Home AISecurity Hub provides AI workload protection and multicloud support for Microsoft Azure

Security Hub provides AI workload protection and multicloud support for Microsoft Azure

by OmarAli
Security Hub provides AI workload protection and multicloud support for Microsoft Azure

Security Hub is our foundation for comprehensive enterprise security across clouds. It centralizes your security operations and turns raw signals into prioritized insights, so your team spends their time managing real risks instead of piecing together tools. Today, that foundation is growing in two directions that our customers have most desired. We’re adding purpose-built protection for AI workloads and security monitoring for Microsoft Azure. Both are steps toward a bigger idea: your best security tools should get smarter by working together.

These enhancements came directly from customers and reflect where security is headed, not where it has been. The old promise of security tools was to collect everything at a glance. Gathering insights was never the hard part. The hard part is understanding them, connecting them and acting before an attacker does, at the speed at which attacks are now moving. From here, the winners will be the programs that can see their entire inventory and respond quickly, not the ones with the most dashboards. That’s what we’re working toward, and these launches are steps toward that journey.

Multicloud security management for Microsoft Azure

Customers across industries have made Security Hub a core part of their security execution on AWS. Most of them have been running on more than one cloud for years and have made it clear to us that they want Security Hub to cover the rest of their inventory. Today we’re doing this for Microsoft Azure, with other clouds following quickly.

Security Hub now discovers Azure virtual machines, container images, function apps, and identities, then assesses them for misconfigurations, internet exposure, and software vulnerabilities with health checks against the CIS Microsoft Azure Foundations Benchmark™. Azure results are prioritized alongside your AWS results, using the same results format, automation, and response workflows, so your team works from a consistent understanding of risk across your entire estate. Azure resources are priced the same as equivalent AWS resources, have no additional fees, and have an independent 30-day free trial. For more information, see the “What’s New” post.

This isn’t really our first step beyond AWS. Earlier this year, we launched Security Hub Extended, integrating best-in-class partner solutions across nine security categories into the same experience you already use. These partner solutions protect endpoints, identities, email, browsers, and data wherever they run, in any cloud, on-premises, and wherever your business operates. Extended was already our first multicloud and multi-workload step. Today we are expanding what our own native capabilities cover, and the two areas of work are now moving forward together.

Protecting AI workloads

Every customer I speak to is building with AI. Generative AI on Amazon Bedrock, model training on SageMaker, agents orchestrating workflows via AgentCore. These workloads reach production faster than most security programs can keep up, and teams often don’t yet have the tools to monitor model calls, track agent behavior, or even know what AI resources exist across the organization. A security leader told me that his team only discovered one compromised service account that had used a foundation model thousands of times because the Treasury department questioned the bill. Through an accounting audit, they discovered a security incident. The visibility gap is real and already expensive.

This summer we start with three launches. Two of these are GuardDuty threat detection and investigation capabilities, and a third is a new Security Hub AI inventory.

GuardDuty AI Protection (generally available)

Amazon GuardDuty AI Protection provides threat detection specifically designed for Bedrock and SageMaker. It detects anomalous model calls, cost harvesting attacks where attackers misuse stolen credentials to make inferences at your expense, and calls for injection attempts through integration with Bedrock Guardrails.

The cost harvest is accelerating. When credentials are compromised, attackers increasingly use them to invoke foundation models. Inference is expensive, demand is high, and stolen access is converted directly into value without the need to deploy any infrastructure. GuardDuty analyzes CloudTrail data events, learns what a normal call looks like at scale, and flags the anomalies that indicate compromise or abuse. This is detection that only works at AWS scale because you need to see the signal across millions of workloads to know what is normal. GuardDuty AI Protection is now available to all GuardDuty customers with a 30-day free trial.

GuardDuty AI-Powered Investigations (Preview)

AI-powered investigations take over the manual investigative work that causes alert fatigue and slows response. The feature automatically analyzes GuardDuty results and associated accounts to distinguish real threats from benign activity.

It examines discovery context, associated activities over the last 90 days, impacted assets, and threat indicators, and leverages knowledge graphs and threat intelligence to do in minutes what once took hours. Each investigation provides a disposition assessment with confidence rating, MITER ATT&CK® classification, supporting evidence, and clear recommendations for suppression, containment, or remediation. Your team focuses on real threats, whether to a single account or an entire AWS organization, reducing time to resolution. GuardDuty’s AI-powered investigations are available in preview in 10 AWS Regions.

