Create AWS Security Hub automation rules to auto-suppress and auto-escalate findings by severity
domain: docs.aws.amazon.com · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗
Steps
From the Security Hub CSPM administrator account, define automation rule criteria (e.g. product name, severity label, resource type) and actions (e.g. set workflow status to SUPPRESSED, change severity, add a note).
Call CreateAutomationRule with the criteria, actions, and a numeric RuleOrder controlling evaluation precedence, where lower values apply first.
Set IsTerminal on a rule when it should stop further automation rules from evaluating a matched finding.
Use ListAutomationRules and BatchGetAutomationRules to audit existing rules and their configured actions across the account.
Test rules against a sample of findings before enabling broadly, since automation rules can apply retroactively to already-ingested findings that match the criteria.
Known gotchas
Automation rules only run in the Security Hub CSPM administrator (or standalone) account — member accounts cannot create rules that apply organization-wide.
A poorly scoped rule can auto-suppress a large backlog of pre-existing real findings because rules are also applied retroactively, not just to new findings.
Give your agent this knowledge — and 15,500+ more routes
One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus:
claude mcp add --transport http waymark https://mcp.waymark.network/mcp
Need this verified for your stack — or a route we don't have yet?