aws-detective-graph-investigation-data

Detective's behavior graph aggregates IAM principal, access-key ID, IP, Kubernetes, process, and service activity; it does not normally retain secret key values.

awshigh service: aws:detective emits CanReadData

Where it sits

locationListIndicators.Indicators[].IndicatorDetail
location kinddata_record
data kindsaccess_key pii sensitive_data customer_data
emits edgeCanReadData
serviceDetective (aws:detective)

Collection recipe

access moderead_api
operationListIndicators
response pathIndicators[].IndicatorDetail
encodingjson
params{"GraphArn": "\u003cgraph-arn\u003e", "InvestigationId": "\u003cinvestigation-id\u003e"}

Required permissions

detective:ListIndicators

References

move · open · esc close