Skip to content

Macie Data Discovery

Macie Data Discovery and Classification

AWS Macie automates the discovery and classification of sensitive data across AWS storage services like Amazon S3, relational databases (e.g., RDS), and NoSQL stores (e.g., DynamoDB). This process identifies data at rest, assesses its sensitivity, and integrates findings into AWS Security Hub for centralized threat detection. Below is a structured walkthrough of the workflow.


Data Discovery in Amazon S3

Macie uses automated discovery to scan S3 buckets for unencrypted data, public access, and misconfigured permissions. It also identifies sensitive data using built-in detectors and custom rules.

Example: Enabling Macie for S3 Discovery

aws macie2 put-organization-admin-account --admin-account-id <YOUR_ACCOUNT_ID>
aws macie2 put-organization-admin-account --admin-account-id <YOUR_ACCOUNT_ID>

Custom Data Identifiers

Create custom rules to detect specific patterns (e.g., PII, PCI):

aws macie2 create-custom-data-identifier \
  --name "SSN-Identifier" \
  --description "Detects Social Security Numbers" \
  --regex-pattern "^\d{3}-\d{2}-\d{4}$"

Diagram:

[Data in S3] --> [Macie Discovery] --> [Classification (Custom/Predefined)] --> [Security Hub Findings]


Data Classification in Databases and Storage Services

Macie supports classification of data in relational databases (e.g., RDS) and NoSQL stores (e.g., DynamoDB). It analyzes table schemas, column types, and content to identify sensitive fields.

Example: Classifying RDS Data

  1. Enable database discovery in the Macie console.
  2. Customize classification rules via the AWS CLI:
    aws macie2 create-custom-data-identifier \
      --name "CreditCard-Regex" \
      --regex-pattern ".*(?:4[2-6][0-9]{12}|4[0-9]{12,14}|(?:2131|15[0-9]{2}|63[0-9]{2})[0-9]{12}|(?:5[1-5][0-9]{14}|5[0-9]{14})).*"
    

Integration with AWS Security Hub

Macie automatically sends findings to AWS Security Hub, enabling centralized threat detection and compliance reporting.

Example: Viewing Findings in Security Hub

  1. Navigate to Security Hub > Findings.
  2. Filter by Macie as the source.
  3. Use AWS CLI to retrieve findings:
    aws securityhub get-findings --findings-id <FINDING_ID>
    

Diagram:

[Macie Findings] --> [Security Hub Aggregation] --> [Alerts/Remediation Workflows]


Best Practices and Use Cases

  • Continuous Monitoring: Enable real-time alerts for data exposure.
  • Compliance: Use pre-built classifiers for GDPR, HIPAA, and CCPA.
  • Audit Trails: Leverage Security Hub to generate compliance reports.

Key takeaways

  • Macie automates sensitive data discovery across S3, RDS, and DynamoDB.
  • Custom data identifiers allow tailored classification rules.
  • Security Hub integration centralizes findings for threat response and compliance.
  • Regularly update classifiers and monitor for data exposure risks.