Elastic Container Service

eventNameDescriptionSampleRule
anyCatch-all entry for Elastic Container Service rules that match the service but not a specific eventName.NN
DescribeTaskDefinitionDescribes a task definition registered to Amazon ECS, returning its family, revision, container definitions, and configuration.YY
RegisterTaskDefinitionRegisters a new task definition from the supplied family and containerDefinitions, creating a new revision in Amazon ECS.YY
RunTaskStarts a new task on a specified cluster using the specified task definition.NY
ContinueServiceDeploymentContinues or rolls back an Amazon ECS service deployment that is paused at a lifecycle hook.NN
CreateCapacityProviderCreates a capacity provider.NN
CreateClusterCreates a new Amazon ECS cluster.YN
CreateDaemonCreates a new daemon in the specified cluster and capacity providers.NN
CreateExpressGatewayServiceCreates an Express service that simplifies deploying containerized web applications on Amazon ECS with managed Amazon Web Services infrastructure.NN
CreateServiceRuns and maintains your desired number of tasks from a specified task definition.YY
CreateTaskSetCreate a task set in the specified cluster and service.NN
DeleteAccountSettingDisables an account setting for a specified user, role, or the root user for an account.YN
DeleteAttributesDeletes one or more custom attributes from an Amazon ECS resource.YN
DeleteCapacityProviderDeletes the specified capacity provider.YN
DeleteClusterDeletes the specified cluster.YN
DeleteDaemonDeletes the specified daemon.YN
DeleteDaemonTaskDefinitionDeletes the specified daemon task definition.YN
DeleteExpressGatewayServiceDeletes an Express service and removes all associated Amazon Web Services resources.YN
DeleteServiceDeletes a specified service within a cluster.YN
DeleteTaskDefinitionsDeletes one or more task definitions.YN
DeleteTaskSetDeletes a specified task set within a service.YN
DeregisterContainerInstanceDeregisters an Amazon ECS container instance from the specified cluster.YN
DeregisterTaskDefinitionDeregisters the specified task definition by family and revision.YN
DescribeCapacityProvidersDescribes one or more of your capacity providers.YN
DescribeClustersDescribes one or more of your clusters.YN
DescribeContainerInstancesDescribes one or more container instances.YN
DescribeDaemonDescribes the specified daemon.YN
DescribeDaemonDeploymentsDescribes one or more of your daemon deployments.YN
DescribeDaemonRevisionsDescribes one or more of your daemon revisions.YN
DescribeDaemonTaskDefinitionDescribes a daemon task definition.YN
DescribeExpressGatewayServiceRetrieves detailed information about an Express service, including current status, configuration, managed infrastructure, and service revisions.YN
DescribeServiceDeploymentsDescribes one or more of your service deployments.YN
DescribeServiceRevisionsDescribes one or more service revisions.YN
DescribeServicesDescribes the specified services running in your cluster.YN
DescribeTasksDescribes a specified task or tasks.YN
DescribeTaskSetsDescribes the task sets in the specified cluster and service.YN
DiscoverPollEndpointThis action is only used by the Amazon ECS agent, and it is not intended for use outside of the agent.YN
ExecuteCommandRuns a command remotely on a container within a task.NN
GetTaskProtectionRetrieves the protection status of tasks in an Amazon ECS service.YN
ListAccountSettingsLists the account settings for a specified principal.YN
ListAttributesLists the attributes for Amazon ECS resources within a specified target type and cluster.YN
ListClustersReturns a list of existing clusters.YN
ListContainerInstancesReturns a list of container instances in a specified cluster.YN
ListDaemonDeploymentsReturns a list of daemon deployments for a specified daemon.YN
ListDaemonsReturns a list of daemons.YN
ListDaemonTaskDefinitionsReturns a list of daemon task definitions that are registered to your account.YN
ListServiceDeploymentsThis operation lists all the service deployments that meet the specified filter criteria.YN
ListServicesReturns a list of services.YN
ListServicesByNamespaceThis operation lists all of the services that are associated with a Cloud Map namespace.YN
ListTagsForResourceList the tags for an Amazon ECS resource.YN
ListTaskDefinitionFamiliesReturns a list of task definition families that are registered to your account.YN
ListTaskDefinitionsReturns a list of task definitions that are registered to your account.YN
ListTasksReturns a list of tasks.YN
PutAccountSettingModifies an account setting.YN
PutAccountSettingDefaultModifies an account setting for all users on an account for whom no individual account setting has been specified.YN
PutAttributesCreate or update an attribute on an Amazon ECS resource.NN
PutClusterCapacityProvidersModifies the available capacity providers and the default capacity provider strategy for a cluster.YN
RegisterContainerInstanceThis action is only used by the Amazon ECS agent, and it is not intended for use outside of the agent.NN
RegisterDaemonTaskDefinitionRegisters a new daemon task definition from the supplied family and containerDefinitions.NN
StartTaskStarts a new task from the specified task definition on the specified container instance or instances.NY
StopServiceDeploymentStops an ongoing service deployment.YN
StopTaskStops a running task.YN
SubmitAttachmentStateChangesThis action is only used by the Amazon ECS agent, and it is not intended for use outside of the agent.NN
SubmitContainerStateChangeThis action is only used by the Amazon ECS agent, and it is not intended for use outside of the agent.NN
SubmitTaskStateChangeThis action is only used by the Amazon ECS agent, and it is not intended for use outside of the agent.NN
TagResourceAssociates the specified tags to a resource with the specified resourceArn.YN
UntagResourceDeletes specified tags from a resource.YN
UpdateCapacityProviderModifies the parameters for a capacity provider.YN
UpdateClusterUpdates the cluster.YN
UpdateClusterSettingsModifies the settings to use for a cluster.YN
UpdateContainerAgentUpdates the Amazon ECS container agent on a specified container instance.YN
UpdateContainerInstancesStateModifies the status of an Amazon ECS container instance.YN
UpdateDaemonUpdates the specified daemon.YN
UpdateExpressGatewayServiceUpdates an existing Express service configuration.YN
UpdateServiceModifies the parameters of a service.YN
UpdateServicePrimaryTaskSetModifies which task set in a service is the primary task set.YN
UpdateTaskProtectionUpdates the protection status of a task.YN
UpdateTaskSetModifies a task set.YN
TaskCreatedTaskCreated recorded by CloudTrail for Amazon Elastic Container Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN

