You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Describe the bug
Get Instance Lambda function assumes role into compromised application account and is unable to retrieves instance information.
To Reproduce
AWS Security Hub operating in AWS application account is reported with details of the compromised instance and the findings get aggregated to AWS Security Hub administrator AWS master Account.
The security administrator initiates one of the following forensic actions in Security Hub.
Forensic triage
Forensic isolation
Amazon EventBridge initiates the triage Step Functions flow.
Expected behavior
A clear and concise description of what you expected to happen.
Please complete the following information about the solution:
Version: [e.g. v1.0.0]
To get the version of the solution, you can look at the description of the created CloudFormation stack. For example, "(SO0191) - Automated Forensics for Amazon EC2. Version v5.0.0". If the description does not contain the version information, you can look at the mappings section of the template:
Can you provide more information like the version of the solution you are using and region's you are working with? Any other information you can provide will be helpful (like if the solution was modified) and you might be able to check CloudTrail to find more information. We will also suggest using the latest version of the solution.
Describe the bug
Get Instance Lambda function assumes role into compromised application account and is unable to retrieves instance information.
To Reproduce
AWS Security Hub operating in AWS application account is reported with details of the compromised instance and the findings get aggregated to AWS Security Hub administrator AWS master Account.
The security administrator initiates one of the following forensic actions in Security Hub.
Amazon EventBridge initiates the triage Step Functions flow.
Expected behavior
A clear and concise description of what you expected to happen.
Please complete the following information about the solution:
To get the version of the solution, you can look at the description of the created CloudFormation stack. For example, "(SO0191) - Automated Forensics for Amazon EC2. Version v5.0.0". If the description does not contain the version information, you can look at the mappings section of the template:
Screenshots
Additional context
Add any other context about the problem here.
The text was updated successfully, but these errors were encountered: