Jul 23, 2026
Enterprise

AWS extends Security Hub to Azure and AI workload monitoring

AWS added Azure posture checks and AI-specific GuardDuty features to Security Hub, pushing the service beyond its AWS-only CSPM roots.

Colin Brandt

By Colin Brandt · Enterprise Reporter

· 3 min read

AWS extends Security Hub to Azure and AI workload monitoring
Photo: SiliconANGLE

Amazon Web Services has expanded Security Hub with Microsoft Azure monitoring and new AI workload protections, a move aimed at making the product a broader security control plane for enterprises running across clouds. The company did not disclose customer adoption, revenue impact or detailed price points for the new capabilities.

The update shifts Security Hub further from its original role as an AWS cloud security posture management tool. AWS is now positioning it as a common place to collect, rank and act on findings from AWS services, Azure resources and partner products, with AI systems treated as first-class assets rather than exceptions handled by separate processes.

What AWS added

AWS said Security Hub can now discover and monitor several Azure resource types: Virtual Machines, container images in Azure Container Registry, Function Apps and identities. The service evaluates those assets for misconfigurations, internet exposure and software vulnerabilities, including checks tied to the CIS Microsoft Azure Foundations Benchmark.

Findings from Azure appear next to AWS findings using the same format, prioritization model and automation workflows, according to AWS. That is the practical pitch for security teams already trying to reconcile posture data from multiple consoles and rule sets.

Michael Fuller, director of security services at AWS, told analyst Zeus Kerravala of ZK Research that customers have been asking AWS not to force them into separate tooling as their environments move beyond one cloud. Fuller also said AWS Config now underpins the Azure monitoring, using change-triggered evaluation rather than the 24-hour polling cycle he associated with many third-party CSPM products.

AWS said setup is handled through a tenant-level decision in Azure and read-only access. The company is consolidating pricing into a per-resource-per-month model across AWS and Azure for four resource categories: virtual machines, container images, functions and identities. Specific dollar amounts were not provided in the details reviewed.

AI security gets pulled into GuardDuty

The AI portion of the release includes GuardDuty AI Protection, GuardDuty AI-powered investigations in preview and a Security Hub AI inventory. AWS said the capabilities are intended for AI workloads using services such as Amazon Bedrock and SageMaker.

GuardDuty AI Protection is designed to detect activity AWS describes as specific to AI services, including unusual model invocation patterns, prompt-injection attempts through an integration with Bedrock Guardrails and “cost harvesting.” AWS uses that term for attacks in which compromised access is used to run large volumes of inference at the victim’s expense, an AI-era variant of cloud abuse patterns such as unauthorized compute usage.

The investigations feature, currently in preview, is meant to reduce manual triage work after GuardDuty raises an alert. AWS said it can gather related activity, affected-resource context and threat intelligence, then produce a confidence score, MITRE ATT&CK mapping, supporting evidence and recommended actions such as suppression, containment or further investigation. Analysts still make the decision, according to AWS.

Fuller said GuardDuty’s production history since 2017 informed how AWS built the investigation capability. That claim is useful context, though AWS has not disclosed benchmarks showing how much the preview reduces triage time or false positives in customer environments.

The inventory layer

Security Hub is also adding an AI inventory that tracks Bedrock models, SageMaker endpoints and agents built with Amazon AgentCore. AWS said the inventory maps those assets to the compute, networking, IAM and data stores they depend on, giving security teams a clearer view of exposure and blast radius.

AWS also said Security Hub Extended now includes 21 curated partner solutions across nine categories, with findings normalized through OCSF. Named partners include CrowdStrike, Okta, Cyera and Splunk.

The broader signal is straightforward: AWS wants Security Hub to compete less as another posture dashboard and more as the operating layer for cloud and AI security workflows. The open question is whether customers with entrenched SIEM, CSPM and partner stacks will centralize more of that work in AWS, especially when their AI deployments span Azure as well as AWS.

This story draws on original reporting from SiliconANGLE.

More from Enterprise

All Enterprise →