View a markdown version of this page

Choose your path - AWS Security Agent

Choose your path

Find the right starting point for what you want to do with AWS Security Agent. Use the table below to match your goal to a task, then go directly to that page. If you’re new to AWS Security Agent, read What is AWS Security Agent? first for a quick overview.

I want to…​ Who Start here

Understand what AWS Security Agent does before setting it up

Everyone

What is AWS Security Agent?

Set up the service and create an Agent Space

Admin

Set up AWS Security Agent

Test my live or deployed application for exploitable vulnerabilities

User

Quickstart: Run a penetration test

Scan my source code for vulnerabilities and policy violations

User

Quickstart: Run a code review

Model how my application could be attacked (STRIDE)

User

Quickstart: Run a threat model

Get security feedback on a design before I write code

User

Create a design review

Scan code without leaving my IDE (Kiro or Claude Code)

Developer

Run code security scans from your IDE

Scan only my changed lines before merging

Developer

Run a differential code scan with S3

Get automatic security comments on pull requests and merge requests

Admin

Enable code review

Review findings and decide what to fix first

User

Penetration test, Code review, Threat model, Design review

Note

AWS Security Agent uses three roles, which you can identify by the interface you work in: Admin works in the AWS Management Console (setup and configuration), User works in the web application (running assessments and reviewing findings), and Developer works in GitHub or an IDE such as Kiro or Claude Code. A single person can hold more than one role. For full definitions, see How AWS Security Agent works.