Create AWS Security Hub automation rules to auto-suppress and auto-escalate findings by severity

domain: docs.aws.amazon.com · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. From the Security Hub CSPM administrator account, define automation rule criteria (e.g. product name, severity label, resource type) and actions (e.g. set workflow status to SUPPRESSED, change severity, add a note).
  2. Call CreateAutomationRule with the criteria, actions, and a numeric RuleOrder controlling evaluation precedence, where lower values apply first.
  3. Set IsTerminal on a rule when it should stop further automation rules from evaluating a matched finding.
  4. Use ListAutomationRules and BatchGetAutomationRules to audit existing rules and their configured actions across the account.
  5. Test rules against a sample of findings before enabling broadly, since automation rules can apply retroactively to already-ingested findings that match the criteria.

Known gotchas

Related routes

Aggregate and normalize findings from AWS Security Hub
docs.aws.amazon.com · 6 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans