Detective
| eventName | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all entry for Detective rules that match the service but not a specific eventName. | N | N |
| Accept | Accepts an invitation for the member account to contribute data to a behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet. | N | N |
| Batch | Gets data source package information for the behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet. | N | N |
| Batch | Gets information on the data source package history for an account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet. | N | N |
| Create | Creates a new behavior graph for the calling account, and sets that account as the administrator account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet. | N | N |
| Create | CreateMembers is used to send invitations to accounts. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet. | N | N |
| Delete | Disables the specified behavior graph and queues it to be deleted. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet. | N | N |
| Delete | Removes the specified member accounts from the behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet. | N | N |
| Describe | Returns information about the configuration for the organization behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet. | N | N |
| Disable | Removes the Detective administrator account in the current Region. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet. | N | N |
| Disassociate | Removes the member account from the specified behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet. | N | N |
| Enable | Designates the Detective administrator account for the organization in the current Region. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet. | N | N |
| Get | Detective investigations lets you investigate IAM users and IAM roles using indicators of compromise. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet. | N | N |
| Get | Returns the membership details for specified member accounts for a behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet. | N | N |
| List | Lists data source packages in the behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet. | N | N |
| List | Returns the list of behavior graphs that the calling account is an administrator account of. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| List | Gets the indicators from an investigation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet. | N | N |
| List | Detective investigations lets you investigate IAM users and IAM roles using indicators of compromise. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet. | N | N |
| List | Retrieves the list of open and accepted behavior graph invitations for the member account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet. | N | N |
| List | Retrieves the list of member accounts for a behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet. | N | N |
| List | Returns information about the Detective administrator account for an organization. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| List | Returns the tag values that are assigned to a behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet. | N | N |
| Reject | Rejects an invitation to contribute the account data to a behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet. | N | N |
| Start | Detective investigations lets you investigate IAM users and IAM roles using indicators of compromise. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet. | N | N |
| Start | Sends a request to enable data ingest for a member account that has a status of ACCEPTED_BUT_DISABLED. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet. | N | N |
| Tag | Applies tag values to a behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet. | N | N |
| Untag | Removes tags from a behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet. | N | N |
| Update | Starts a data source package for the Detective behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet. | N | N |
| Update | Updates the state of an investigation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet. | N | N |
| Update | Updates the configuration for the Organizations integration in the current Region. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet. | N | N |
any: Detective (catch-all)
#Description
Catch-all entry for Detective rules that match the service but not a specific eventName.
AcceptInvitation
#Description
Accepts an invitation for the member account to contribute data to a behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.
BatchGetGraphMemberDatasources
#Description
Gets data source package information for the behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.
BatchGetMembershipDatasources
#Description
Gets information on the data source package history for an account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.
CreateGraph
#Description
Creates a new behavior graph for the calling account, and sets that account as the administrator account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.
CreateMembers
#Description
CreateMembers is used to send invitations to accounts. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.
DeleteGraph
#Description
Disables the specified behavior graph and queues it to be deleted. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.
DeleteMembers
#Description
Removes the specified member accounts from the behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.
DescribeOrganizationConfiguration
#Description
Returns information about the configuration for the organization behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.
DisableOrganizationAdminAccount
#Description
Removes the Detective administrator account in the current Region. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.
DisassociateMembership
#Description
Removes the member account from the specified behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.
EnableOrganizationAdminAccount
#Description
Designates the Detective administrator account for the organization in the current Region. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.
GetInvestigation
#Description
Detective investigations lets you investigate IAM users and IAM roles using indicators of compromise. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.
GetMembers
#Description
Returns the membership details for specified member accounts for a behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.
ListDatasourcePackages
#Description
Lists data source packages in the behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.
ListGraphs
#Description
Returns the list of behavior graphs that the calling account is an administrator account of. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "e001fcee-bc9e-4f0a-baa8-46ffe0bceccd",
"eventSource": "detective.amazonaws.com",
"eventName": "ListGraphs",
"awsRegion": "eu-west-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "b2f82626-90d5-45c5-9083-b91603284f4b",
"userAgent": "config.amazonaws.com"
}
ListIndicators
#Description
Gets the indicators from an investigation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.
ListInvestigations
#Description
Detective investigations lets you investigate IAM users and IAM roles using indicators of compromise. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.
ListInvitations
#Description
Retrieves the list of open and accepted behavior graph invitations for the member account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.
ListMembers
#Description
Retrieves the list of member accounts for a behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.
ListOrganizationAdminAccounts
#Description
Returns information about the Detective administrator account for an organization. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "1ab46f63-f716-4872-b880-b7963bcc5e59",
"eventSource": "detective.amazonaws.com",
"eventName": "ListOrganizationAdminAccounts",
"awsRegion": "ap-southeast-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "dee7bdb3-a453-4a50-b78e-56ff44d83d4b",
"userAgent": "config.amazonaws.com",
"errorCode": "AccessDenied"
}
RejectInvitation
#Description
Rejects an invitation to contribute the account data to a behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.
StartInvestigation
#Description
Detective investigations lets you investigate IAM users and IAM roles using indicators of compromise. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.
StartMonitoringMember
#Description
Sends a request to enable data ingest for a member account that has a status of ACCEPTED_BUT_DISABLED. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.
TagResource
#Description
Applies tag values to a behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.
UntagResource
#Description
Removes tags from a behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.
UpdateDatasourcePackages
#Description
Starts a data source package for the Detective behavior graph. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.
UpdateInvestigationState
#Description
Updates the state of an investigation. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.
UpdateOrganizationConfiguration
#Description
Updates the configuration for the Organizations integration in the current Region. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is confirmed by observed CloudTrail records, but no sample confirms this eventName yet.