Tool integration

AWS Security Hub Integration Guide

AWS centralised security findings service with ASFF format and SARIF export via MITRE SAF

Get a Free API Key

Integrate AWS Security Hub with Vulnetix. Export centralised security findings from AWS Security Hub via the CLI or API, convert to SARIF using MITRE SAF, and upload to Vulnetix.

SaaS platformSARIFJSONASFF

How Vulnetix compares: better together

Vulnetix does not replace AWS Security Hub. Keep running it. Vulnetix sits on top of AWS Security Hub (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.

AWS Security Hub is strongest at its core category and also carries features in SCA, Container & Image Scanning, SBOM Generation, Network & Vulnerability Scanners, Compliance & Policy Engines, just as Vulnetix spans categories.

CapabilityVulnetixAWS Security Hub
Security coverage
SAST (static code analysis)Built-in rules + Semgrep augmentation
SCA / dependencies40+ ecosystems, transitive graph~ Via Amazon Inspector: package CVE scanning of ECR/Lambda/EC2 workloads
DAST (dynamic testing)~ Ingests DAST results; no native dynamic engine
Container & imageImage CVEs, base image, Dockerfile~ Inspector ECR container image CVE scanning aggregated into Security Hub
IaC / misconfigurationTerraform, k8s, CloudFormation
Secret scanning1,000+ rules, source + binary + git history
Cloud / CSPMCloud-posture findings, compliance tabCSPM standards (AWS FSBP, CIS, PCI, NIST) with continuous config checks and security scores
Mobile (MAST)~ Ingests mobile scanner output; no native mobile engine
License complianceSPDX, copyleft/AGPL/SSPL policy
SBOM generationCycloneDX 1.7 + SPDX 2.3, cosign-signable~ Inspector exports consolidated CycloneDX 1.4 and SPDX 2.3 SBOMs to S3
Malware / supply-chainDe-duplicated corpus + install-time firewall (25+ registries)
Network / infra vuln~ Ingests network scanner output; no native network scanner~ Inspector network-reachability scans assess unintended internet exposure of hosts and adjust risk scores
FuzzingIngests fuzzing crashes; no native fuzzer
Pentest / bug bountyIngests pentest/bug-bounty findings; not a testing service
The Vulnetix orchestration layer
Cross-scanner dedup & one queue (ASPM)Correlates every scanner into one prioritised queue with ownership routing~ Aggregates, correlates and normalises multi-source findings into ASFF, reducing duplicate signals
Exploit-intel prioritisationEPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV~ Inspector risk score correlates CVE exploitability and network reachability (EPSS-informed)
Reachability analysisTree-sitter + CVEAffected; direct/transitive/semantic
Versioned VEX + audit trailImmutable OpenVEX/CycloneDX, cosign-signable
Safe Harbour autofixResolves + applies the nearest safe version
End-of-life policyFlags/blocks past-EOL runtimes & packages
SSVC / risk-based policySSVC v2 + CISA/FedRAMP/Essential-8 presets

✓ full · ~ partial · ✗ not covered

What AWS Security Hub does well

Where Vulnetix adds to it: AWS Security Hub is an excellent AWS-centric findings aggregator and CSPM, but its consolidation is scoped to the AWS ecosystem and ASFF, with no SAST rule engine, no supply-chain malware/package firewall, no versioned VEX, EOL or SSVC policy, and no autofix. Vulnetix converts ASFF to SARIF (via MITRE SAF) and ingests Security Hub/Inspector output, then deduplicates it alongside non-AWS scanners into one vendor-neutral prioritised queue, layering EPSS/KEV/Coalition-ESS/CWSS/LEV, tree-sitter reachability, immutable versioned VEX, EOL/SSVC policy and Safe Harbour autofix on top.

No migration, no rip-and-replace. AWS Security Hub keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.

Centralise AWS Security Hub results in Vulnetix

Upload AWS Security Hub SARIF, JSON, ASFF output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.

AWS Security Hub documentation ↗

Wire AWS Security Hub into your CI/CD pipeline →