aws-ec2-resource-tags-value-config
EC2 resource tag values are plaintext and broadly enumerable.
Where it sits
| location | DescribeTags.Tags[].Value |
|---|---|
| location kind | tag |
| data kinds | credential sensitive_data pii |
| emits edge | ContainsSecret |
| service | EC2 (aws:ec2) |
Collection recipe
| access mode | read_api |
|---|---|
| operation | DescribeTags |
| response path | Tags[].Value |
| encoding | string |
| params | {"Filters": [{"Name": "resource-id", "Values": ["\u003cresource-id\u003e"]}]} |
Required permissions
ec2:DescribeTags