Quick Links

Cloud security in Hearth

Overview

The Cloud security page gives you one place to see the security posture of your connected cloud accounts. The page surfaces the risky misconfigurations, over-permissioned IAM, and exposed resources as follows:

  • Cloud misconfigurations (Cloud Security Posture Management - CSPM): Settings across your cloud accounts that leave resources exposed or weakly protected.
  • Over-permissioned IAM identities (Cloud Infrastructure Entitlement Management - CIEM): Users, roles, and service identities that hold more access than they use. This lens shows you which identities can cause real damage, rather than only which identities exist.

How it works

After you connect a cloud account, Hearth reads the configuration of that account and evaluates it against a set of detectors. Hearth groups the issues into the lenses above and stores them for each workspace, so that the picture builds up over time. Cloud security assesses AWS, Azure, and GCP.

Elements of the Cloud security page

The following table describes the elements of the page:

ElementDescription
IssuesDisplays the cloud misconfigurations and the over-permissioned IAM identities, each with the affected account and resource. They are grouped by triage state – Flagged, Open, Snoozed, Accepted, Hidden, False positive – one row per resource with provider, severity, and fix details.
Coverage lineStates what this release supports. The release covers CSPM and CIEM for your connected accounts. CWPP and DSPM are not yet available.
Row quick actionsSnooze 1 week and Hide
Row ⋯ menuAccept risk (90d), False positive, Prioritize, and Custom snooze…
Hestia actionsInvestigate with Hestia and Ask Hestia how to fix, which send the issue to Hestia

Issue statuses

Every issue starts in the Open status. You can prioritize an issue to flag it, or choose one of the suppressing actions to move the issue out of the Open list. Hearth surfaces an accept or a snooze again when that action expires, and you can reopen a suppressed issue at any time.

Connecting a cloud account

Hearth reads the configuration of a cloud account only after you connect it. Add your data sources on the Integrations page by following the steps provided in each setup guide.

Triaging an issue

To work an issue, do the following:

  1. Navigate to the Cloud security page (Posture > Cloud security).
  2. Review the summary at the top of the page.
  3. Review the issues. 
    Note: An identity issue names the user, role, or service account, the permissions that the identity holds, and the reason for the flag. Hearth usually flags an identity because its access is broader than the access that it uses, or because it grants a sensitive capability.
  4. Do one of the following:
    • Fix the issue in your cloud provider.
    • Click Snooze 1 week or Hide.
    • Click the ⋯ menu, and then click [Accept risk (90d) | False positive | Prioritize | Custom snooze…].
  5. (Optional) To act on a suppressed issue again, reopen it.

Troubleshooting common issues

IssueWhat to do
A provider displays no issuesConfirm that the cloud account is connected. Coverage reflects connected accounts that Hearth has assessed.
You can view issues but do not see the options to accept, snooze, or hide themTriage requires the “Run investigations” permission. Ask an administrator for the permission that you need.