ingest-security-hub-ocsf
ingest-security-hub-ocsf
Thin passthrough ingestion skill with ASFF validation: raw Security Hub ASFF JSON in → canonical finding projection → OCSF 1.8 Detection Finding (2004) JSONL or native enriched finding JSONL out. Security Hub is an aggregator — it already collects findings from GuardDuty, Inspector, Macie, Config, Firewall Manager, and third-party products, all normalised to the same ASFF schema. This skill does one thing: validate that the ASFF required fields are present and transform them into the repo's stable finding contract.
Wire contract
Reads any of the three shapes Security Hub emits:
- Single finding — one JSON object per line (NDJSON, e.g. EventBridge → Kinesis Firehose to S3)
- BatchImportFindings / GetFindings wrapper — top-level
{"Findings": [...]}(the format fromaws securityhub get-findingsor fromBatchImportFindingsrequest bodies) - EventBridge event envelope — top-level
{"detail-type": "Security Hub Findings - Imported", "detail": {"findings": [...]}, ...}; the skill auto-unwrapsdetail.findings.
Writes OCSF 1.8 Detection Finding (class_uid: 2004, category_uid: 2). See ../OCSF_CONTRACT.md for the field-level pinning every event matches.
When --output-format native is selected, it emits the same finding in the repo's native enriched shape with stable event_uid, normalized provider/account/severity fields, MITRE ATT&CK annotations, preserved compliance/resource context, and no OCSF envelope fields.
Native output format
--output-format native returns one JSON object per Security Hub finding with: