aws-guardduty-threat-intel-object-content

Custom threat-intelligence files can expose confidential indicators and internal investigation data.

awshigh service: aws:guardduty emits CanReadData

Where it sits

locationGetThreatIntelSet.Location -> S3 object body
location kinddata_record
data kindssensitive_data pii
emits edgeCanReadData
serviceGuardDuty (aws:guardduty)

Collection recipe

access modeindirect_destination
operationGetThreatIntelSet then s3:GetObject
response pathLocation -> S3 GetObject.Body
encodingstring
params{"DetectorId": "\u003cdetector-id\u003e", "ThreatIntelSetId": "\u003cset-id\u003e"}

Required permissions

guardduty:GetThreatIntelSet
s3:GetObject

References

move · open · esc close