any: Elastic Container Service (catch-all)

#
Service
ecs

Description

Catch-all entry for Elastic Container Service rules that match the service but not a specific eventName.

DescribeTaskDefinition

#
Service
ecs

Description

Describes a task definition registered to Amazon ECS, returning its family, revision, container definitions, and configuration.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ClientException",
  "errorMessage": "Unable to describe task definition.",
  "eventCategory": "Management",
  "eventID": "b1e0cc2b-eb76-4331-aa95-60e70558665e",
  "eventName": "DescribeTaskDefinition",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T18:43:21Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "311d5b27-b119-4798-95cb-1d68c3a5b106",
  "requestParameters": {
    "taskDefinition": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

RegisterTaskDefinition

#
Service
ecs

Description

Registers a new task definition from the supplied family and containerDefinitions, creating a new revision in Amazon ECS.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "8c65bfd5-1a78-4de4-ad9e-d83f9f0f9615",
  "eventName": "RegisterTaskDefinition",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T20:07:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "ecd7b6ad-36f5-40e5-96ad-9a5a50e71b84",
  "requestParameters": {
    "containerDefinitions": [
      {
        "cpu": 0,
        "essential": true,
        "image": "busybox",
        "memory": 128,
        "name": "dw"
      }
    ],
    "dryrun": false,
    "family": "dwfix-td"
  },
  "responseElements": {
    "taskDefinition": {
      "compatibilities": [
        "EXTERNAL",
        "EC2"
      ],
      "containerDefinitions": [
        {
          "cpu": 0,
          "environment": "HIDDEN_DUE_TO_SECURITY_REASONS",
          "essential": true,
          "image": "busybox",
          "memory": 128,
          "mountPoints": [],
          "name": "dw",
          "portMappings": [],
          "systemControls": [],
          "volumesFrom": []
        }
      ],
      "family": "dwfix-td",
      "placementConstraints": [],
      "registeredAt": "2026-06-29T20:07:28Z",
      "registeredBy": "arn:aws:iam::123456789012:user/sample-user",
      "revision": 1,
      "status": "ACTIVE",
      "taskDefinitionArn": "arn:aws:ecs:us-west-1:123456789012:task-definition/dwfix-td:1",
      "volumes": []
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • AWS Potential Cryptomining via ECS Task Definition Deployment source high: Identifies a principal that, within a short window, both registers an Amazon ECS task definition using a public / non-ECR container image at a high CPU allocation (8 or 16 vCPU) AND launches ECS workloads (RunTask, StartTask, or CreateService). Registering a public miner image at maximum compute and then launching it is the ECS/Fargate cryptocurrency-mining deployment pattern seen after credential compromise. Requiring both the mining-signature registration and a launch by the same principal confirms an actual deployment rather than a standalone (possibly benign) task-definition registration, which sharply reduces false positives from high-compute workloads that are merely registered.T1496↳ also matches RunTask, CreateService, StartTask

