Lambda Triggers
Automating Remediation with AWS Lambda Triggers¶
AWS Lambda functions can be triggered by security events from AWS Security Hub or AWS Config to automate remediation workflows. These triggers enable real-time responses to findings or compliance violations, reducing manual intervention and improving incident resolution speed. This section explains how to configure Lambda triggers for Security Hub findings and Config rule violations, along with practical examples and best practices.
Setting Up Lambda Triggers for Security Events¶
1. Security Hub Trigger Configuration¶
To trigger a Lambda function when a Security Hub finding is detected, use EventBridge (CloudWatch Events) as the event source. Security Hub findings are delivered to EventBridge, and Lambda must be configured as a target in EventBridge.
Steps:
1. Create a Lambda function with an IAM role that grants permissions to invoke AWS services (e.g., EC2, IAM).
2. Set up an EventBridge rule to route Security Hub findings to the Lambda function:
- In the AWS Management Console, navigate to EventBridge > Rules > Create rule.
- Select Event Source as Security Hub, specify the ARN of the Security Hub event bus, and add the Lambda function as a target.
Example CLI Command:
aws events put-targets --rule "SecurityHubFindings" --targets '[{"Id": "1", "Arn": "arn:aws:lambda:us-west-2:123456789012:function:SecurityHubRemediation"}]'
Diagram:
Figure 1: Architecture Diagram of Security Hub Triggering Lambda Function via EventBridge
2. Config Rule Violation Trigger¶
For Config rule violations, use EventBridge as the intermediary to invoke Lambda. Config rules publish events to EventBridge, and Lambda must be configured as a target in EventBridge.
Steps:
1. Create a Config rule that monitors compliance (e.g., iam-user-password-policy).
2. Set up an EventBridge rule to trigger the Lambda function when the Config rule is violated:
- In the AWS Management Console, navigate to EventBridge > Rules > Create rule.
- Select Event Source as AWS Config, specify the ARN of the Config event bus, and add the Lambda function as a target.
Example CloudFormation Template:
Resources:
MyEventBridgeRule:
Type: AWS::Events::Rule
Properties:
Name: "ConfigViolationRule"
EventPattern:
source:
- "aws.config"
detail-type:
- "AWS Config Rule Compliance Status"
Targets:
- Id: "1"
Arn: "arn:aws:lambda:us-west-2:123456789012:function:RemediationLambda"
Example Use Cases¶
Use Case 1: Disable Compromised EC2 Instance¶
A Lambda function triggered by a Security Hub finding can stop a compromised EC2 instance.
Lambda Code (Python):
import boto3
import json
def handler(event, context):
ec2 = boto3.client('ec2')
instance_id = event['detail']['findings'][0]['resources'][0]['resourceId']
ec2.stop_instances(InstanceIds=[instance_id])
return {
'statusCode': 200,
'body': json.dumps(f'Stopped instance {instance_id}')
}
Diagram:
Figure 2: Remediation Workflow for EC2 Instance Compromise
Use Case 2: Remove Non-Compliant Resource¶
A Lambda function triggered by a Config rule violation can delete a non-compliant S3 bucket.
Lambda Code (Python):
import boto3
def handler(event, context):
s3 = boto3.client('s3')
bucket_name = event['detail']['configuration']['resourceId'].split('/')[-1]
s3.delete_bucket(Bucket=bucket_name)
return {
'statusCode': 200,
'body': f'Deleted bucket {bucket_name}'
}
Best Practices¶
- IAM Roles and Permissions
- Ensure the Lambda role has least-privilege permissions to interact with target resources.
-
Example:
AWSLambdaBasicExecutionRolefor logging, plus custom policies for EC2 or S3. -
Logging and Monitoring
- Enable CloudWatch Logs for Lambda to track remediation actions.
-
Use CloudWatch Alarms to monitor for errors or failed invocations.
-
Error Handling
- Implement retries for transient failures (e.g., using
boto3’swaitermechanisms). -
Log detailed error messages for debugging.
-
Testing
- Use AWS SAM or Lambda Test Event to simulate Security Hub or Config events.
Key takeaways¶
- Lambda functions can be triggered by Security Hub findings or Config rule violations to automate remediation.
- Use EventBridge as the intermediary to route events from Security Hub/Config to Lambda.
- Ensure proper IAM permissions and test thoroughly to ensure reliability and compliance.
- Combine Lambda with Security Hub/Config for real-time, scalable security response workflows.