AWS Puts Security Hub Findings Into the AI Conversation
AWS launched a preview of the Security Hub MCP App on July 27. The tool is a local Model Context Protocol server. It connects AWS Security Hub exposure findings directly to Claude Desktop.
The server targets context switching and manual triage in security investigations. Analysts can investigate your security posture in natural language. They stay inside their AI workflow the whole time.
The server runs locally using existing AWS credentials. Every tool in the app is read-only. Nothing in the environment changes.
The app costs nothing extra for Security Hub customers. It is live in preview across all AWS commercial Regions that support Security Hub.
What the Tool Actually Does
Security Hub exposure findings are already data-rich. Each finding correlates signals from multiple AWS security services. Those services include GuardDuty for threat detection, Amazon Inspector for vulnerability assessment, Security Hub CSPM for configuration checks, and Macie for sensitive data exposure.
Findings include attack paths, blast radius views, severity classifications, and remediation guidance. The MCP App makes that data conversational.
Analysts can view top exposure findings and drill into a finding's attack path and expanded network path. They can also examine correlated findings and affected resource configurations. They can pull remediation recommendations. All of that happens from one chat interface.
The response design is practical. Each tool call returns a text summary for the AI agent and an interactive visualization for the analyst. The AI summarizes. The analyst confirms. Neither step replaces the other.
Security Hub transforms complex security signals into actionable insights through visualizations. The MCP App extends that capability into a chat layer.
Why This Changes the Investigation Workflow
Reducing context switching and manual triage are the stated goals of the MCP App. As Metrotechs analysis, security investigations typically pull from several data sources in sequence. Attack paths, resource configs, and correlated findings each live in different parts of the console. Moving between them adds friction.
The MCP App compresses that sequence. The analyst stays in one interface. They ask a question. They get a structured summary and an interactive visualization back.
As Metrotechs analysis, this does not replace the Security Hub console. It adds a conversational layer over data the console already holds. For teams using Claude Desktop daily, the integration cuts friction without changing the underlying data source.
Every tool is read-only. That limits remediation execution inside the chat interface. As Metrotechs analysis, any fix still happens outside it. The announcement does not state whether that constraint is a long-term design choice or just the scope of this preview.
Governance Questions Before Production Adoption
The announcement does not confirm the final feature set, SLA, or pricing beyond the current no-cost offer. Cloud security leaders need clear answers before moving the app into a production SOC workflow.
Credential scope. The server uses existing AWS credentials. The credential's permission set controls what findings the app can surface. As Metrotechs analysis, a least-privilege credential scoped to Security Hub read access is a reasonable starting point. The announcement does not specify what credential scope AWS recommends. Verify that the credential does not carry broader IAM permissions than the analyst requires.
Data handling. The MCP server runs locally on your machine. Findings pass through Claude Desktop for processing. As Metrotechs analysis, teams with data-residency or compliance obligations should check whether Security Hub finding content is permissible under their framework. Exposure findings include IAM permissions, roles, resource access patterns, and network paths. The announcement does not describe how Claude Desktop handles that content. Confirm before enabling the app.
Audit trail. The MCP App is read-only. Queries may still be material for audit purposes. As Metrotechs analysis, confirm whether Claude Desktop sessions are logged, where those logs live, and whether they meet your retention requirements. The announcement does not address session logging.
Preview risk. As Metrotechs analysis, previews can change behavior before general availability. Build any pilot with the assumption that tool outputs or interfaces may shift.
What to Do Next
Cloud security leaders should treat this as a bounded pilot. It is not an immediate rollout.
Start in a non-production AWS account. Use a scoped read-only credential. Ask the same questions an analyst would ask in a real investigation. Surface the top five critical exposure findings. Drill into one attack path. Check whether the interactive visualization matches what the Security Hub console shows for the same finding.
That comparison confirms accuracy before the tool enters a real workflow.
If the pilot confirms accurate results, document the data-handling posture and credential policy. Set a clear threshold before treating the tool as a standard step in SOC runbooks.
The announcement does not state a GA date. Follow the AWS Security Hub User Guide for updates. If AWS moves the app to general availability, revisit the cost model and SLA commitments before formalizing the workflow.

