aws-ssm-session-log-destination

Interactive shell transcripts can record typed passwords, tokens, credential files, and command output.

awscritical service: aws:ssm emits ContainsCredential

Where it sits

locationCloudWatch Logs/S3 Session Manager transcript
location kindlog_field
data kindscredential password api_key access_key secret_key private_key sensitive_data
emits edgeContainsCredential
serviceSystems Manager (aws:ssm)

Collection recipe

access modeindirect_destination
operationlogs:FilterLogEvents or s3:GetObject
response pathtranscript event or object body
encodingstring
params{"Destination": "\u003csession-log-destination\u003e", "SessionId": "\u003csession-id\u003e"}

Required permissions

ssm:DescribeSessions
logs:FilterLogEvents

References

move · open · esc close