2026/10/01 - AWS SecurityHub - 2 new api methods
Changes Adds GetRemediationsV2 and ListExposuresByRemediationV2 APIs. This feature allows customers to see their highest priority remediations for their Exposure findings. Remediations target key changes customers can make to resources to drive finding resolution.
Retrieves the exposure findings tied to a specific remediation target. Results are sorted by previous severity, highest first, and are paginated.
See also: AWS API Documentation
Request Syntax
client.list_exposures_by_remediation_v2(
TargetUid='string',
MaxResults=123,
NextToken='string'
)
string
[REQUIRED]
The unique identifier (ID) of an existing remediation target to list exposure findings for.
integer
The maximum number of results to return. Valid range is 1-100. If you don't specify a value, the operation returns up to 25 results.
string
The token used to paginate the exposures list returned. On your first call to ListExposuresByRemediationV2, omit this parameter or set it to NULL. For subsequent calls, use the NextToken value returned in the previous response to retrieve the next page of results.
dict
Response Syntax
{
'Items': [
{
'MetadataUid': 'string',
'Title': 'string',
'PreviousSeverity': 'Informational'|'Low'|'Medium'|'High'|'Critical',
'ProjectedSeverity': 'Informational'|'Low'|'Medium'|'High'|'Critical',
'Impact': 'Reduces'|'Resolves'|'Unchanged'
},
],
'TargetUid': 'string',
'Resource': {
'AccountId': 'string',
'Region': 'string',
'ResourceOwnerAccountId': 'string',
'ResourceOwnerOrgId': 'string',
'Type': 'string',
'Name': 'string',
'Id': 'string',
'ResourceGuid': 'string',
'ResourceRegion': 'string',
'CloudProvider': 'Azure'|'AWS'
},
'TotalCount': 123,
'Trait': {
'Type': 'string',
'Title': 'string'
},
'NextToken': 'string'
}
Response Structure
(dict) --
Items (list) --
An array of exposure findings returned by the operation.
(dict) --
Provides details about an exposure finding and the effect the specific remediation target has on it.
MetadataUid (string) --
The unique identifier (ID) of the Security Hub exposure finding, found under the metadata.uid field of the finding.
Title (string) --
The title of the exposure finding.
PreviousSeverity (string) --
The severity of the exposure finding before the remediation target is resolved.
ProjectedSeverity (string) --
The severity of the exposure finding after the remediation target is resolved.
Impact (string) --
The impact resolving a remediation target has on the exposure finding.
Reduces specifies that resolving the remediation target lowers the severity of the exposure finding, but does not resolve it.
Resolves specifies that resolving the remediation target resolves the exposure finding.
Unchanged specifies that resolving the remediation target does not change the severity of the exposure finding.
TargetUid (string) --
The unique identifier (ID) of the remediation target that the exposure findings are associated with.
Resource (dict) --
Provides comprehensive details about a resource.
AccountId (string) --
The Amazon Web Services account that recorded the resource data in Security Hub.
Region (string) --
The Amazon Web Services Region in which Security Hub recorded the resource data.
ResourceOwnerAccountId (string) --
The identifier of the cloud account that owns the resource. For Amazon Web Services resources, this is the Amazon Web Services account ID. For Azure resources, this is the Azure subscription ID.
ResourceOwnerOrgId (string) --
The identifier of the cloud organization that owns the resource. For Amazon Web Services resources, this is the Organizations ID. For Azure resources, this is the Azure tenant ID.
Type (string) --
The type of the resource.
Name (string) --
The name of the resource.
Id (string) --
The unique identifier for a resource.
ResourceGuid (string) --
The global identifier used to identify a resource.
ResourceRegion (string) --
The native cloud region where the resource is located. For Amazon Web Services, this is an Amazon Web Services Region (for example, us-east-1). For Azure resources, this is the Azure region (for example, westus2). This field is always included.
CloudProvider (string) --
The cloud provider where the resource exists.
