aws-ssm-command-invocation-output

Command stdout and stderr can echo credential files, environment variables, and command-line secrets.

awscritical service: aws:ssm emits ContainsCredential

Where it sits

locationGetCommandInvocation.StandardOutputContent / StandardErrorContent
location kindlog_field
data kindscredential password api_key access_key secret_key private_key sensitive_data
emits edgeContainsCredential
serviceSystems Manager (aws:ssm)

Collection recipe

access moderead_api
operationGetCommandInvocation
response pathStandardOutputContent / StandardErrorContent
encodingstring
params{"CommandId": "\u003ccommand-id\u003e", "InstanceId": "\u003cmanaged-node-id\u003e", "PluginName": "\u003coptional-plugin\u003e"}

Required permissions

ssm:GetCommandInvocation

References

move · open · esc close