Detective

eventNameDescriptionSampleRule
anyCatch-all entry for Detective rules that match the service but not a specific eventName.NN
AcceptInvitationAccepts an invitation for the member account to contribute data to a behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
BatchGetGraphMemberDatasourcesGets data source package information for the behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
BatchGetMembershipDatasourcesGets information on the data source package history for an account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateGraphCreates a new behavior graph for the calling account, and sets that account as the administrator account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
CreateMembersCreateMembers is used to send invitations to accounts. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteGraphDisables the specified behavior graph and queues it to be deleted. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DeleteMembersRemoves the specified member accounts from the behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DescribeOrganizationConfigurationReturns information about the configuration for the organization behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DisableOrganizationAdminAccountRemoves the Detective administrator account in the current Region. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
DisassociateMembershipRemoves the member account from the specified behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
EnableOrganizationAdminAccountDesignates the Detective administrator account for the organization in the current Region. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
GetInvestigationDetective investigations lets you investigate IAM users and IAM roles using indicators of compromise. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
GetMembersReturns the membership details for specified member accounts for a behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListDatasourcePackagesLists data source packages in the behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListGraphsReturns the list of behavior graphs that the calling account is an administrator account of. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListIndicatorsGets the indicators from an investigation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListInvestigationsDetective investigations lets you investigate IAM users and IAM roles using indicators of compromise. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListInvitationsRetrieves the list of open and accepted behavior graph invitations for the member account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListMembersRetrieves the list of member accounts for a behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
ListOrganizationAdminAccountsReturns information about the Detective administrator account for an organization. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListTagsForResourceReturns the tag values that are assigned to a behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
RejectInvitationRejects an invitation to contribute the account data to a behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
StartInvestigationDetective investigations lets you investigate IAM users and IAM roles using indicators of compromise. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
StartMonitoringMemberSends a request to enable data ingest for a member account that has a status of ACCEPTED_BUT_DISABLED. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
TagResourceApplies tag values to a behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UntagResourceRemoves tags from a behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateDatasourcePackagesStarts a data source package for the Detective behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateInvestigationStateUpdates the state of an investigation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN
UpdateOrganizationConfigurationUpdates the configuration for the Organizations integration in the current Region. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.NN

any: Detective (catch-all)

#
Service
detective

Description

Catch-all entry for Detective rules that match the service but not a specific eventName.

AcceptInvitation

#
Service
detective

Description

Accepts an invitation for the member account to contribute data to a behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

BatchGetGraphMemberDatasources

#
Service
detective

Description

Gets data source package information for the behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

BatchGetMembershipDatasources

#
Service
detective

Description

Gets information on the data source package history for an account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateGraph

#
Service
detective

Description

Creates a new behavior graph for the calling account, and sets that account as the administrator account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

CreateMembers

#
Service
detective

Description

CreateMembers is used to send invitations to accounts. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteGraph

#
Service
detective

Description

Disables the specified behavior graph and queues it to be deleted. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DeleteMembers

#
Service
detective

Description

Removes the specified member accounts from the behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DescribeOrganizationConfiguration

#
Service
detective

Description

Returns information about the configuration for the organization behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DisableOrganizationAdminAccount

#
Service
detective

Description

Removes the Detective administrator account in the current Region. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

DisassociateMembership

#
Service
detective

Description

Removes the member account from the specified behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

EnableOrganizationAdminAccount

#
Service
detective

Description

Designates the Detective administrator account for the organization in the current Region. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

GetInvestigation

#
Service
detective

Description

Detective investigations lets you investigate IAM users and IAM roles using indicators of compromise. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

GetMembers

#
Service
detective

Description

Returns the membership details for specified member accounts for a behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListDatasourcePackages

#
Service
detective

Description

Lists data source packages in the behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListGraphs

#
Service
detective

Description

Returns the list of behavior graphs that the calling account is an administrator account of. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "e001fcee-bc9e-4f0a-baa8-46ffe0bceccd",
  "eventSource": "detective.amazonaws.com",
  "eventName": "ListGraphs",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "b2f82626-90d5-45c5-9083-b91603284f4b",
  "userAgent": "config.amazonaws.com"
}

ListIndicators

#
Service
detective

Description

Gets the indicators from an investigation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListInvestigations

#
Service
detective

Description

Detective investigations lets you investigate IAM users and IAM roles using indicators of compromise. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListInvitations

#
Service
detective

Description

Retrieves the list of open and accepted behavior graph invitations for the member account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListMembers

#
Service
detective

Description

Retrieves the list of member accounts for a behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

ListOrganizationAdminAccounts

#
Service
detective

Description

Returns information about the Detective administrator account for an organization. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "1ab46f63-f716-4872-b880-b7963bcc5e59",
  "eventSource": "detective.amazonaws.com",
  "eventName": "ListOrganizationAdminAccounts",
  "awsRegion": "ap-southeast-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "dee7bdb3-a453-4a50-b78e-56ff44d83d4b",
  "userAgent": "config.amazonaws.com",
  "errorCode": "AccessDenied"
}

ListTagsForResource

#
Service
detective

Description

Returns the tag values that are assigned to a behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

RejectInvitation

#
Service
detective

Description

Rejects an invitation to contribute the account data to a behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

StartInvestigation

#
Service
detective

Description

Detective investigations lets you investigate IAM users and IAM roles using indicators of compromise. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

StartMonitoringMember

#
Service
detective

Description

Sends a request to enable data ingest for a member account that has a status of ACCEPTED_BUT_DISABLED. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

TagResource

#
Service
detective

Description

Applies tag values to a behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UntagResource

#
Service
detective

Description

Removes tags from a behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateDatasourcePackages

#
Service
detective

Description

Starts a data source package for the Detective behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateInvestigationState

#
Service
detective

Description

Updates the state of an investigation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.

UpdateOrganizationConfiguration

#
Service
detective

Description

Updates the configuration for the Organizations integration in the current Region. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.