The identity and technical contract details declared by the specification.
CoverageFilterCriterionKey
string
CoverageEksClusterDetails
object
Information about the EKS cluster that has a coverage status.
4 properties
OrganizationAdditionalConfiguration
object
A list of additional configurations which will be configured for the organization.
2 properties
CoverageFilterCriterion
object
Represents a condition that when matched will be added to the response of the operation.
2 properties
AwsApiCallAction
object
Contains information about the API action.
9 properties
FreeTrialFeatureConfigurationResult
object
Contains information about the free trial period for a feature.
2 properties
FeatureAdditionalConfiguration
string
ScanEc2InstanceWithFindings
object
Describes whether Malware Protection for EC2 instances with findings will be enabled as a data source.
1 property
DataSourcesFreeTrial
object
Contains information about which data sources are enabled for the GuardDuty member account.
6 properties
ThreatIntelSetStatus
string
Resource
object
Contains information about the Amazon Web Services resource associated with the activity that prompted GuardDuty to generate a finding.
12 properties
RuntimeContext
object
Additional information about the suspicious activity.
20 properties
Scan
object
Contains information about a malware scan.
14 properties
DeleteFilterResponse
object
ScanEc2InstanceWithFindingsResult
object
An object that contains information on the status of whether Malware Protection for EC2 instances with findings will be enabled as a data source.
1 property
StartMonitoringMembersResponse
object
1 property
1 required
GetThreatIntelSetResponse
object
5 properties
4 required
OrganizationAdditionalConfigurationResults
array
NetworkInterface
object
Contains information about the elastic network interface of the EC2 instance.
10 properties
ListCoverageResponse
object
2 properties
1 required
Volume
object
Volume used by the Kubernetes workload.
2 properties
LocalIpDetails
object
Contains information about the local IP address of the connection.
1 property
PermissionConfiguration
object
Contains information about how permissions are configured for the S3 bucket.
2 properties
VolumeMount
object
Container volume mount.
2 properties
StopMonitoringMembersResponse
object
1 property
1 required
DefaultServerSideEncryption
object
Contains information on the server side encryption method used in the S3 bucket. See S3 Server-Side Encryption for more information.
2 properties
GetFindingsResponse
object
1 property
1 required
MemberDataSourceConfiguration
object
Contains information on which data sources are enabled for a member account.
3 properties
1 required
ResourceDetails
object
Represents the resources that were scanned in the scan entry.
1 property
ScanFilePath
object
Contains details of infected file including name, file path and hash.
4 properties
OrganizationS3LogsConfiguration
object
Describes whether S3 data event logs will be automatically enabled for new members of the organization.
1 property
1 required
OrganizationMalwareProtectionConfigurationResult
object
An object that contains information on the status of all Malware Protection data source for an organization.
1 property
VpcConfig
object
Amazon Virtual Private Cloud configuration details associated with your Lambda function.
3 properties
ScanResourceCriteria
object
Contains information about criteria used to filter resources before triggering malware scan.
2 properties
Service
object
Contains additional information about the generated finding.
14 properties
MemberDataSourceConfigurations
array
DisassociateMembersResponse
object
1 property
1 required
Member
object
Contains information about the member account.
8 properties
5 required
ListMembersResponse
object
2 properties
UsageResourceResultList
array
OrganizationS3LogsConfigurationResult
object
The current configuration of S3 data event logs as a data source for the organization.
1 property
1 required
LoginAttribute
object
Information about the login attempts.
4 properties
DetectorAdditionalConfigurationResult
object
Information about the additional configuration.
3 properties
MalwareProtectionDataSourceFreeTrial
object
Provides details about Malware Protection when it is enabled as a data source.
1 property
LocalPortDetails
object
Contains information about the port for the local connection.
2 properties
AccountLevelPermissions
object
Contains information about the account level permissions on the S3 bucket.
1 property
CoverageStatistics
object
Information about the coverage statistics for a resource.