Security Hub AI Inventory (generally available)

You can’t back up something you don’t know exists. Security Hub now offers AI Inventory, a continuously updated, enterprise-wide view of your AI assets and their security status. When teams deploy models, agents, and pipelines, security often can’t see what’s running, and without linking those assets to active threats and misconfigurations, it’s difficult to know what to secure first.

Security Hub’s AI inventory discovers and catalogs AI workloads in your AWS environment in two ways. For managed services, AWS Config resources are inventoried in Bedrock, SageMaker, and AgentCore. For self-hosted and external workloads, it uses runtime analysis to find models running on EC2, ECS, and EKS and identify the external model endpoints that your workloads call. It maps every asset to the underlying infrastructure, including compute, network, IAM roles and data storage, and correlates it with security signals such as GuardDuty scores. When GuardDuty AI Protection reports an anomalous call, AI Inventory immediately shows you what infrastructure is affected, what is connected to it, and where it belongs in your priority order.

AI resources are multiplying rapidly. A developer launches a Bedrock agent for a proof of concept. A data science team deploys a SageMaker endpoint for internal testing. Another team connects an external model API via a Lambda function. When you multiply that across hundreds or thousands of accounts, you can quickly lose track. AI Inventory gives you this overview of every account in your organization, available in your Security Hub Essentials plan at no additional cost.

A different approach to full-stack security

These launches share something worth pausing over. You have not purchased AI protection as a separate product and will not perform separate operations for Azure. You add them to the Security Hub you’re already running, and they appear in your prioritized risk view. The same idea is extended to the rest of the security space by Security Hub Extended.

Security Hub Extended now has 21 curated partners across nine categories: 7AI, Britive, CrowdStrike, Idira (CyberArk), Cyera, Island, LayerX, Native Security, Noma, Okta, Oligo, Opti, Proofpoint, SailPoint, SentinelOne, Splunk, Sublime, Upwind, Varonis, Zenity and Zscaler. These are best-in-class solutions for endpoints, identity, email, network, data, browser, cloud, AI and security operations. None of them are here by default. Everyone has earned their place by committing to a shared view of the future of enterprise security and investing in building it with us. Curation is the point. A recommendation only means something if it can be rejected.

The commercial benefits of Extended are real today. Pay-as-you-go pricing, a single AWS bill, EDP eligibility, and no long-term commitments. But the work we’re most excited about goes beyond that, and it’s not about procurement at all. The results of each participating solution are output in the Open Cybersecurity Schema Framework (OCSF) and aggregated in the Security Hub. We aim for a single correlation across all solutions so that a signal from an endpoint solution, an identity solution, and a cloud solution is aggregated into one compromise and attack path, rather than three separate alerts. We’re working to reduce the deployment and onboarding effort between subscribing and seeing value. And we build the exchanges that allow partner outcomes to enrich each other, so the best-in-class tools you already trust are greater than the sum of their parts. This is the differentiated future we are investing in, and we are building it openly, guided by what customers want next. For more information about Extended, see the What’s New post.

Acceleration forward

Step back and the form is clear. Security Hub spans all cloud providers, starting with Azure and expanding from there. It covers all workload types with purpose-built AI protection and inventory. And it covers all security categories through Extended and its curated partners. What started as a way to bring order to AWS security outcomes has evolved into the way more and more companies do full-stack security.

Detection and visibility are the basis. We build on this to create a security experience that connects signals from all trusted sources and helps you respond faster. It’s still Day 1 and Security Hub continues to expand as your environment and the threats you face continue to change.

If you have feedback on this post, submit comments in Comments Section below.


Security Hub provides AI workload protection and multicloud support for

Michael Fuller

Michael has been at AWS for 16 years and led product for AWS Security Services for 11 years. Michael has been in the industry for 29 years and has held various positions in product management, business development and software development for IBM, Cisco and Amazon. Michael holds a Bachelor of Science in Computer Engineering from the University of Arizona and an MBA from the University of Washington.

https://aws.amazon.com/blogs/security/security-hub-adds-ai-workload-protection-and-multicloud-support-for-microsoft-azure/

Viral Trends

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Accept Read More