[ aws . securityhub ]

get-remediations-v2

Description

Retrieves remediation targets for the account, or for all member accounts if the caller is the delegated administrator. Results are sorted by priority, highest first, and are paginated. Use TargetUid or MetadataUid to scope the request to a single target or finding.

See also: AWS API Documentation

get-remediations-v2 is a paginated operation. Multiple API calls may be issued in order to retrieve the entire data set of results. You can disable pagination by providing the --no-paginate argument. When using --output text and the --query argument on a paginated response, the --query argument must extract data from the results of the following query expressions: Items

Synopsis

  get-remediations-v2
[--target-uid <value>]
[--metadata-uid <value>]
[--filters <value>]
[--show-guidance | --no-show-guidance]
[--guidance-format <value>]
[--starting-token <value>]
[--page-size <value>]
[--max-items <value>]
[--cli-input-json | --cli-input-yaml]
[--generate-cli-skeleton <value>]
[--debug]
[--endpoint-url <value>]
[--no-verify-ssl]
[--no-paginate]
[--output <value>]
[--query <value>]
[--profile <value>]
[--region <value>]
[--version <value>]
[--color <value>]
[--no-sign-request]
[--ca-bundle <value>]
[--cli-read-timeout <value>]
[--cli-connect-timeout <value>]
[--cli-binary-format <value>]
[--no-cli-pager]
[--cli-auto-prompt]
[--no-cli-auto-prompt]
[--cli-error-format <value>]

Options

--target-uid (string)

The unique identifier (ID) of an existing remediation target to return. Returns the single matching target. You can’t use TargetUid together with MetadataUid or Filters .

Constraints:

  • min: 1
  • max: 2048

--metadata-uid (string)

The unique identifier (ID) of the Security Hub exposure finding, found under the metadata.uid field of the finding. Returns the remediation targets associated with that finding. You can’t use MetadataUid together with TargetUid or Filters .

Constraints:

  • min: 1
  • max: 2048

--filters (structure)

Filters remediation targets based on a set of criteria. You can’t use Filters together with TargetUid or MetadataUid .

CompositeFilters -> (list)

A collection of complex filtering conditions that can be applied to remediation target data.

Constraints:

  • min: 0
  • max: 1

(structure)

Enables the creation of criteria for remediation targets.

StringFilters -> (list)

Enables filtering based on string field values.

Constraints:

  • min: 0
  • max: 2

(structure)

A string filter for filtering remediation targets.

FieldName -> (string) [required]

The name of the filter field. Valid values are Resource.Type , Priority , Status , Resource.Id , Resource.ResourceOwnerAccountId , and Resource.CloudProvider .

Possible values:

  • Resource.Type
  • Priority
  • Status
  • Resource.Id
  • Resource.ResourceOwnerAccountId
  • Resource.CloudProvider

Filter -> (structure) [required]

The string filter definition.

Value -> (string) [required]

The value the string filter is comparing against.

Constraints:

  • pattern: .*\S.*

JSON Syntax:

{
  "CompositeFilters": [
    {
      "StringFilters": [
        {
          "FieldName": "Resource.Type"|"Priority"|"Status"|"Resource.Id"|"Resource.ResourceOwnerAccountId"|"Resource.CloudProvider",
          "Filter": {
            "Value": "string"
          }
        }
        ...
      ]
    }
    ...
  ]
}

--show-guidance | --no-show-guidance (boolean)

Specifies whether to show remediation target guidance.

--guidance-format (string)

The format of the remediation guidance examples to return. Valid values are All , AwsCli , Cli , Python , Terraform , Cdk , CloudFormation , IaC , and Template . If you don’t specify a value, all formats are returned. Applies only when ShowGuidance is true .

Possible values:

  • All
  • AwsCli
  • Cli
  • Python
  • Terraform
  • Cdk
  • CloudFormation
  • IaC
  • Template

--starting-token (string)

A token to specify where to start paginating. This is the NextToken from a previously truncated response.

For usage examples, see Pagination in the AWS Command Line Interface User Guide .

--page-size (integer)

The size of each page to get in the AWS service call. This does not affect the number of items returned in the command’s output. Setting a smaller page size results in more calls to the AWS service, retrieving fewer items in each call. This can help prevent the AWS service calls from timing out.

For usage examples, see Pagination in the AWS Command Line Interface User Guide .

