Automated Security Response on AWS adds AI Toolkit for custom remediations
AWS expands Automated Security Response with an AI toolkit for custom remediations and broader coverage across security services, aiming to reduce manual triage and accelerate incident response.
AWS has introduced four new capabilities for Automated Security Response on AWS (ASR), now deployable across all commercial and opt-in regions, including GovCloud (US) and China. The AI-driven Toolkit allows customers to generate custom remediations using any AI assistant with built-in safety guardrails, reducing development time from weeks to hours. This feature minimizes misconfigurations and removes the need for deep SSM Automation expertise, streamlining the creation of tailored security responses.
Customers can now automatically remediate findings from Amazon Inspector, Amazon GuardDuty, and Amazon Macie, expanding ASR’s service coverage. The system addresses credential compromise, unpatched vulnerabilities, and sensitive data exposure with minimal manual intervention. This expansion reduces reliance on manual triage, enabling faster and more consistent security responses across AWS environments.
An enhanced web console centralizes the management of over 100 security controls, replacing error-prone manual configurations in DynamoDB and SSM. The console includes built-in validation to ensure accuracy and consistency in automated remediations. This centralized approach simplifies oversight and reduces the administrative burden on security teams managing multiple accounts, organizational units, regions, and resource tags.
ASR now supports configurable multi-channel notifications for AWS Security Hub findings, including Email, Slack, Jira, and ServiceNow. The notifications include severity-based filtering, remediation links, deadlines, and Infrastructure as Code (IaC) code snippets. This feature helps teams address root causes promptly and ensures accountability in incident response workflows.