2 properties
UnprocessedAccounts
array
UsageDataSourceResultList
array
OrganizationKubernetesConfigurationResult
object
The current configuration of all Kubernetes data sources for the organization.
1 property
1 required
FreeTrialFeatureResult
string
Destination
object
Contains information about the publishing destination, including the ID, type, and status.
3 properties
3 required
HighestSeverityThreatDetails
object
Contains details of the highest severity threat detected during scan and number of infected files.
3 properties
Owner
object
Contains information on the owner of the bucket.
1 property
AccountDetail
object
Contains information about the account.
2 properties
2 required
IamInstanceProfile
object
Contains information about the EC2 instance profile.
2 properties
MemberAdditionalConfiguration
object
Information about the additional configuration for the member account.
2 properties
UpdatePublishingDestinationResponse
object
DisassociateFromMasterAccountResponse
object
This output is deprecated, use DisassociateFromAdministratorAccountResponse instead
KubernetesAuditLogsConfigurationResult
object
Describes whether Kubernetes audit logs are enabled as a data source.
1 property
1 required
GetCoverageStatisticsResponse
object
1 property
InstanceDetails
object
Contains information about the details of an instance.
13 properties
MemberAdditionalConfigurations
array
FindingStatistics
object
Contains information about finding statistics.
1 property
BlockPublicAccess
object
Contains information on how the bucker owner's S3 Block Public Access settings are being applied to the S3 bucket. See S3 Block Public Access for more informat…
4 properties
GetRemainingFreeTrialDaysResponse
object
2 properties
Master
object
Contains information about the administrator account and invitation.
4 properties
Total
object
Contains the total usage with the corresponding currency unit for that value.
2 properties
OrganizationAdditionalConfigurations
array
InternalServerErrorException
InviteMembersResponse
object
1 property
1 required
GetUsageStatisticsResponse
object
2 properties
OrganizationScanEc2InstanceWithFindings
object
Organization-wide EC2 instances with findings scan configuration.
1 property
CreateSampleFindingsResponse
object
KubernetesAuditLogsConfiguration
object
Describes whether Kubernetes audit logs are enabled as a data source.
1 property
1 required
DetectorAdditionalConfiguration
object
Information about the additional configuration for a feature in your GuardDuty account.
2 properties
BucketLevelPermissions
object
Contains information about the bucket level permissions for the S3 bucket.
3 properties
SecurityGroup
object
Contains information about the security groups associated with the EC2 instance.
2 properties
GetAdministratorAccountResponse
object
1 property
1 required
UsageAccountResult
object
Contains information on the total of usage based on account IDs.
2 properties
GetDetectorResponse
object
8 properties
2 required
DetectorAdditionalConfigurations
array
Tag
object
Contains information about a tag associated with the EC2 instance.
2 properties
ScanConditionPair
object
Represents key, value pair to be matched against given resource property.
2 properties
1 required
NetworkConnectionAction
object
Contains information about the NETWORKCONNECTION action described in the finding.
7 properties
ScannedItemCount
object
Total number of scanned files.
3 properties
ThreatsDetectedItemCount
object
Contains total number of infected files.
1 property
ThreatIntelligenceDetails
array
ScanCondition
object
Contains information about the condition.
1 property
1 required
DeletePublishingDestinationResponse
object
OrganizationFeatureConfiguration
object
A list of features which will be configured for the organization.
3 properties
RdsDbUserDetails
object
Contains information about the user and authentication details for a database instance involved in the finding.
5 properties
AccountFreeTrialInfo
object
Provides details of the GuardDuty member account that uses a free trial service.
3 properties
AccessControlList
object
Contains information on the current access control policies for the bucket.
2 properties
CoverageFilterCondition
object
Represents a condition that when matched will be added to the response of the operation.
2 properties
PublicAccess
object
Describes the public access policies that apply to the S3 bucket.
