

Implementing AWS Security Hub

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Deploy AWS Security Hub as a centralized CSPM platform, backed by AWS Config, aggregating findings from GuardDuty, Inspector, Macie, and third-party tools; enable CIS Foundations, PCI-DSS, and NIST…

Apache-2.0Auto-check passedSecurity

Install Implementing AWS Security Hub

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-aws-security-hub -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-aws-security-hub --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-aws-security-hub .claude/skills/implementing-aws-security-hub && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
implementing-aws-security-hub
GitHub stars
34k
Token cost
~2.5k tokens
SKILL.md length
604 words
Files
4 (incl. scripts, references)
Skills in repo
639
Repo updated
First seen
Licence
Apache-2.0

At a glance

Deploy AWS Security Hub as a centralized CSPM platform, backed by AWS Config, aggregating findings from GuardDuty, Inspector, Macie, and third-party tools; enable CIS Foundations, PCI-DSS, and NIST…

  • Works in 5 steps: Enable Security Hub with Standards → Configure Multi-Account Aggregation → Integrate Security Services and… → …
  • A centralized findings dashboard
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder; calls aws

What it does

Implementing AWS Security Hub is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Deploy AWS Security Hub as a centralized CSPM platform, backed by AWS Config, aggregating findings from GuardDuty, Inspector, Macie, and third-party tools; enable CIS Foundations, PCI-DSS, and NIST standards; automate remediation via EventBridge/Systems Manager; and produce Audit Manager evidence. Use for a centralized findings dashboard or compliance audit evidence; not for threat detection or container scanning.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Security, covering Cloud security, Healthcare and finance regulation and SOC 2 and security compliance. It works with Amazon Web Services. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • A centralized findings dashboard
  • Compliance audit evidence
  • Not for threat detection
  • Container scanning

Example prompts

  • “/implementing-aws-security-hub”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Enable Security Hub with Standards
  2. Configure Multi-Account Aggregation
  3. Integrate Security Services and Third-Party Tools
  4. Build Automated Remediation
  5. Monitor Compliance Scores and Generate Reports

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use aws, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Implementing AWS Security Hub loads about 2.5k tokens when it runs, and up to ~3.1k if it reads all its reference files. Until then it costs about 112 tokens; SKILL.md has 604 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~112
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 604 words, ~2,473 tokens.

Download SKILL.mdSave it as .claude/skills/implementing-aws-security-hub/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
implementing-aws-security-hub
description
Deploy AWS Security Hub as a centralized CSPM platform, backed by AWS Config, aggregating findings from GuardDuty, Inspector, Macie, and third-party tools; enable CIS Foundations, PCI-DSS, and NIST standards; automate remediation via EventBridge/Systems Manager; and produce Audit Manager evidence. Use for a centralized findings dashboard or compliance audit evidence; not for threat detection or container scanning.
domain
cybersecurity
subdomain
cloud-security
tags
aws-security-hub, cspm, compliance-automation, security-standards, finding-aggregation
version
1.0.0
author
mahipal
license
Apache-2.0
nist_csf
PR.IR-01, ID.AM-08, GV.SC-06, DE.CM-01
mitre_attack
T1078.004, T1530, T1537, T1580

Implementing AWS Security Hub

When to Use

  • When establishing a centralized security findings dashboard across multiple AWS accounts
  • When enabling automated compliance checks against CIS, PCI-DSS, NIST, or AWS Foundational Security Best Practices
  • When integrating findings from GuardDuty, Inspector, Macie, and third-party security tools
  • When building automated remediation workflows for recurring security misconfigurations
  • When preparing compliance evidence for auditors requiring continuous posture monitoring

Do not use for real-time threat detection (see detecting-cloud-threats-with-guardduty), for Azure compliance monitoring (see securing-azure-with-microsoft-defender), or for deep vulnerability scanning of container images (see securing-container-registry).