AWS specifies that the resource exists in Amazon Web Services.
Azure specifies that the resource exists in Microsoft Azure.
TotalCount (integer) --
The total count of exposure findings associated with the remediation target.
Trait (dict) --
The specific trait associated with the remediation target.
Type (string) --
The trait type.
Title (string) --
The trait title.
NextToken (string) --
The pagination token to use to request the next page of results. Otherwise, this parameter is null.
Retrieves remediation targets for the account, or for all member accounts if the caller is the delegated administrator. Results are sorted by priority, highest first, and are paginated. Use TargetUid or MetadataUid to scope the request to a single target or finding.
See also: AWS API Documentation
Request Syntax
client.get_remediations_v2(
TargetUid='string',
MetadataUid='string',
Filters={
'CompositeFilters': [
{
'StringFilters': [
{
'FieldName': 'Resource.Type'|'Priority'|'Status'|'Resource.Id'|'Resource.ResourceOwnerAccountId'|'Resource.CloudProvider',
'Filter': {
'Value': 'string'
}
},
]
},
]
},
ShowGuidance=True|False,
GuidanceFormat='All'|'AwsCli'|'Cli'|'Python'|'Terraform'|'Cdk'|'CloudFormation'|'IaC'|'Template',
MaxResults=123,
NextToken='string'
)
string
The unique identifier (ID) of an existing remediation target to return. Returns the single matching target. You can't use TargetUid together with MetadataUid or Filters.
string
The unique identifier (ID) of the Security Hub exposure finding, found under the metadata.uid field of the finding. Returns the remediation targets associated with that finding. You can't use MetadataUid together with TargetUid or Filters.
dict
Filters remediation targets based on a set of criteria. You can't use Filters together with TargetUid or MetadataUid.
CompositeFilters (list) --
A collection of complex filtering conditions that can be applied to remediation target data.
(dict) --
Enables the creation of criteria for remediation targets.
StringFilters (list) --
Enables filtering based on string field values.
(dict) --
A string filter for filtering remediation targets.
FieldName (string) -- [REQUIRED]
The name of the filter field. Valid values are Resource.Type, Priority, Status, Resource.Id, Resource.ResourceOwnerAccountId, and Resource.CloudProvider.
Filter (dict) -- [REQUIRED]
The string filter definition.
Value (string) -- [REQUIRED]
The value the string filter is comparing against.
boolean
Specifies whether to show remediation target guidance.
string
The format of the remediation guidance examples to return. Valid values are All, AwsCli, Cli, Python, Terraform, Cdk, CloudFormation, IaC, and Template. If you don't specify a value, all formats are returned. Applies only when ShowGuidance is true.
integer
The maximum number of results to return. Valid range is 1-100. If you don't specify a value, the operation returns up to 25 results.
string
The token used to paginate the remediations target list returned. On your first call to GetRemediationsV2, omit this parameter or set it to NULL. For subsequent calls, use the NextToken value returned in the previous response to retrieve the next page of results.