Constraints:

  • min: 1
  • max: 100

--max-items (integer)

The total number of items to return in the command’s output. If the total number of items available is more than the value specified, a NextToken is provided in the command’s output. To resume pagination, provide the NextToken value in the starting-token argument of a subsequent command. Do not use the NextToken response element directly outside of the AWS CLI.

For usage examples, see Pagination in the AWS Command Line Interface User Guide .

--cli-input-json | --cli-input-yaml (string) Reads arguments from the JSON string provided. The JSON string follows the format provided by --generate-cli-skeleton. If other arguments are provided on the command line, those values will override the JSON-provided values. It is not possible to pass arbitrary binary values using a JSON-provided value as the string will be taken literally. This may not be specified along with --cli-input-yaml.

--generate-cli-skeleton (string) Prints a JSON skeleton to standard output without sending an API request. If provided with no value or the value input, prints a sample input JSON that can be used as an argument for --cli-input-json. Similarly, if provided yaml-input it will print a sample input YAML that can be used with --cli-input-yaml. If provided with the value output, it validates the command inputs and returns a sample output JSON for that command. The generated JSON skeleton is not stable between versions of the AWS CLI and there are no backwards compatibility guarantees in the JSON skeleton generated.

Global Options

--debug (boolean)

Turn on debug logging.

--endpoint-url (string)

Override command’s default URL with the given URL.

--no-verify-ssl (boolean)

By default, the AWS CLI uses SSL when communicating with AWS services. For each SSL connection, the AWS CLI will verify SSL certificates. This option overrides the default behavior of verifying SSL certificates.

--no-paginate (boolean)

Disable automatic pagination. If automatic pagination is disabled, the AWS CLI will only make one call, for the first page of results.

--output (string)

The formatting style for command output.

  • json
  • text
  • table
  • yaml
  • yaml-stream
  • off

--query (string)

A JMESPath query to use in filtering the response data.

--profile (string)

Use a specific profile from your credential file.

--region (string)

The region to use. Overrides config/env settings.

--version (string)

Display the version of this tool.

--color (string)

Turn on/off color output.

  • on
  • off
  • auto

--no-sign-request (boolean)

Do not sign requests. Credentials will not be loaded if this argument is provided.

--ca-bundle (string)

The CA certificate bundle to use when verifying SSL certificates. Overrides config/env settings.

--cli-read-timeout (int)

The maximum socket read time in seconds. If the value is set to 0, the socket read will be blocking and not timeout. The default value is 60 seconds.

--cli-connect-timeout (int)

The maximum socket connect time in seconds. If the value is set to 0, the socket connect will be blocking and not timeout. The default value is 60 seconds.

--cli-binary-format (string)

The formatting style to be used for binary blobs. The default format is base64. The base64 format expects binary blobs to be provided as a base64 encoded string. The raw-in-base64-out format preserves compatibility with AWS CLI V1 behavior and binary values must be passed literally. When providing contents from a file that map to a binary blob fileb:// will always be treated as binary and use the file contents directly regardless of the cli-binary-format setting. When using file:// the file contents will need to properly formatted for the configured cli-binary-format.

  • base64
  • raw-in-base64-out

--no-cli-pager (boolean)

Disable cli pager for output.

--cli-auto-prompt (boolean)

Automatically prompt for CLI input parameters.

--no-cli-auto-prompt (boolean)

Disable automatically prompt for CLI input parameters.

--cli-error-format (string)

The formatting style for error output. By default, errors are displayed in enhanced format.

  • legacy
  • json
  • yaml
  • text
  • table
  • enhanced

Output

Items -> (list)

An array of remediation targets returned by the operation.

Constraints:

  • min: 0
  • max: 100

(structure)

A remediation target.

TargetUid -> (string) [required]

The unique identifier (ID) of the remediation target.

Constraints:

  • pattern: .*\S.*

Outcome -> (structure) [required]

The outcome of the remediation target’s resolution.

ResolvedFindingsCount -> (integer) [required]

The number of associated exposure findings that are resolved by remediating the target.

SeverityReductionFindingsCount -> (integer) [required]

The number of associated exposure findings whose severity is reduced by remediating the target.

SeverityUnchangedCount -> (integer) [required]

The number of associated exposure findings whose severity is unchanged by remediating the target.

Priority -> (string) [required]

The remediation target’s priority. Valid values are Critical , High , Medium , and Low .

Possible values:

  • Critical
  • High
  • Medium
  • Low

RemediationSummary -> (structure) [required]

A summary of the remediation target.