Prerequisites

  • AWS Organization with a designated security administrator account
  • AWS Config enabled in all target accounts and regions
  • GuardDuty, Inspector, and Macie activated for finding integration
  • IAM permissions for securityhub:* and config:* in the administrator account

Workflow

Step 1: Enable Security Hub with Standards

Activate Security Hub in the delegated administrator account and enable security standards. AWS Security Hub CSPM supports CIS AWS Foundations Benchmark v5.0, AWS Foundational Security Best Practices, PCI DSS v3.2.1, and NIST SP 800-53.

bash
# Enable Security Hub with standards
aws securityhub enable-security-hub \
  --enable-default-standards \
  --tags '{"Environment":"production","ManagedBy":"security-team"}'

# Enable CIS AWS Foundations Benchmark v5.0
aws securityhub batch-enable-standards \
  --standards-subscription-requests '[
    {"StandardsArn": "arn:aws:securityhub:::ruleset/cis-aws-foundations-benchmark/v/5.0.0"},
    {"StandardsArn": "arn:aws:securityhub:us-east-1::standards/aws-foundational-security-best-practices/v/1.0.0"},
    {"StandardsArn": "arn:aws:securityhub:us-east-1::standards/pci-dss/v/3.2.1"}
  ]'

# Verify enabled standards
aws securityhub get-enabled-standards \
  --query 'StandardsSubscriptions[*].[StandardsArn,StandardsStatus]' --output table
Step 2: Configure Multi-Account Aggregation

Designate a Security Hub administrator and automatically enroll all organization member accounts. Configure cross-region aggregation to consolidate findings into a single region.

bash
# Designate delegated admin
aws securityhub enable-organization-admin-account \
  --admin-account-id 111122223333

# Auto-enable for all org members
aws securityhub update-organization-configuration \
  --auto-enable \
  --organization-configuration '{"ConfigurationType": "CENTRAL"}'

# Enable cross-region aggregation
aws securityhub create-finding-aggregator \
  --region-linking-mode ALL_REGIONS
Step 3: Integrate Security Services and Third-Party Tools

Configure product integrations to receive findings from AWS services and partner security tools. Map third-party findings to AWS Security Finding Format (ASFF).

bash
# List available product integrations
aws securityhub describe-products \
  --query 'Products[*].[ProductName,CompanyName,ProductSubscriptionResourcePolicy]' --output table

# Enable specific integrations
aws securityhub enable-import-findings-for-product \
  --product-arn "arn:aws:securityhub:us-east-1::product/aws/guardduty"

aws securityhub enable-import-findings-for-product \
  --product-arn "arn:aws:securityhub:us-east-1::product/aws/inspector"

# Import custom findings using ASFF format
aws securityhub batch-import-findings --findings '[{
  "SchemaVersion": "2018-10-08",
  "Id": "custom-finding-001",
  "ProductArn": "arn:aws:securityhub:us-east-1:123456789012:product/123456789012/default",
  "GeneratorId": "custom-scanner",
  "AwsAccountId": "123456789012",
  "Types": ["Software and Configuration Checks/Vulnerabilities/CVE"],
  "Title": "Unpatched OpenSSL in production ALB backend",
  "Description": "CVE-2024-12345 detected on backend instances",
  "Severity": {"Label": "HIGH"},
  "Resources": [{"Type": "AwsEc2Instance", "Id": "arn:aws:ec2:us-east-1:123456789012:instance/i-0abc123"}]
}]'
Step 4: Build Automated Remediation

Create Security Hub custom actions linked to EventBridge rules and Lambda functions for one-click or fully automated remediation of common findings.

bash
# Create a custom action for remediation
aws securityhub create-action-target \
  --name "IsolateInstance" \
  --description "Isolate EC2 instance by replacing security groups" \
  --id "IsolateInstance"

# EventBridge rule for automated remediation of specific controls
aws events put-rule \
  --name SecurityHubAutoRemediate \
  --event-pattern '{
    "source": ["aws.securityhub"],
    "detail-type": ["Security Hub Findings - Imported"],
    "detail": {
      "findings": {
        "Compliance": {"Status": ["FAILED"]},
        "Severity": {"Label": ["CRITICAL", "HIGH"]},
        "GeneratorId": ["aws-foundational-security-best-practices/v/1.0.0/S3.1"]
      }
    }
  }'
Step 5: Monitor Compliance Scores and Generate Reports

Track security scores across standards, monitor compliance drift over time, and generate reports for audit evidence.

bash
# Get security score for a standard
aws securityhub get-security-control-definition \
  --security-control-id "S3.1"