dict
Response Syntax
{
'Items': [
{
'TargetUid': 'string',
'Outcome': {
'ResolvedFindingsCount': 123,
'SeverityReductionFindingsCount': 123,
'SeverityUnchangedCount': 123
},
'Priority': 'Critical'|'High'|'Medium'|'Low',
'RemediationSummary': {
'Action': 'string',
'Description': 'string',
'IsImmediate': True|False,
'PostRemediationSteps': [
'string',
],
'KbArticles': [
{
'Title': 'string',
'Url': 'string'
},
]
},
'Resource': {
'AccountId': 'string',
'Region': 'string',
'ResourceOwnerAccountId': 'string',
'ResourceOwnerOrgId': 'string',
'Type': 'string',
'Name': 'string',
'Id': 'string',
'ResourceGuid': 'string',
'ResourceRegion': 'string',
'CloudProvider': 'Azure'|'AWS'
},
'Status': 'New'|'Updated'|'Resolved',
'Trait': {
'Type': 'string',
'Title': 'string'
},
'Guidance': {
'TargetTypeName': 'string',
'Pattern': 'string',
'Version': 'string',
'Context': {
'ProblemStatement': 'string',
'RiskAssessment': 'string',
'AffectedScope': 'string',
'Prerequisites': [
'string',
]
},
'Specification': {
'Parameters': [
{
'Name': 'string',
'Type': 'string',
'Description': 'string',
'Required': True|False
},
],
'Steps': [
{
'Phase': 'string',
'Description': 'string',
'Service': 'string',
'Action': 'string',
'Logic': 'string',
'Inverse': 'string',
'VerifyAfter': 'string'
},
],
'ExpectedEndState': 'string',
'RequiredPermissions': [
'string',
]
},
'Examples': {
'AwsCli': 'string',
'Cli': 'string',
'Python': 'string',
'Terraform': 'string',
'Cdk': 'string',
'CloudFormation': 'string',
'IaC': 'string',
'Template': 'string'
},
'Metadata': {
'ResourceType': 'string',
'ExposureType': 'string',
'TraitTitles': [
'string',
],
'Reversibility': 'string',
'FixEffect': 'string',
'RiskLevel': 'string',
'AutomationLevel': 'string',
'HumanReviewRequired': True|False,
'GeneratedAt': datetime(2015, 1, 1),
'VerificationStatus': 'string'
}
},
'UpdatedAt': datetime(2015, 1, 1)
},
],
'NextToken': 'string'
}
Response Structure
(dict) --
Items (list) --
An array of remediation targets returned by the operation.
(dict) --
A remediation target.
TargetUid (string) --
The unique identifier (ID) of the remediation target.
Outcome (dict) --
The outcome of the remediation target's resolution.
ResolvedFindingsCount (integer) --
The number of associated exposure findings that are resolved by remediating the target.
SeverityReductionFindingsCount (integer) --
The number of associated exposure findings whose severity is reduced by remediating the target.
SeverityUnchangedCount (integer) --
The number of associated exposure findings whose severity is unchanged by remediating the target.
Priority (string) --
The remediation target's priority. Valid values are Critical, High, Medium, and Low.
RemediationSummary (dict) --
A summary of the remediation target.
Action (string) --
A summarized action to take for the remediation target.
Description (string) --
A description of the remediation target.
IsImmediate (boolean) --
Specifies whether the effect of this target is immediate.
PostRemediationSteps (list) --
An array of steps to be taken after remediation.
(string) --
KbArticles (list) --
An array of KbArticle objects.
(dict) --
A knowledge base article that provides additional guidance related to the remediation target.
Title (string) --
The title of the KbArticle.
Url (string) --
The URL of the KbArticle.
Resource (dict) --
The remediation target's associated resource.
AccountId (string) --
The Amazon Web Services account that recorded the resource data in Security Hub.
Region (string) --
The Amazon Web Services Region in which Security Hub recorded the resource data.
ResourceOwnerAccountId (string) --
The identifier of the cloud account that owns the resource. For Amazon Web Services resources, this is the Amazon Web Services account ID. For Azure resources, this is the Azure subscription ID.
ResourceOwnerOrgId (string) --
The identifier of the cloud organization that owns the resource. For Amazon Web Services resources, this is the Organizations ID. For Azure resources, this is the Azure tenant ID.
Type (string) --
The type of the resource.
Name (string) --
The name of the resource.
Id (string) --
The unique identifier for a resource.
ResourceGuid (string) --
The global identifier used to identify a resource.
ResourceRegion (string) --
The native cloud region where the resource is located. For Amazon Web Services, this is an Amazon Web Services Region (for example, us-east-1). For Azure resources, this is the Azure region (for example, westus2). This field is always included.
CloudProvider (string) --
The cloud provider where the resource exists.
