aws-cloudtrail-trail-tags-value-config
CloudTrail trail and event-data-store tag values are plaintext metadata.
Where it sits
| location | ListTags.ResourceTagList[].TagsList[].Value |
|---|---|
| location kind | tag |
| data kinds | credential sensitive_data |
| emits edge | ContainsSecret |
| service | CloudTrail (aws:cloudtrail) |
Collection recipe
| access mode | read_api |
|---|---|
| operation | ListTags |
| response path | ResourceTagList[].TagsList[].Value |
| encoding | string |
| params | {"ResourceIdList": ["\u003cresource-arn\u003e"]} |
Required permissions
cloudtrail:ListTags