Guide · AWS Security Hub · Setup
AWS Security Hub for MCP Servers — Finding Aggregation, Standards, Integrations
AWS Security Hub is a regional service that collects security findings from GuardDuty, Inspector, Macie, IAM Access Analyzer, Firewall Manager, and third-party tools, normalizes them into the AWS Security Finding Format (ASFF), and presents a unified view with compliance scoring against CIS, PCI DSS, and AWS best-practice standards. For MCP server operators the critical setup detail is to pass --no-enable-default-standards when enabling Security Hub — the default behavior automatically enables CIS AWS Foundations Benchmark v1.2, which generates hundreds of Config rule evaluations and charges per evaluation. Decide which standards you actually need before enabling. A second common mistake is enabling Security Hub without first enabling GuardDuty — Security Hub can aggregate GuardDuty findings, but only if GuardDuty is already running; enabling Hub does not retroactively pull historical GuardDuty findings from before the integration was activated.
TL;DR
Enable Security Hub with --no-enable-default-standards, then deliberately choose which compliance standards to run. Wire GuardDuty, Inspector, and IAM Access Analyzer integrations. Enable cross-region aggregation if your MCP infrastructure spans multiple AWS regions. See the findings API guide for ASFF format and BatchImportFindings, the compliance standards guide for CIS/PCI/FSBP control details, the automation rules guide for automated finding triage, and the cross-account guide for Organizations-based multi-account setup.
Enable Security Hub
Security Hub is enabled per-account per-region. There is no single global switch. If your MCP servers run in three AWS regions, you must enable Security Hub in each region to get findings from that region's services.
# Enable Security Hub WITHOUT default standards (recommended)
# Default behavior auto-enables CIS v1.2 (200+ Config rules) — skip it unless you want that
aws securityhub enable-security-hub \
--no-enable-default-standards \
--tags "Environment=production,Service=mcp-platform"
# Verify Hub is enabled and check configuration
aws securityhub describe-hub
# Output includes:
# HubArn: arn:aws:securityhub:us-east-1:123456789012:hub/default
# SubscribedAt: 2026-10-08T10:00:00Z
# AutoEnableControls: true (controls auto-enabled when new ones added to subscribed standards)
# ControlFindingGenerator: SECURITY_CONTROL (recommended — deduplicates findings across standards)
# Set ControlFindingGenerator to SECURITY_CONTROL if not already set
# This generates one finding per control per resource instead of one per standard per resource
# Critical for accounts subscribed to multiple overlapping standards
aws securityhub update-security-hub-configuration \
--control-finding-generator SECURITY_CONTROL
The ControlFindingGenerator setting is the most important configuration decision after enabling. With SECURITY_CONTROL mode, if a single EC2 misconfiguration is flagged by both FSBP and CIS, you receive one finding (the control finding) rather than two separate standard-specific findings. This reduces finding volume by 30–60% in accounts subscribed to multiple standards. The only reason to use the legacy STANDARD_CONTROL mode is if you have automation that depends on the old finding IDs — new deployments should always use SECURITY_CONTROL.
# Check current Security Hub configuration
aws securityhub describe-hub \
--query '{HubArn:HubArn,AutoEnableControls:AutoEnableControls,ControlFindingGenerator:ControlFindingGenerator}'
# List all Security Hub subscriptions in this region
aws securityhub list-enabled-standards
# Disable Security Hub if needed (deletes all findings — irreversible per region)
# This is a destructive operation — all findings are permanently deleted
# aws securityhub disable-security-hub
Integrations: enabling finding sources
Security Hub supports native AWS integrations and third-party partner integrations. Native AWS integrations (GuardDuty, Inspector, Macie, IAM Access Analyzer, Firewall Manager) are enabled separately from Security Hub itself — enabling Security Hub does not automatically start receiving their findings.
# List all available product integrations (native AWS + partner)
aws securityhub describe-products \
--query 'Products[?CompanyName==`Amazon`].{Name:ProductName,Arn:ProductArn}'
# Key native AWS integration ARNs (us-east-1):
# GuardDuty: arn:aws:securityhub:us-east-1::product/aws/guardduty
# Inspector v2: arn:aws:securityhub:us-east-1::product/aws/inspector
# Macie: arn:aws:securityhub:us-east-1::product/aws/macie
# IAM Access Analyzer: arn:aws:securityhub:us-east-1::product/aws/access-analyzer
# Firewall Manager: arn:aws:securityhub:us-east-1::product/aws/firewall-manager
# Security Lake: arn:aws:securityhub:us-east-1::product/aws/security-lake
# Enable GuardDuty integration (most critical for MCP server threat detection)
aws securityhub enable-import-findings-for-product \
--product-subscription-arn "arn:aws:securityhub:us-east-1::product/aws/guardduty"
# Enable Inspector v2 (vulnerability scanning for container images, EC2 AMIs, Lambda packages)
aws securityhub enable-import-findings-for-product \
--product-subscription-arn "arn:aws:securityhub:us-east-1::product/aws/inspector"
# Enable IAM Access Analyzer (cross-account access, unused permissions findings)
aws securityhub enable-import-findings-for-product \
--product-subscription-arn "arn:aws:securityhub:us-east-1::product/aws/access-analyzer"
# List all currently enabled product integrations
aws securityhub list-enabled-products-for-import
GuardDuty is the highest-value integration for MCP server operators — it surfaces threat-detection findings (compromised credentials, C&C activity, crypto mining) alongside the compliance findings from standards. Inspector v2 covers container image vulnerabilities in ECR (if your MCP servers deploy as Docker images) and Lambda function package scanning. IAM Access Analyzer surfaces overly-permissive resource policies — critical if your MCP server uses S3 buckets or KMS keys accessible from external accounts.