Action -> (string) [required]

A summarized action to take for the remediation target.

Constraints:

  • pattern: .*\S.*

Description -> (string)

A description of the remediation target.

Constraints:

  • pattern: .*\S.*

IsImmediate -> (boolean) [required]

Specifies whether the effect of this target is immediate.

PostRemediationSteps -> (list)

An array of steps to be taken after remediation.

Constraints:

  • min: 0
  • max: 50

(string)

Constraints:

  • pattern: .*\S.*

KbArticles -> (list)

An array of KbArticle objects.

Constraints:

  • min: 0
  • max: 10

(structure)

A knowledge base article that provides additional guidance related to the remediation target.

Title -> (string) [required]

The title of the KbArticle .

Constraints:

  • pattern: .*\S.*

Url -> (string) [required]

The URL of the KbArticle .

Constraints:

  • pattern: .*\S.*

Resource -> (structure) [required]

The remediation target’s associated resource.

AccountId -> (string) [required]

The Amazon Web Services account that recorded the resource data in Security Hub.

Constraints:

  • pattern: .*\S.*

Region -> (string) [required]

The Amazon Web Services Region in which Security Hub recorded the resource data.

Constraints:

  • pattern: .*\S.*

ResourceOwnerAccountId -> (string)

The identifier of the cloud account that owns the resource. For Amazon Web Services resources, this is the Amazon Web Services account ID. For Azure resources, this is the Azure subscription ID.

Constraints:

  • pattern: .*\S.*

ResourceOwnerOrgId -> (string)

The identifier of the cloud organization that owns the resource. For Amazon Web Services resources, this is the Organizations ID. For Azure resources, this is the Azure tenant ID.

Constraints:

  • pattern: .*\S.*

Type -> (string) [required]

The type of the resource.

Constraints:

  • pattern: .*\S.*

Name -> (string)

The name of the resource.

Constraints:

  • pattern: .*\S.*

Id -> (string) [required]

The unique identifier for a resource.

Constraints:

  • pattern: .*\S.*

ResourceGuid -> (string)

The global identifier used to identify a resource.

Constraints:

  • pattern: .*\S.*

ResourceRegion -> (string) [required]

The native cloud region where the resource is located. For Amazon Web Services, this is an Amazon Web Services Region (for example, us-east-1 ). For Azure resources, this is the Azure region (for example, westus2 ). This field is always included.

Constraints:

  • pattern: .*\S.*

CloudProvider -> (string) [required]

The cloud provider where the resource exists.

  • AWS specifies that the resource exists in Amazon Web Services.
  • Azure specifies that the resource exists in Microsoft Azure.

Possible values:

  • Azure
  • AWS

Status -> (string) [required]

The current status of the remediation target.

  • New specifies that the remediation target was newly identified.
  • Updated specifies that the remediation target changed after it was identified.
  • Resolved specifies that the remediation target is no longer present.

Possible values:

  • New
  • Updated
  • Resolved

Trait -> (structure) [required]

The trait associated with the remediation target.

Type -> (string) [required]

The trait type.

Constraints:

  • pattern: .*\S.*

Title -> (string) [required]

The trait title.

Constraints:

  • pattern: .*\S.*

Guidance -> (structure)

The remediation target’s guidance. Returned only when ShowGuidance is true in the request.

TargetTypeName -> (string) [required]

The name of the remediation target type.

Constraints:

  • pattern: .*\S.*

Pattern -> (string) [required]

The remediation pattern of the remediation target.

Constraints:

  • pattern: .*\S.*

Version -> (string) [required]

The guidance version.

Constraints:

  • pattern: .*\S.*

Context -> (structure) [required]

The context behind the remediation target’s existence and guidance.

ProblemStatement -> (string)

Explains the cause which directly created the remediation target.

Constraints:

  • pattern: .*\S.*

RiskAssessment -> (string)

An assessment of the existing risk the remediation target creates.

Constraints:

  • pattern: .*\S.*

AffectedScope -> (string)

The scope of the resources affected by the resolution of the remediation target.

Constraints:

  • pattern: .*\S.*

Prerequisites -> (list)

An array of prerequisite steps in resolving the remediation target.

Constraints:

  • min: 0
  • max: 50

(string)

Constraints:

  • pattern: .*\S.*

Specification -> (structure) [required]

The specification of the remediation target guidance. This outlines required resource parameters and permissions, remediation steps, and the end state.

Parameters -> (list)

An array of the parameters used in running the steps provided.

Constraints:

  • min: 0
  • max: 50

(structure)

A parameter used in running the guidance steps.

Name -> (string) [required]

The name of the parameter.

Constraints:

  • pattern: .*\S.*

Type -> (string) [required]

The type of the parameter.

Constraints:

  • pattern: .*\S.*

Description -> (string) [required]

A description of the parameter.

Constraints:

  • pattern: .*\S.*

Required -> (boolean)

Specifies whether the parameter is required for running the guidance steps.

Steps -> (list)

An array of ordered steps for resolving the remediation targets.

Constraints:

  • min: 0
  • max: 50

(structure)

A step in the remediation guidance.

Phase -> (string) [required]

The phase of the remediation plan that this step belongs to (for example, FIX ).

Constraints:

  • pattern: .*\S.*

Description -> (string) [required]

A description of what the step does.

Constraints:

  • pattern: .*\S.*

Service -> (string) [required]

Which service this step is performed in.

Constraints:

  • pattern: .*\S.*

Action -> (string) [required]

The action to be taken for this step.

Constraints:

  • pattern: .*\S.*

Logic -> (string)

The logic behind the existence of this step.

Constraints:

  • pattern: .*\S.*

Inverse -> (string)

The inverse of the step, to be used if the step needs to be rolled back.

Constraints:

  • pattern: .*\S.*

VerifyAfter -> (string)

The action to take after the step to verify its success.

Constraints:

  • pattern: .*\S.*

ExpectedEndState -> (string)

The expected end state of the associated resources after completion of the steps.

Constraints:

  • pattern: .*\S.*

RequiredPermissions -> (list)

An array of required permissions to run the steps.

Constraints:

  • min: 0
  • max: 50

(string)

Constraints:

  • pattern: .*\S.*

Examples -> (structure) [required]

Provided remediation guidance examples in different formats that can be run for remediating the target.

AwsCli -> (string)

An CLI snippet version of the example.

Constraints:

  • pattern: .*\S.*

Cli -> (string)

A CLI snippet version of the example.

Constraints:

  • pattern: .*\S.*

Python -> (string)

A Python snippet version of the example.

Constraints:

  • pattern: .*\S.*

Terraform -> (string)

A Terraform snippet version of the example.

Constraints:

  • pattern: .*\S.*

Cdk -> (string)

A CDK snippet version of the example.

Constraints:

  • pattern: .*\S.*

CloudFormation -> (string)

A CloudFormation snippet version of the example.

Constraints:

  • pattern: .*\S.*

IaC -> (string)

An IaC snippet version of the example.

Constraints:

  • pattern: .*\S.*

Template -> (string)

A Template snippet version of the example.

Constraints:

  • pattern: .*\S.*

Metadata -> (structure) [required]

The metadata of the remediation guidance.

ResourceType -> (string) [required]

The resource type of the remediation target.

Constraints:

  • pattern: .*\S.*

ExposureType -> (string) [required]

The exposure type of the related exposure findings.

Constraints:

  • pattern: .*\S.*

TraitTitles -> (list) [required]

The titles of traits this guidance applies to.

Constraints:

  • min: 0
  • max: 50

(string)

Constraints:

  • pattern: .*\S.*

Reversibility -> (string) [required]

The extent to which changes made in accordance with the guidance can be reversed, for example Fully reversible .

Constraints:

  • pattern: .*\S.*

FixEffect -> (string) [required]

When the fix takes effect, for example Immediate or Deferred .

Constraints:

  • pattern: .*\S.*

RiskLevel -> (string) [required]

The risk when implementing the guidance provided.

Constraints:

  • pattern: .*\S.*

AutomationLevel -> (string)

The extent to which the guidance can be automated, for example Full .

Constraints:

  • pattern: .*\S.*

HumanReviewRequired -> (boolean)

Specifies whether human review is required.

GeneratedAt -> (timestamp)

Timestamp of when the guidance was generated.

For more information about the validation and formatting of timestamp fields in Security Hub CSPM, see Timestamps .

VerificationStatus -> (string)

Verification status of the guidance.

Constraints:

  • pattern: .*\S.*

UpdatedAt -> (timestamp)

The remediation target’s last updated timestamp.

For more information about the validation and formatting of timestamp fields in Security Hub CSPM, see Timestamps .

NextToken -> (string)

The pagination token to use to request the next page of results. Otherwise, this parameter is null.