Auto-remediate open EC2 security groups with AI agents

Starting promptUse this prompt as a starting point to build your workflow.

Build a workflow triggered by AWS Security Hub findings for the EC2.19 control (overly permissive security groups). For each finding, use an AI agent to investigate the rule and its context, then revoke the unauthorized ingress rules via the EC2 API. Open a Tines case documenting the finding and actions; if it can't be auto-remediated, escalate via email to the owner. Require approval for production changes, handle already-resolved findings, and retry API errors. Output the remediation result and case reference per finding.

New to Tines?Sign up free for Tines 3B Explore Edition

What this prompt builds

Detect overly permissive EC2 security groups, investigate with an agent, and strip unauthorized rules.

The problem

Open security groups (the EC2.19 control) expose ports like SSH/RDP to the internet and are a leading cause of cloud compromise, yet they accumulate faster than teams can review them. Manual remediation lags detection.

Solution and impact

This workflow monitors Security Hub for EC2.19 violations, uses an agent to investigate each, removes unauthorized network rules, and documents everything in Tines Cases while escalating unresolved issues by email. Risky exposures get closed quickly with a full audit trail.

Auto-remediate open EC2 security groups with AI agents | Tines 3B examples | Tines