| Integration | Finding types for MCP ops | Prerequisite | Auto-send to Hub |
|---|---|---|---|
| GuardDuty | Threat findings (InstanceCredentialExfiltration, C&CActivity, CryptoCurrency) | GuardDuty detector enabled in same region | Yes — no extra config in GuardDuty |
| Inspector v2 | CVE findings for ECR images, Lambda packages, EC2 AMIs | Inspector v2 enabled | Yes — auto-sends on finding creation |
| Macie | Sensitive data in S3 buckets (secrets in config files, env vars in logs) | Macie enabled with S3 scanning jobs configured | Yes — sends policy and classification findings |
| IAM Access Analyzer | External access to S3 buckets, KMS keys, Lambda functions | Analyzer created in same region | Yes — sends on finding generation |
| Firewall Manager | WAF rule compliance, Network Firewall policy violations | Organizations + Firewall Manager admin account | Yes — sends policy non-compliance findings |
Cross-region aggregation
If your MCP servers run in multiple AWS regions, enable finding aggregation to funnel all regional findings into a single home region. Without aggregation, you must check Security Hub in each region separately — there is no global view by default.
# Create a finding aggregator in your home region (the region where you want all findings)
# This is a one-time setup — run in the region you want as the aggregation target
aws securityhub create-finding-aggregator \
--linking-mode ALL_REGIONS
# Output: {"FindingAggregatorArn": "arn:aws:securityhub:us-east-1:123456789012:finding-aggregator/abcd1234"}
# Verify aggregation status — LinkedRegions should list all active regions
aws securityhub get-finding-aggregator \
--finding-aggregator-arn "arn:aws:securityhub:us-east-1:123456789012:finding-aggregator/abcd1234"
# If you only want specific regions (not all):
aws securityhub create-finding-aggregator \
--linking-mode SPECIFIED_REGIONS \
--regions us-east-1 us-west-2 eu-west-1
# Update aggregation config to add new regions later
aws securityhub update-finding-aggregator \
--finding-aggregator-arn "arn:aws:securityhub:us-east-1:123456789012:finding-aggregator/abcd1234" \
--linking-mode ALL_REGIONS_EXCEPT_SPECIFIED \
--regions ap-east-1 ap-southeast-3
Cross-region aggregation replicates findings to the home region but does not delete them from source regions. Findings updated in the home region propagate back to the source region within a few minutes. Aggregation adds a small delay (typically under 2 minutes) for findings from linked regions to appear in the home region. The home region change takes effect immediately but may cause a brief gap in finding aggregation — plan any home region changes during low-activity periods.
Pricing model
Security Hub pricing has two components: finding ingestion and compliance check evaluations. Understanding both is essential before enabling all standards and integrations.
| Component | Free tier | Paid rate | MCP impact |
|---|---|---|---|
| Finding ingestion (from AWS services) | 10,000 findings/month per account/region | $0.00003/finding after free tier | Low for most MCP deployments; GuardDuty + Inspector generate hundreds/month, not thousands |
| Custom finding ingestion (BatchImportFindings) | 10,000 findings/month per account/region (shared with above) | $0.00003/finding | Relevant if you build a custom ASFF integrator for MCP server health events |
| Config rule evaluations (standards) | First 100,000/month free for 30 days | $0.0008/evaluation/month after free tier | Each CIS/FSBP/PCI control runs as a Config rule — 100 controls × 50 resources = 5,000 evaluations/month |
| Automation rules | Included | No additional charge | Free regardless of how many rules or findings they process |
# Estimate your monthly finding volume before committing
# Count GuardDuty findings in the past 30 days
aws guardduty list-findings \
--detector-id <detector-id> \
--finding-criteria '{
"Criterion": {
"updatedAt": {
"Gte": 1727740800000
}
}
}' \
--query 'length(FindingIds)'
# Count Security Hub findings currently active
aws securityhub get-findings \
--filters '{"WorkflowStatus":[{"Value":"NEW","Comparison":"EQUALS"}]}' \
--query 'length(Findings)'
Failure modes reference
| Failure | Symptom | Fix |
|---|---|---|
| No GuardDuty findings appearing in Security Hub | GuardDuty has active findings; Security Hub shows zero from GuardDuty | GuardDuty integration not enabled; run enable-import-findings-for-product with GuardDuty product ARN |
| Default standards generating unexpected Config charges | AWS bill shows unexpected Config rule evaluation charges within hours of enabling | CIS v1.2 auto-enabled by default; disable with batch-disable-standards or re-enable Hub with --no-enable-default-standards |
| Cross-region findings not appearing in home region | Findings visible in us-west-2 but not in us-east-1 aggregation region | Security Hub not enabled in us-west-2; Hub must be enabled in each linked region before aggregation works |
| Duplicate findings for same control violation | Same S3 misconfiguration appears twice — once for FSBP, once for CIS | ControlFindingGenerator set to STANDARD_CONTROL (legacy); update to SECURITY_CONTROL via update-security-hub-configuration |
| Inspector findings not appearing | ECR image vulnerabilities visible in Inspector console but absent from Security Hub | Inspector integration not enabled in Security Hub; enable-import-findings-for-product with Inspector product ARN |
| enable-security-hub returns AlreadyExistsException | Running enable-security-hub fails | Hub already enabled in this region/account; use describe-hub to verify existing configuration |