aws-guardduty-ip-set-object-content

Trusted IP set files can reveal private partners, scanner ranges, or sensitive network allowlists; the S3 object is the authoritative content.

awshigh service: aws:guardduty emits CanReadData

Where it sits

locationGetIPSet.Location -> S3 object body
location kinddata_record
data kindssensitive_data pii credential
emits edgeCanReadData
serviceGuardDuty (aws:guardduty)

Collection recipe

access modeindirect_destination
operationGetIPSet then s3:GetObject
response pathLocation -> S3 GetObject.Body
encodingstring
params{"DetectorId": "\u003cdetector-id\u003e", "IpSetId": "\u003cip-set-id\u003e"}

Required permissions

guardduty:GetIPSet
s3:GetObject

References

move · open · esc close