Back to marketplace catalog
Idira Audit Service to Amazon Web Services (AWS) Security Hub
By: Idira
Use case Identity Threat Detection & Response (ITDR)
Category ITDR & security operations
Certification Certified
Version N/A
Released N/A
Last updated Sep 10, 2026

Overview

Feed Idira Audit logs into Amazon Web Services (AWS) Security Hub for security analytics.

Customer problem

Security teams that operate inside the Amazon Web Services (AWS) console triage cloud findings in AWS Security Hub every day, but identity-driven threats such as privilege escalation, suspicious access, and lateral movement are detected in a separate identity console those analysts often do not own. The highest-consequence risk in a cloud environment, privileged-account abuse, sits one tool away from where triage actually happens. The result is slower response, manual pivoting between consoles, and identity events that are missing from AWS-native compliance reporting.

Solution

Palo Alto Networks Idira® surfaces identity threat detections from Idira® Audit Service by Palo Alto Networks directly in AWS Security Hub, where AWS-native security teams already work. A scheduled function deployed in the customer's own AWS account reads Idira Audit Service events, transforms them to the Open Cybersecurity Schema Framework (OCSF), and imports them into AWS Security Hub. Identity findings appear alongside AWS-native sources for unified triage, correlation, and compliance reporting, so analysts investigate identity and cloud threats in one place without adding a tool to the workflow.

Key benefits

Idira privilege escalation, lateral movement, and credential-abuse detections appear as findings in AWS Security Hub, mapped to the OCSF v1.1.0 schema with MITRE ATT&CK aligned classifications so analysts can triage immediately. Idira severity maps directly to the native Security Hub severity scale (Low, Medium, High, Critical), and identity findings can be correlated with Amazon GuardDuty, Amazon Inspector, and other sources in a single view. Identity-control evidence is available natively in AWS Security Hub compliance reporting for frameworks such as SOC 2 and NIST. The integration deploys as a scheduled function in the customer's own AWS account through AWS CloudFormation or Terraform from the public integration repository, and delivers events in near-real-time within the Idira Audit polling interval.

No version information available.