shiichan

You can now investigate AWS Security Hub findings straight from Claude!

Hi everyone, it's Shii! Today's news is about bringing AWS security investigations right into your conversation with an AI assistant. Let's dig in!

AWS What's New aws.amazon.com

What was announced?

According to AWS What's New, AWS announced a preview of the AWS Security Hub MCP App, a Model Context Protocol (MCP) server that brings your AWS Security Hub exposure findings directly into Claude Desktop. It runs locally, and lets you work with your Security Hub data right inside your conversation with Claude.

Specifically, you can use natural language to:

  • View your top exposure findings
  • Drill into a finding's attack path and expanded network path
  • Examine correlated findings and affected resource configurations
  • Get remediation recommendations

Each tool call returns both a text summary for the AI agent to reason over, and an interactive visualization you can verify in the same conversation.

The story so far

Until now, security investigations usually meant switching back and forth between the Security Hub console and your chat tools, triaging things by hand. The original announcement frames this MCP App as a way to "reduce context switching and manual triage" — that back-and-forth outside your AI workflow was a quiet source of friction.

What changes

With the Security Hub MCP App, you can investigate your security posture and talk through remediation without ever leaving your AI-assisted workflow. Being able to analyze attack paths and pull up correlated findings right in the conversation is a real win for engineers doing incident response or security reviews.

Dive Deep

The app runs on your local machine and uses your existing AWS credentials. Every tool is explicitly read-only — it makes no changes to your environment — so it should feel safe to use for investigation.

Pricing-wise, it's available at no additional cost to Security Hub customers. It's supported in all AWS commercial Regions where Security Hub is available.

Wrap-up

  • A preview MCP server now lets you investigate AWS Security Hub findings in natural language from Claude Desktop
  • You can check attack paths, network paths, and correlated findings, and get remediation suggestions
  • It runs locally, uses your existing AWS credentials, and is entirely read-only by design
  • Available at no extra cost for Security Hub customers

If you're on a security or incident response team, this one is worth checking out!