aws-detective-graph-investigation-data
Detective's behavior graph aggregates IAM principal, access-key ID, IP, Kubernetes, process, and service activity; it does not normally retain secret key values.
Where it sits
location ListIndicators.Indicators[].IndicatorDetail
location kind data_record
data kinds access_key pii sensitive_data customer_data
emits edge CanReadData
service Detective (aws:detective)
Collection recipe
access mode read_api
operation ListIndicators
response path Indicators[].IndicatorDetail
encoding json
params {"GraphArn": "\u003cgraph-arn\u003e", "InvestigationId": "\u003cinvestigation-id\u003e"}
Required permissions
detective:ListIndicators
Copy
References