2 properties
UpdateMemberDetectorsResponse
object
1 property
1 required
ScanThreatName
object
Contains files infected with the given threat providing details of malware name and severity.
4 properties
EbsVolumesResult
object
Describes the configuration of scanning EBS volumes as a data source.
2 properties
OrganizationKubernetesAuditLogsConfigurationResult
object
The current configuration of Kubernetes audit logs as a data source for the organization.
1 property
1 required
CreateFilterResponse
object
1 property
1 required
CoverageStatisticsType
string
ScanDetections
object
Contains a complete view providing malware scan result details.
4 properties
ListFindingsResponse
object
2 properties
1 required
GetMembersResponse
object
2 properties
2 required
CreateThreatIntelSetResponse
object
1 property
1 required
DataSourceFreeTrial
object
Contains information about which data sources are enabled for the GuardDuty member account.
1 property
OrganizationFeaturesConfigurationsResults
array
MemberFeaturesConfiguration
object
Contains information about the features for the member account.
3 properties
CountByCoverageStatus
object
ListDetectorsResponse
object
2 properties
1 required
DataSourceConfigurationsResult
object
Contains information on the status of data sources for the detector.
6 properties
4 required
ListPublishingDestinationsResponse
object
2 properties
1 required
FlowLogsConfigurationResult
object
Contains information on the status of VPC flow logs as a data source.
1 property
1 required
ListThreatIntelSetsResponse
object
2 properties
1 required
FilterCriterionList
array
MemberFeaturesConfigurationsResults
array
KubernetesUserDetails
object
Details about the Kubernetes user involved in a Kubernetes finding.
3 properties
FindingCriteria
object
Contains information about the criteria used for querying findings.
1 property
KubernetesDataSourceFreeTrial
object
Provides details about the Kubernetes resources when it is enabled as a data source.
1 property
ScanCriterion
object
Represents a map of resource properties that match specified conditions and values when triggering malware scans.
LineageObject
object
Information about the runtime process details.
9 properties
Administrator
object
Contains information about the administrator account and invitation.
4 properties
OrganizationDataSourceConfigurationsResult
object
An object that contains information on which data sources are automatically enabled for new members within the organization.
3 properties
1 required
DeleteDetectorResponse
object
GetIPSetResponse
object
5 properties
4 required
EksClusterDetails
object
Details about the EKS cluster involved in a Kubernetes finding.
6 properties
S3LogsConfiguration
object
Describes whether S3 data event logs will be enabled as a data source.
1 property
1 required
DescribeOrganizationConfigurationResponse
object
6 properties
1 required
ThreatDetectedByName
object
Contains details about identified threats organized by threat name.
4 properties
DescribePublishingDestinationResponse
object
5 properties
5 required
PrivateIpAddressDetails
object
Contains other private IP address information of the EC2 instance.
2 properties
UsageFeatureResult
object
Contains information about the result of the total usage based on the feature.
2 properties
DestinationProperties
object
Contains the Amazon Resource Name (ARN) of the resource to publish to, such as an S3 bucket, and the ARN of the KMS key to use to encrypt published findings.
2 properties
OrganizationEbsVolumesResult
object
An object that contains information on the status of whether EBS volumes scanning will be enabled as a data source for an organization.
1 property
UsageStatistics
object
Contains the result of GuardDuty usage. If a UsageStatisticType is provided the result for other types will be null.
5 properties
OrganizationKubernetesAuditLogsConfiguration
object
Organization-wide Kubernetes audit logs configuration.
1 property
1 required
UpdateThreatIntelSetResponse
object
DescribeMalwareScansResponse
object
2 properties
1 required
KubernetesConfigurationResult
object
Describes whether any Kubernetes logs will be enabled as a data source.
1 property
1 required
DnsRequestAction
object
Contains information about the DNSREQUEST action described in this finding.
3 properties
DNSLogsConfigurationResult
object
Contains information on the status of DNS logs as a data source.
