aws-guardduty-threat-intel-object-content
Custom threat-intelligence files can expose confidential indicators and internal investigation data.
Where it sits
| location | GetThreatIntelSet.Location -> S3 object body |
| location kind | data_record |
| data kinds | sensitive_data pii |
| emits edge | CanReadData |
| service | GuardDuty (aws:guardduty) |
Collection recipe
| access mode | indirect_destination |
| operation | GetThreatIntelSet then s3:GetObject |
| response path | Location -> S3 GetObject.Body |
| encoding | string |
| params | {"DetectorId": "\u003cdetector-id\u003e", "ThreatIntelSetId": "\u003cset-id\u003e"} |
Required permissions
guardduty:GetThreatIntelSet
s3:GetObject
References