Glossary

    EventBridge Security Automation

    Monitoring & Detection

    EventBridge Security Automation uses Amazon EventBridge as the backbone for event-driven security response. Security services emit events that trigger automated remediation.

    Security Event Sources

    • GuardDuty: threat findings (compromised instance, malicious IP, crypto mining)
    • Security Hub: compliance findings and imported findings from all security services
    • IAM Access Analyzer: external access findings
    • Config: non-compliant resource events
    • Inspector: vulnerability findings
    • Macie: sensitive data discovery findings

    Automation Patterns

    • Auto-remediate: Lambda function disables compromised access key when GuardDuty detects credential abuse
    • Notify: SNS → Slack/PagerDuty when high-severity finding detected
    • Quarantine: Lambda applies restrictive security group to compromised EC2 instance
    • Enrich & Ticket: Step Functions workflow that enriches findings and creates Jira tickets

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.