Mods
AWS

IAM Role: AWS/Security Hub/Admin

PermissionGrant
iam:PassRoleAdmin
securityhub:AcceptInvitationAdmin
securityhub:BatchDisableStandardsAdmin
securityhub:BatchEnableStandardsAdmin
securityhub:BatchImportFindingsAdmin
securityhub:CancelProductSubscriptionAdmin
securityhub:CreateActionTargetAdmin
securityhub:CreateInsightAdmin
securityhub:CreateMembersAdmin
securityhub:DeclineInvitationsAdmin
securityhub:DeleteActionTargetAdmin
securityhub:DeleteInsightAdmin
securityhub:DeleteInvitationsAdmin
securityhub:DeleteMembersAdmin
securityhub:DisableSecurityHubAdmin
securityhub:DisassociateFromMasterAccountAdmin
securityhub:DisassociateMembersAdmin
securityhub:EnableImportFindingsForProductAdmin
securityhub:EnableSecurityHubAdmin
securityhub:InviteMembersAdmin
securityhub:UpdateActionTargetAdmin
securityhub:UpdateFindingsAdmin
securityhub:UpdateInsightAdmin
securityhub:DisableImportFindingsForProductOperator
securityhub:TagResourceOperator
securityhub:UntagResourceOperator
health:DescribeEventAggregatesMetadata
securityhub:DescribeActionTargetsMetadata
securityhub:DescribeHubMetadata
securityhub:DescribeProductsMetadata
securityhub:GetEnabledStandardsMetadata
securityhub:GetFindingsMetadata
securityhub:GetInsightResultsMetadata
securityhub:GetInsightsMetadata
securityhub:GetInvitationsCountMetadata
securityhub:GetMasterAccountMetadata
securityhub:GetMembersMetadata
securityhub:GetProductSubscriptionMetadata
securityhub:IsSecurityHubEnabledMetadata
securityhub:ListEnabledProductsForImportMetadata
securityhub:ListInvitationsMetadata
securityhub:ListMembersMetadata
securityhub:ListTagsForResourceMetadata