# List all failed controls with counts
aws securityhub get-findings \
  --filters '{
    "ComplianceStatus": [{"Value": "FAILED", "Comparison": "EQUALS"}],
    "RecordState": [{"Value": "ACTIVE", "Comparison": "EQUALS"}]
  }' \
  --sort-criteria '{"Field": "SeverityLabel", "SortOrder": "desc"}' \
  --max-items 50

Key Concepts

TermDefinition
Security StandardPre-packaged set of controls mapped to compliance frameworks such as CIS, PCI-DSS, NIST 800-53, and AWS best practices
Security ControlIndividual automated check that evaluates a specific AWS resource configuration against a security requirement
ASFFAWS Security Finding Format, a standardized JSON schema for normalizing findings from all integrated security products
Compliance ScorePercentage of controls in a passing state within a given security standard, calculated per account and aggregated at the organization level
Finding AggregatorCross-region mechanism that consolidates findings from all enabled regions into a single administrator region
Custom ActionUser-defined action that can be triggered from the Security Hub console to invoke EventBridge rules for manual or automated response
Show full SKILL.md (213 more words)Show less

Tools & Systems

  • AWS Security Hub CSPM: Core platform for automated security posture checks and finding aggregation
  • AWS Config: Underlying configuration recorder that Security Hub relies on for resource evaluation
  • Amazon EventBridge: Event routing service for connecting Security Hub findings to automated remediation workflows
  • AWS Systems Manager: Automation documents that Security Hub can invoke for remediation of common misconfigurations
  • AWS Audit Manager: Generates audit-ready reports using Security Hub findings as evidence

Common Scenarios

Scenario: Failed CIS Controls Across 50 Accounts

Context: An enterprise enables CIS AWS Foundations Benchmark v5.0 and discovers 340 failed controls across 50 accounts, primarily in IAM password policy, CloudTrail configuration, and VPC flow log enablement.

Approach:

  1. Export all FAILED findings grouped by control ID to identify the most prevalent issues
  2. Prioritize Critical and High severity controls that affect the most accounts
  3. Create Systems Manager Automation documents for the top 10 recurring failures
  4. Deploy automated remediation via EventBridge for controls like S3.1 (block public access) and CloudTrail.1 (enable multi-region trail)
  5. Schedule weekly compliance score reviews and track improvement over a 90-day remediation window

Pitfalls: Enabling automated remediation for all controls at once can break production workloads that legitimately require public S3 access or specific network configurations. Always test remediation in a staging account first.

Output Format

AWS Security Hub Compliance Report
====================================
Organization: acme-corp
Administrator Account: 111122223333
Report Date: 2025-02-23
Standards Enabled: CIS v5.0, AWS FSBP v1.0, PCI DSS v3.2.1

COMPLIANCE SCORES:
  CIS AWS Foundations Benchmark v5.0: 78%
  AWS Foundational Security Best Practices: 85%
  PCI DSS v3.2.1: 72%

TOP FAILED CONTROLS (by account count):
  [S3.1]   Block public access settings enabled      - 23/50 accounts FAILED
  [CT.1]   CloudTrail multi-region enabled            - 12/50 accounts FAILED
  [IAM.4]  Root account has no access keys            -  3/50 accounts FAILED
  [EC2.19] Security groups restrict unrestricted ports- 31/50 accounts FAILED
  [RDS.3]  RDS encryption at rest enabled             - 18/50 accounts FAILED

FINDING SUMMARY:
  Total Active Findings: 1,247
  Critical: 34 | High: 189 | Medium: 567 | Low: 457
  Auto-Remediated This Month: 89
  Suppressed: 23

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/implementing-aws-security-hub of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Implementing AWS Security Hub next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Implementing AWS Security Hub compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Implementing AWS Security Hub this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: PassApache-2.0
Security Engineertheneoai/awesome-skills183—~2.1kAutomated safety check: PassMIT
Eks Securityaws-samples/appmod-blueprints113—~4.7kAutomated safety check: PassMIT-0
Atmos AWS Compliancecloudposse/atmos1.4k—~679Automated safety check: PassApache-2.0
AWS Compliance Checkeraiskillstore/marketplace4304 repos~3.7kAutomated safety check: PassNone
Senior Secopsalirezarezvani/claude-skills28k1 repos~4kAutomated safety check: PassMIT

Similar skills

  • Security Engineer

    theneoai/awesome-skills

    Elite Security Engineer skill with deep expertise in application security, cloud security architecture, penetration testing, Zero Trust implementation, threat modeling (STRIDE), and compliance…

    183 GitHub stars~2.1k tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Eks Security

    aws-samples/appmod-blueprints

    Official

    A skill your agent uses whenever someone needs security or compliance guidance for Amazon EKS — phrased as "CIS Benchmark for EKS", "HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS", "harden my EKS…

    113 GitHub stars~4.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Atmos AWS Compliance

    cloudposse/atmos

    AWS compliance commands in Atmos: atmos aws compliance report, Security Hub standards, CIS AWS, PCI DSS, SOC2, HIPAA, NIST, report formats, AI summaries

    1.4k GitHub stars~679 tokensUpdated today
    Legal & ComplianceAuto-check passed
  • AWS Compliance Checker

    aiskillstore/marketplace

    Automated compliance checking against CIS, PCI-DSS, HIPAA, and SOC 2 benchmarks

    430 GitHub starsUsed in 4 repos~3.7k tokens
    Legal & ComplianceAuto-check passed
  • Senior Secops

    alirezarezvani/claude-skills

    Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices.

    28k GitHub starsUsed in 1 repo~4k tokens
    SecurityAuto-check passed
  • Architecting Security

    telagod/code-abyss

    安全架构与治理:威胁建模 (STRIDE/PASTA/LINDDUN)、零信任身份架构、IAM/SSO/MFA/PAM、合规框架 (SOC2/PCI/HIPAA/GDPR)、DLP、隐私工程、安全控制设计。Use when designing security architecture, threat modeling new systems, implementing zero-trust…

    244 GitHub stars~712 tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 639 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Implementing AWS Security Hub

What does Implementing AWS Security Hub do?

Deploy AWS Security Hub as a centralized CSPM platform, backed by AWS Config, aggregating findings from GuardDuty, Inspector, Macie, and third-party tools; enable CIS Foundations, PCI-DSS, and NIST…. Implementing AWS Security Hub is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Deploy AWS Security Hub as a centralized CSPM platform, backed by AWS Config, aggregating findings from GuardDuty, Inspector, Macie, and third-party tools; enable CIS Foundations, PCI-DSS, and NIST standards; automate remediation via EventBridge/Systems Manager; and produce Audit Manager evidence.

When should I use Implementing AWS Security Hub?

Implementing AWS Security Hub fits situations like: A centralized findings dashboard; compliance audit evidence; not for threat detection; container scanning.

How do I install Implementing AWS Security Hub in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-aws-security-hub -a claude-code`. Or copy the skill folder (skills/implementing-aws-security-hub in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/implementing-aws-security-hub in your project. Claude Code loads it when a task matches its description.

How do I install Implementing AWS Security Hub in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-aws-security-hub -a codex`. Or copy the skill folder (skills/implementing-aws-security-hub in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/implementing-aws-security-hub in your project. Codex loads it when a task matches its description.

Can I use Implementing AWS Security Hub in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-aws-security-hub -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-aws-security-hub, .gemini/skills/implementing-aws-security-hub, .github/skills/implementing-aws-security-hub and .opencode/skills/implementing-aws-security-hub in your project.

What does Implementing AWS Security Hub need to run?

Going by SKILL.md and its folder, Implementing AWS Security Hub needs Python for the scripts in its folder and the command-line tools its instructions call (aws). Our summary lists: Python 3.

Does Implementing AWS Security Hub access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Implementing AWS Security Hub safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Implementing AWS Security Hub use?

Implementing AWS Security Hub is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Implementing AWS Security Hub use?

About 2.5k tokens (SKILL.md is roughly 9.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 589 tokens, read only when the agent opens those files.

What are the alternatives to Implementing AWS Security Hub?

Skills that share tags, products or a category with Implementing AWS Security Hub: Security Engineer (theneoai/awesome-skills, 183 stars), Eks Security (aws-samples/appmod-blueprints, 113 stars), Atmos AWS Compliance (cloudposse/atmos, 1.4k stars) and AWS Compliance Checker (aiskillstore/marketplace, 430 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Implementing AWS Security Hub?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,870 GitHub stars. The repository holds 639 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.