如何通过AWS Security Hub SDK检查特定账号及区域的集成启用状态
如何借助AWS Security Hub SDK核查指定账号与区域的集成状态
嘿,要搞定指定AWS账号和区域下Security Hub是否启用的核查问题,用DescribeHub API就能轻松实现,下面我分场景给你讲具体操作:
前提准备
首先得确保你已经配置好AWS SDK的访问凭证(比如环境变量、~/.aws/credentials文件,或者依托IAM角色),并且凭证拥有securityhub:DescribeHub权限——如果是跨账号核查,还需要目标账号有可被你假设的IAM角色,且该角色附带这个权限。
单账号核查(当前凭证所属账号)
以Python的boto3 SDK为例,代码非常直观:
先安装依赖:
pip install boto3
然后写核查脚本:
import boto3 from botocore.exceptions import ClientError def check_sh_enabled(account_id, region): # 初始化指定区域的Security Hub客户端 sh_client = boto3.client('securityhub', region_name=region) try: # 调用DescribeHub接口,成功返回则说明已启用 hub_info = sh_client.describe_hub() print(f"✅ Security Hub在账号{account_id}的{region}区域已启用") print(f"Hub ARN: {hub_info['HubArn']}") print(f"订阅状态: {hub_info['SubscriptionStatus']}") return True except ClientError as e: # 资源未找到异常 = 未启用Security Hub if e.response['Error']['Code'] == 'ResourceNotFoundException': print(f"❌ Security Hub在账号{account_id}的{region}区域未启用") return False # 其他错误(比如权限不足)直接抛出 else: print(f"⚠️ 核查出错: {e.response['Error']['Message']}") raise # 示例调用 if __name__ == "__main__": TARGET_ACCOUNT = "123456789012" # 替换成你的目标账号ID TARGET_REGION = "us-east-1" # 替换成目标区域 check_sh_enabled(TARGET_ACCOUNT, TARGET_REGION)
跨账号核查
如果要核查的不是当前凭证所属的账号,就得通过STS角色假设切换到目标账号,修改后的代码如下:
import boto3 from botocore.exceptions import ClientError def assume_target_role(account_id, role_name): # 调用STS接口假设目标账号的角色 sts_client = boto3.client('sts') try: role_creds = sts_client.assume_role( RoleArn=f"arn:aws:iam::{account_id}:role/{role_name}", RoleSessionName="SecurityHubCheckSession" )['Credentials'] return role_creds except ClientError as e: print(f"❌ 角色假设失败: {e.response['Error']['Message']}") raise def check_sh_enabled(account_id, region, role_name=None): if role_name: # 使用假设的角色初始化客户端 creds = assume_target_role(account_id, role_name) sh_client = boto3.client( 'securityhub', region_name=region, aws_access_key_id=creds['AccessKeyId'], aws_secret_access_key=creds['SecretAccessKey'], aws_session_token=creds['SessionToken'] ) else: sh_client = boto3.client('securityhub', region_name=region) # 后面的核查逻辑和单账号版本完全一致 try: hub_info = sh_client.describe_hub() print(f"✅ Security Hub在账号{account_id}的{region}区域已启用") print(f"Hub ARN: {hub_info['HubArn']}") print(f"订阅状态: {hub_info['SubscriptionStatus']}") return True except ClientError as e: if e.response['Error']['Code'] == 'ResourceNotFoundException': print(f"❌ Security Hub在账号{account_id}的{region}区域未启用") return False else: print(f"⚠️ 核查出错: {e.response['Error']['Message']}") raise # 跨账号示例调用 if __name__ == "__main__": TARGET_ACCOUNT = "987654321098" TARGET_REGION = "eu-west-1" TARGET_ROLE_NAME = "SecurityHubReadOnlyRole" # 目标账号中已配置的角色名 check_sh_enabled(TARGET_ACCOUNT, TARGET_REGION, TARGET_ROLE_NAME)
用AWS CLI快速验证
如果你不想写代码,也可以直接用CLI命令快速核查:
aws securityhub describe-hub --region <目标区域>
- 如果返回包含
HubArn的JSON结果,说明已启用; - 如果报错
ResourceNotFoundException,说明该区域未启用Security Hub。
权限说明
不管是SDK还是CLI,都需要以下权限:
- 单账号:
securityhub:DescribeHub - 跨账号:当前账号需要
sts:AssumeRole权限,目标账号的角色需要securityhub:DescribeHub权限
内容的提问来源于stack exchange,提问作者Kailas Andhale
相关产品推荐
相关产品推荐