1 property
1 required
SecurityContext
object
Container security context.
1 property
MemberAdditionalConfigurationResult
object
Information about the additional configuration for the member account.
3 properties
GetFindingsStatisticsResponse
object
1 property
1 required
PortProbeAction
object
Contains information about the PORTPROBE action described in the finding.
2 properties
S3BucketDetail
object
Contains information on the S3 bucket.
8 properties
Container
object
Details of a container.
7 properties
OrganizationEbsVolumes
object
Organization-wide EBS volumes scan configuration.
1 property
UsageResourceResult
object
Contains information on the sum of usage based on an Amazon Web Services resource.
2 properties
DetectorFeatureResult
string
CoverageResourceDetails
object
Information about the resource for each individual EKS cluster.
2 properties
BucketPolicy
object
Contains information on the current bucket policies for the S3 bucket.
2 properties
UpdateIPSetResponse
object
DetectorFeatureConfiguration
object
Contains information about a GuardDuty feature.
3 properties
KubernetesConfiguration
object
Describes whether any Kubernetes data sources are enabled.
1 property
1 required
EcsTaskDetails
object
Contains information about the task in an ECS cluster.
10 properties
OrgFeatureAdditionalConfiguration
string
CoverageFilterCriterionList
array
KubernetesDetails
object
Details about Kubernetes resources such as a Kubernetes user or workload resource involved in a Kubernetes finding.
2 properties
CreateDetectorResponse
object
2 properties
DisassociateFromAdministratorAccountResponse
object
Organization
object
Contains information about the ISP organization of the remote IP address.
4 properties
EbsSnapshotPreservation
string
UnprocessedAccount
object
Contains information about the accounts that weren't processed.
2 properties
2 required
ListFiltersResponse
object
2 properties
1 required
UnarchiveFindingsResponse
object
ProductCode
object
Contains information about the product code for the EC2 instance.
2 properties
CountByResourceType
object
CreateIPSetResponse
object
1 property
1 required
UsageDataSourceResult
object
Contains information on the result of usage based on data source type.
2 properties
DeleteIPSetResponse
object
DetectorAdditionalConfigurationResults
array
AccountFreeTrialInfos
array
UpdateFindingsFeedbackResponse
object
UpdateOrganizationConfigurationResponse
object
EbsVolumeScanDetails
object
Contains details from the malware scan that created a finding.
6 properties
GetMasterAccountResponse
object
This output is deprecated, use GetAdministratorAccountResponse instead
1 property
1 required
EbsVolumeDetails
object
Contains list of scanned and skipped EBS volumes with details.
2 properties
CreatePublishingDestinationResponse
object
1 property
1 required
OrganizationKubernetesConfiguration
object
Organization-wide Kubernetes data sources configurations.
1 property
1 required
Finding
object
Contains information about the finding, which is generated when abnormal or suspicious activity is detected.
15 properties
10 required
MemberFeaturesConfigurationResult
object
Contains information about the features for the member account.
4 properties
AcceptInvitationResponse
object
This output is deprecated, use AcceptAdministratorInvitationResponse instead
ProcessDetails
object
Information about the observed process.
13 properties
ListIPSetsResponse
object
2 properties
1 required
CoverageResource
object
Information about the resource of the GuardDuty account.
7 properties
GetFilterResponse
object
6 properties
3 required
PortProbeDetail
object
Contains information about the port probe details.
3 properties
KubernetesApiCallAction
object
Information about the Kubernetes API call action described in this finding.
7 properties
RemoteIpDetails
object
Contains information about the remote IP address of the connection.
5 properties
CloudTrailConfigurationResult
object
Contains information on the status of CloudTrail as a data source for the detector.
1 property
1 required
MemberAdditionalConfigurationResults
array
UnprocessedDataSourcesResult
object
Specifies the names of the data sources that couldn't be enabled.
