Integrate AWS Security Hub with Vulnetix. Export centralised security findings from AWS Security Hub via the CLI or API, convert to SARIF using MITRE SAF, and upload to Vulnetix.
How Vulnetix compares: better together
Vulnetix does not replace AWS Security Hub. Keep running it. Vulnetix sits on top of AWS Security Hub (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.
AWS Security Hub is strongest at its core category and also carries features in SCA, Container & Image Scanning, SBOM Generation, Network & Vulnerability Scanners, Compliance & Policy Engines, just as Vulnetix spans categories.
| Capability | Vulnetix | AWS Security Hub |
|---|---|---|
| Security coverage | ||
| SAST (static code analysis) | ✓ Built-in rules + Semgrep augmentation | ✗ |
| SCA / dependencies | ✓ 40+ ecosystems, transitive graph | ~ Via Amazon Inspector: package CVE scanning of ECR/Lambda/EC2 workloads |
| DAST (dynamic testing) | ~ Ingests DAST results; no native dynamic engine | ✗ |
| Container & image | ✓ Image CVEs, base image, Dockerfile | ~ Inspector ECR container image CVE scanning aggregated into Security Hub |
| IaC / misconfiguration | ✓ Terraform, k8s, CloudFormation | ✗ |
| Secret scanning | ✓ 1,000+ rules, source + binary + git history | ✗ |
| Cloud / CSPM | ✓ Cloud-posture findings, compliance tab | ✓ CSPM standards (AWS FSBP, CIS, PCI, NIST) with continuous config checks and security scores |
| Mobile (MAST) | ~ Ingests mobile scanner output; no native mobile engine | ✗ |
| License compliance | ✓ SPDX, copyleft/AGPL/SSPL policy | ✗ |
| SBOM generation | ✓ CycloneDX 1.7 + SPDX 2.3, cosign-signable | ~ Inspector exports consolidated CycloneDX 1.4 and SPDX 2.3 SBOMs to S3 |
| Malware / supply-chain | ✓ De-duplicated corpus + install-time firewall (25+ registries) | ✗ |
| Network / infra vuln | ~ Ingests network scanner output; no native network scanner | ~ Inspector network-reachability scans assess unintended internet exposure of hosts and adjust risk scores |
| Fuzzing | ✗ Ingests fuzzing crashes; no native fuzzer | ✗ |
| Pentest / bug bounty | ✗ Ingests pentest/bug-bounty findings; not a testing service | ✗ |
| The Vulnetix orchestration layer | ||
| Cross-scanner dedup & one queue (ASPM) | ✓ Correlates every scanner into one prioritised queue with ownership routing | ~ Aggregates, correlates and normalises multi-source findings into ASFF, reducing duplicate signals |
| Exploit-intel prioritisation | ✓ EPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV | ~ Inspector risk score correlates CVE exploitability and network reachability (EPSS-informed) |
| Reachability analysis | ✓ Tree-sitter + CVEAffected; direct/transitive/semantic | ✗ |
| Versioned VEX + audit trail | ✓ Immutable OpenVEX/CycloneDX, cosign-signable | ✗ |
| Safe Harbour autofix | ✓ Resolves + applies the nearest safe version | ✗ |
| End-of-life policy | ✓ Flags/blocks past-EOL runtimes & packages | ✗ |
| SSVC / risk-based policy | ✓ SSVC v2 + CISA/FedRAMP/Essential-8 presets | ✗ |
✓ full · ~ partial · ✗ not covered
What AWS Security Hub does well
- Central aggregation and normalisation of security findings across AWS-native services (GuardDuty, Inspector, Macie, IAM Access Analyzer, Config) and third-party partners into the standard ASFF JSON schema
- CSPM security standards mapped to AWS Foundational Security Best Practices, CIS, PCI-DSS and NIST with automated continuous checks and per-account security scores
- Deep native AWS integration and automation hooks (EventBridge, Automations) for at-scale governance and response
- Paired Amazon Inspector adds CVE scanning of EC2/ECR/Lambda plus CycloneDX/SPDX SBOM export and contextual risk scoring
Where Vulnetix adds to it: AWS Security Hub is an excellent AWS-centric findings aggregator and CSPM, but its consolidation is scoped to the AWS ecosystem and ASFF, with no SAST rule engine, no supply-chain malware/package firewall, no versioned VEX, EOL or SSVC policy, and no autofix. Vulnetix converts ASFF to SARIF (via MITRE SAF) and ingests Security Hub/Inspector output, then deduplicates it alongside non-AWS scanners into one vendor-neutral prioritised queue, layering EPSS/KEV/Coalition-ESS/CWSS/LEV, tree-sitter reachability, immutable versioned VEX, EOL/SSVC policy and Safe Harbour autofix on top.
No migration, no rip-and-replace. AWS Security Hub keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.
Centralise AWS Security Hub results in Vulnetix
Upload AWS Security Hub SARIF, JSON, ASFF output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.