AWS specifies that the resource exists in Amazon Web Services.
Azure specifies that the resource exists in Microsoft Azure.
Status (string) --
The current status of the remediation target.
New specifies that the remediation target was newly identified.
Updated specifies that the remediation target changed after it was identified.
Resolved specifies that the remediation target is no longer present.
Trait (dict) --
The trait associated with the remediation target.
Type (string) --
The trait type.
Title (string) --
The trait title.
Guidance (dict) --
The remediation target's guidance. Returned only when ShowGuidance is true in the request.
TargetTypeName (string) --
The name of the remediation target type.
Pattern (string) --
The remediation pattern of the remediation target.
Version (string) --
The guidance version.
Context (dict) --
The context behind the remediation target's existence and guidance.
ProblemStatement (string) --
Explains the cause which directly created the remediation target.
RiskAssessment (string) --
An assessment of the existing risk the remediation target creates.
AffectedScope (string) --
The scope of the resources affected by the resolution of the remediation target.
Prerequisites (list) --
An array of prerequisite steps in resolving the remediation target.
(string) --
Specification (dict) --
The specification of the remediation target guidance. This outlines required resource parameters and permissions, remediation steps, and the end state.
Parameters (list) --
An array of the parameters used in running the steps provided.
(dict) --
A parameter used in running the guidance steps.
Name (string) --
The name of the parameter.
Type (string) --
The type of the parameter.
Description (string) --
A description of the parameter.
Required (boolean) --
Specifies whether the parameter is required for running the guidance steps.
Steps (list) --
An array of ordered steps for resolving the remediation targets.
(dict) --
A step in the remediation guidance.
Phase (string) --
The phase of the remediation plan that this step belongs to (for example, FIX).
Description (string) --
A description of what the step does.
Service (string) --
Which service this step is performed in.
Action (string) --
The action to be taken for this step.
Logic (string) --
The logic behind the existence of this step.
Inverse (string) --
The inverse of the step, to be used if the step needs to be rolled back.
VerifyAfter (string) --
The action to take after the step to verify its success.
ExpectedEndState (string) --
The expected end state of the associated resources after completion of the steps.
RequiredPermissions (list) --
An array of required permissions to run the steps.
(string) --
Examples (dict) --
Provided remediation guidance examples in different formats that can be run for remediating the target.
AwsCli (string) --
An AWS CLI snippet version of the example.
Cli (string) --
A CLI snippet version of the example.
Python (string) --
A Python snippet version of the example.
Terraform (string) --
A Terraform snippet version of the example.
Cdk (string) --
A CDK snippet version of the example.
CloudFormation (string) --
A CloudFormation snippet version of the example.
IaC (string) --
An IaC snippet version of the example.
Template (string) --
A Template snippet version of the example.
Metadata (dict) --
The metadata of the remediation guidance.
ResourceType (string) --
The resource type of the remediation target.
ExposureType (string) --
The exposure type of the related exposure findings.
TraitTitles (list) --
The titles of traits this guidance applies to.
(string) --
Reversibility (string) --
The extent to which changes made in accordance with the guidance can be reversed, for example Fully reversible.
FixEffect (string) --
When the fix takes effect, for example Immediate or Deferred.
RiskLevel (string) --
The risk when implementing the guidance provided.
AutomationLevel (string) --
The extent to which the guidance can be automated, for example Full.
HumanReviewRequired (boolean) --
Specifies whether human review is required.
GeneratedAt (datetime) --
Timestamp of when the guidance was generated.
For more information about the validation and formatting of timestamp fields in Security Hub CSPM, see Timestamps.
VerificationStatus (string) --
Verification status of the guidance.
UpdatedAt (datetime) --
The remediation target's last updated timestamp.
For more information about the validation and formatting of timestamp fields in Security Hub CSPM, see Timestamps.
NextToken (string) --
The pagination token to use to request the next page of results. Otherwise, this parameter is null.