1 property
RdsDbInstanceDetails
object
Contains information about the resource type RDSDBInstance involved in a GuardDuty finding.
6 properties
HostPath
object
Represents a pre-existing file or directory on the host machine that the volume maps to.
1 property
OrganizationFeatureConfigurationResult
object
A list of features which will be configured for the organization.
3 properties
OrganizationAdditionalConfigurationResult
object
A list of additional configuration which will be configured for the organization.
2 properties
OrganizationScanEc2InstanceWithFindingsResult
object
An object that contains information on the status of scanning EC2 instances with findings for an organization.
1 property
S3LogsConfigurationResult
object
Describes whether S3 data event logs will be enabled as a data source.
1 property
1 required
GetMemberDetectorsResponse
object
2 properties
2 required
Action
object
Contains information about actions.
7 properties
MalwareProtectionConfigurationResult
object
An object that contains information on the status of all Malware Protection data sources.
2 properties
DetectorFeatureConfigurationResult
object
Contains information about a GuardDuty feature.
4 properties
ArchiveFindingsResponse
object
DetectorFeatureConfigurationsResults
array
EcsClusterDetails
object
Contains information about the details of the ECS Cluster.
8 properties
OrganizationMalwareProtectionConfiguration
object
Organization-wide Malware Protection configurations.
1 property
GetMalwareScanSettingsResponse
object
2 properties
AccessKeyDetails
object
Contains information about the access keys.
4 properties
RemotePortDetails
object
Contains information about the remote port.
2 properties
KubernetesWorkloadDetails
object
Details about the Kubernetes workload involved in a Kubernetes finding.
7 properties
ServiceAdditionalInfo
object
Additional information about the generated finding.
2 properties
ThreatIntelSetFormat
string
DeleteThreatIntelSetResponse
object
FilterCriterion
object
Represents a condition that when matched will be added to the response of the operation. Irrespective of using any filter criteria, an administrator account ca…
2 properties
Condition
object
Contains information about the condition.
12 properties
MalwareProtectionConfiguration
object
Describes whether Malware Protection will be enabled as a data source.
1 property
RdsLoginAttemptAction
object
Indicates that a login attempt was made to the potentially compromised database from a remote IP address.
2 properties
DomainDetails
object
Contains information about the domain.
1 property
ThreatIntelligenceDetail
object
An instance of a threat intelligence detail that constitutes evidence for the finding.
2 properties
UsageFeatureResultList
array
TriggerDetails
object
Represents the reason the scan was triggered.
2 properties
FreeTrialFeatureConfigurationsResults
array
Country
object
Contains information about the country where the remote IP address is located.
2 properties
City
object
Contains information about the city associated with the IP address.
1 property
VolumeDetail
object
Contains EBS volume details.
7 properties
AcceptAdministratorInvitationResponse
object
ScanResultDetails
object
Represents the result of the scan.
1 property
UpdateDetectorResponse
object
UsageAccountResultList
array
CreateMembersResponse
object
1 property
1 required
RuntimeDetails
object
Information about the process and any required context values for a specific finding.
2 properties
DeleteMembersResponse
object
1 property
1 required
LambdaDetails
object
Information about the Lambda function involved in the finding.
9 properties
Evidence
object
Contains information about the reason that the finding was generated.
1 property
GeoLocation
object
Contains information about the location of the remote IP address.
2 properties
RemoteAccountDetails
object
Contains details about the remote Amazon Web Services account that made the API call.
2 properties
FilterCondition
object
Contains information about the condition.
3 properties
UpdateMalwareScanSettingsResponse
object
AddonDetails
object
Information about the installed EKS add-on (GuardDuty security agent).
2 properties
FindingPublishingFrequency
string
FindingStatisticType
string
UpdateFilterResponse
object
1 property
1 required
The full machine-readable OpenAPI contract behind this narrative.
Other APIs Amazon GuardDuty publishes across the network.