aws-guardduty-finding-resource-evidence

GuardDuty findings contain access-key IDs, principal names, network endpoints, process/file details, Kubernetes identities, and sampled activity evidence.

awshigh service: aws:guardduty emits CanReadData

Where it sits

locationGetFindings.Findings[]
location kinddata_record
data kindsaccess_key pii sensitive_data customer_data
emits edgeCanReadData
serviceGuardDuty (aws:guardduty)

Collection recipe

access moderead_api
operationGetFindings
response pathFindings[]
encodingjson
params{"DetectorId": "\u003cdetector-id\u003e", "FindingIds": ["\u003cfinding-id\u003e"]}

Required permissions

guardduty:GetFindings

References

move · open · esc close