AWS Security Findings Now Export to SARIF and OCSF
The atmos aws security analyze command is the native Atmos command for turning AWS security findings into infrastructure-aware remediation guidance. It reads findings from AWS Security Hub and Amazon Inspector, including Security Hub product findings from services such as AWS Config, GuardDuty, Macie, and IAM Access Analyzer, then uses Atmos component tags and mapping heuristics to connect affected resources back to the stacks and components that manage them.
Those mappings make findings more actionable: instead of stopping at an AWS resource ARN, Atmos can show the owning stack, component path, severity, source service, and remediation context. With new SARIF 2.1.0 and OCSF 1.4.0 output, those findings can now flow into code scanning, SIEM, governance, risk, and compliance workflows without a translation layer.
What Changed
The command now gains two new output formats:
--format=sarif— produces a SARIF 2.1.0 document. Findings keep their Atmos context (stack, component, component path, remediation steps) as SARIF result properties, so downstream tooling sees the same information the Markdown report does. Output is byte-stable across runs, so diffs and dedup work cleanly.--format=ocsf— produces OCSF 1.4.0 Detection Finding events with cloud and vulnerability profile fields, suitable for SIEM and security data lake ingestion.
# Local SARIF for GitHub code scanning.
atmos aws security analyze --format=sarif --file=findings.sarif
# OCSF Detection Findings for security data lakes.
atmos aws security analyze --format=ocsf --file=findings.ocsf.json
