You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过AWS Security Hub SDK检查特定账号及区域的集成启用状态

如何借助AWS Security Hub SDK核查指定账号与区域的集成状态

嘿,要搞定指定AWS账号和区域下Security Hub是否启用的核查问题,用DescribeHub API就能轻松实现,下面我分场景给你讲具体操作:

前提准备

首先得确保你已经配置好AWS SDK的访问凭证(比如环境变量、~/.aws/credentials文件,或者依托IAM角色),并且凭证拥有securityhub:DescribeHub权限——如果是跨账号核查,还需要目标账号有可被你假设的IAM角色,且该角色附带这个权限。

单账号核查(当前凭证所属账号)

以Python的boto3 SDK为例,代码非常直观:

先安装依赖:

pip install boto3

然后写核查脚本:

import boto3
from botocore.exceptions import ClientError

def check_sh_enabled(account_id, region):
    # 初始化指定区域的Security Hub客户端
    sh_client = boto3.client('securityhub', region_name=region)
    
    try:
        # 调用DescribeHub接口,成功返回则说明已启用
        hub_info = sh_client.describe_hub()
        print(f"✅ Security Hub在账号{account_id}的{region}区域已启用")
        print(f"Hub ARN: {hub_info['HubArn']}")
        print(f"订阅状态: {hub_info['SubscriptionStatus']}")
        return True
    except ClientError as e:
        # 资源未找到异常 = 未启用Security Hub
        if e.response['Error']['Code'] == 'ResourceNotFoundException':
            print(f"❌ Security Hub在账号{account_id}的{region}区域未启用")
            return False
        # 其他错误(比如权限不足)直接抛出
        else:
            print(f"⚠️ 核查出错: {e.response['Error']['Message']}")
            raise

# 示例调用
if __name__ == "__main__":
    TARGET_ACCOUNT = "123456789012"  # 替换成你的目标账号ID
    TARGET_REGION = "us-east-1"     # 替换成目标区域
    check_sh_enabled(TARGET_ACCOUNT, TARGET_REGION)

跨账号核查

如果要核查的不是当前凭证所属的账号,就得通过STS角色假设切换到目标账号,修改后的代码如下:

import boto3
from botocore.exceptions import ClientError

def assume_target_role(account_id, role_name):
    # 调用STS接口假设目标账号的角色
    sts_client = boto3.client('sts')
    try:
        role_creds = sts_client.assume_role(
            RoleArn=f"arn:aws:iam::{account_id}:role/{role_name}",
            RoleSessionName="SecurityHubCheckSession"
        )['Credentials']
        return role_creds
    except ClientError as e:
        print(f"❌ 角色假设失败: {e.response['Error']['Message']}")
        raise

def check_sh_enabled(account_id, region, role_name=None):
    if role_name:
        # 使用假设的角色初始化客户端
        creds = assume_target_role(account_id, role_name)
        sh_client = boto3.client(
            'securityhub',
            region_name=region,
            aws_access_key_id=creds['AccessKeyId'],
            aws_secret_access_key=creds['SecretAccessKey'],
            aws_session_token=creds['SessionToken']
        )
    else:
        sh_client = boto3.client('securityhub', region_name=region)
    
    # 后面的核查逻辑和单账号版本完全一致
    try:
        hub_info = sh_client.describe_hub()
        print(f"✅ Security Hub在账号{account_id}的{region}区域已启用")
        print(f"Hub ARN: {hub_info['HubArn']}")
        print(f"订阅状态: {hub_info['SubscriptionStatus']}")
        return True
    except ClientError as e:
        if e.response['Error']['Code'] == 'ResourceNotFoundException':
            print(f"❌ Security Hub在账号{account_id}的{region}区域未启用")
            return False
        else:
            print(f"⚠️ 核查出错: {e.response['Error']['Message']}")
            raise

# 跨账号示例调用
if __name__ == "__main__":
    TARGET_ACCOUNT = "987654321098"
    TARGET_REGION = "eu-west-1"
    TARGET_ROLE_NAME = "SecurityHubReadOnlyRole"  # 目标账号中已配置的角色名
    check_sh_enabled(TARGET_ACCOUNT, TARGET_REGION, TARGET_ROLE_NAME)

用AWS CLI快速验证

如果你不想写代码,也可以直接用CLI命令快速核查:

aws securityhub describe-hub --region <目标区域>
  • 如果返回包含HubArn的JSON结果,说明已启用;
  • 如果报错ResourceNotFoundException,说明该区域未启用Security Hub。

权限说明

不管是SDK还是CLI,都需要以下权限:

  • 单账号:securityhub:DescribeHub
  • 跨账号:当前账号需要sts:AssumeRole权限,目标账号的角色需要securityhub:DescribeHub权限

内容的提问来源于stack exchange,提问作者Kailas Andhale

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.06 18:08:09