This template creates an AWS Security Hub automation rule with the specified criteria and actions. The automation rule is used to automatically respond to security findings based on the defined criteria. The example includes all available fields for criteria and actions.

RuleWithCriteriaActionsTags
AWS::SecurityHub::AutomationRule


Actions
FindingFieldsUpdate *
Note
RelatedFindings
Severity

Types

Workflow
Criteria
AwsAccountId
CompanyName
ComplianceAssociatedStandardsId
ComplianceSecurityControlId
ComplianceStatus
Confidence
CreatedAt
DateRange
Criticality
Description
FirstObservedAt
DateRange
GeneratorId
Id
LastObservedAt
DateRange
NoteText
NoteUpdatedAt
DateRange
NoteUpdatedBy
ProductArn
ProductName
RecordState
RelatedFindingsId
RelatedFindingsProductArn
ResourceDetailsOther
ResourceId
ResourcePartition
ResourceRegion
ResourceTags
ResourceType
SeverityLabel
SourceUrl
Title
Type
UpdatedAt
DateRange
UserDefinedFields
VerificationState
WorkflowStatus

CloudFormation Template

Share Template