Documentation Index
Fetch the complete documentation index at: https://docs.iru.com/llms.txt
Use this file to discover all available pages before exploring further.
About AWS Security Hub
AWS Security Hub aggregates findings and compliance posture across enabled Regions. Security Hub must be turned on where you expect evidence. Iru assumes a cross-account IAM role and readssecurityhub: metadata APIs.
How it works
AttachAWSSecurityHubReadOnlyAccess or use:
| Detail | Value |
|---|---|
| Category | Security posture |
| Authentication | Cross-account IAM role |
Prerequisites
- IAM admin rights.
- Security Hub enabled per Region under review.
Connect AWS Security Hub to Iru
Copy the trust policy from Iru
Turn on AWS Security Hub
Find AWS Security Hub (use Category or Search by name or description). On that card, turn on the toggle. Leave the wizard tab open.
Create the IAM role in AWS
Configure trusted entity
Choose AWS account → Another AWS account. Enter
753695775620 (or the ID Iru shows). Enable Require external ID and paste the value from Iru.Attach Security Hub permissions
Attach
AWSSecurityHubReadOnlyAccess, or attach an inline policy matching the JSON under How it works above.Submit the role ARN in Iru
Paste the IAM Role ARN
Return to Iru. Paste the Role ARN into the connector where the wizard prompts for it.
Troubleshooting
Nothing opens when you turn the source on
Nothing opens when you turn the source on
Check pop-up blocker settings for the Iru site and try again.
Empty Regions
Empty Regions
Enable Security Hub there first.
AssumeRole denied
AssumeRole denied
External ID mismatch.
See also
- See Sources Management for the full connector list.
