ingest-security-hub-ocsf

Installation
SKILL.md

ingest-security-hub-ocsf

Thin passthrough ingestion skill with ASFF validation: raw Security Hub ASFF JSON in → canonical finding projection → OCSF 1.8 Detection Finding (2004) JSONL or native enriched finding JSONL out. Security Hub is an aggregator — it already collects findings from GuardDuty, Inspector, Macie, Config, Firewall Manager, and third-party products, all normalised to the same ASFF schema. This skill does one thing: validate that the ASFF required fields are present and transform them into the repo's stable finding contract.

Wire contract

Reads any of the three shapes Security Hub emits:

  1. Single finding — one JSON object per line (NDJSON, e.g. EventBridge → Kinesis Firehose to S3)
  2. BatchImportFindings / GetFindings wrapper — top-level {"Findings": [...]} (the format from aws securityhub get-findings or from BatchImportFindings request bodies)
  3. EventBridge event envelope — top-level {"detail-type": "Security Hub Findings - Imported", "detail": {"findings": [...]}, ...}; the skill auto-unwraps detail.findings.

Writes OCSF 1.8 Detection Finding (class_uid: 2004, category_uid: 2). See ../OCSF_CONTRACT.md for the field-level pinning every event matches.

When --output-format native is selected, it emits the same finding in the repo's native enriched shape with stable event_uid, normalized provider/account/severity fields, MITRE ATT&CK annotations, preserved compliance/resource context, and no OCSF envelope fields.

Native output format

--output-format native returns one JSON object per Security Hub finding with:

Installs
1
GitHub Stars
3
First Seen
Apr 20, 2026
ingest-security-hub-ocsf — msaad00/cloud-ai-security-skills