RunTask

#
Service
ecs

Description

Starts a new task on a specified cluster using the specified task definition.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "4e582835-af26-4b8e-9042-0fefd60e4b52",
  "eventSource": "ecs.amazonaws.com",
  "eventName": "RunTask",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "b4f0bf93-b55b-4bf1-b44c-bc3d440da231",
  "userAgent": "events.amazonaws.com"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • AWS Potential Cryptomining via ECS Task Definition Deployment source high: Identifies a principal that, within a short window, both registers an Amazon ECS task definition using a public / non-ECR container image at a high CPU allocation (8 or 16 vCPU) AND launches ECS workloads (RunTask, StartTask, or CreateService). Registering a public miner image at maximum compute and then launching it is the ECS/Fargate cryptocurrency-mining deployment pattern seen after credential compromise. Requiring both the mining-signature registration and a launch by the same principal confirms an actual deployment rather than a standalone (possibly benign) task-definition registration, which sharply reduces false positives from high-compute workloads that are merely registered.T1496↳ also matches RegisterTaskDefinition, CreateService, StartTask

ContinueServiceDeployment

#
Service
ecs

Description

Continues or rolls back an Amazon ECS service deployment that is paused at a lifecycle hook.

CreateCapacityProvider

#
Service
ecs

Description

Creates a capacity provider.

CreateCluster

#
Service
ecs

Description

Creates a new Amazon ECS cluster.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "7c7bb44d-412d-4e32-a8f0-50a9efbf53e5",
  "eventName": "CreateCluster",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T20:07:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "1db0d811-2d97-4270-96f2-9f91503e1fa8",
  "requestParameters": {
    "clusterName": "dwfix-cluster"
  },
  "responseElements": {
    "cluster": {
      "activeServicesCount": 0,
      "capacityProviders": [],
      "clusterArn": "arn:aws:ecs:us-west-1:123456789012:cluster/dwfix-cluster",
      "clusterName": "dwfix-cluster",
      "defaultCapacityProviderStrategy": [],
      "pendingTasksCount": 0,
      "registeredContainerInstancesCount": 0,
      "runningTasksCount": 0,
      "settings": [
        {
          "name": "containerInsights",
          "value": "disabled"
        }
      ],
      "statistics": [],
      "status": "ACTIVE",
      "tags": []
    },
    "clusterCount": 1
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateDaemon

#
Service
ecs

Description

Creates a new daemon in the specified cluster and capacity providers.

CreateExpressGatewayService

#
Service
ecs

Description

Creates an Express service that simplifies deploying containerized web applications on Amazon ECS with managed Amazon Web Services infrastructure.

CreateService

#
Service
ecs

Description

Runs and maintains your desired number of tasks from a specified task definition.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "07982dee-31aa-4d48-b8e3-d4a5795defac",
  "eventName": "CreateService",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T21:00:52Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "a45b8f12-63f7-42fa-8a43-c7def279e671",
  "requestParameters": {
    "cluster": "dwfix-ecs-cluster",
    "desiredCount": 0,
    "dryrun": false,
    "enableECSManagedTags": false,
    "enableExecuteCommand": false,
    "serviceName": "dwfix-svc",
    "taskDefinition": "dwfix-task"
  },
  "responseElements": {
    "service": {
      "availabilityZoneRebalancing": "ENABLED",
      "clusterArn": "arn:aws:ecs:us-west-1:123456789012:cluster/dwfix-ecs-cluster",
      "createdAt": "2026-06-29T21:00:52Z",
      "createdBy": "arn:aws:iam::123456789012:user/sample-user",
      "currentServiceRevisions": [
        {
          "arn": "arn:aws:ecs:us-west-1:123456789012:service-revision/dwfix-ecs-cluster/dwfix-svc/8700944245995359981",
          "pendingTaskCount": 0,
          "requestedTaskCount": 0,
          "runningTaskCount": 0
        }
      ],
      "deploymentConfiguration": {
        "bakeTimeInMinutes": 0,
        "deploymentCircuitBreaker": {
          "enable": false,
          "resetOnHealthyTask": true,
          "rollback": false,
          "thresholdConfiguration": {
            "type": "BOUNDED_PERCENT",
            "value": 50
          }
        },
        "maximumPercent": 200,
        "minimumHealthyPercent": 100,
        "strategy": "ROLLING"
      },
      "deploymentController": {
        "type": "ECS"
      },
      "deployments": [
        {
          "createdAt": "2026-06-29T21:00:52Z",
          "desiredCount": 0,
          "failedLaunchTaskCount": 0,
          "failedTasks": 0,
          "id": "ecs-svc/8700944245995359981",
          "launchType": "EC2",
          "pendingCount": 0,
          "replacedTaskCount": 0,
          "rolloutState": "IN_PROGRESS",
          "rolloutStateReason": "ECS deployment ecs-svc/8700944245995359981 in progress.",
          "runningCount": 0,
          "scale": {
            "unit": "PERCENT",
            "value": 0.0
          },
          "stabilityStatus": "STABILIZING",
          "status": "PRIMARY",
          "taskDefinition": "arn:aws:ecs:us-west-1:123456789012:task-definition/dwfix-task:1",
          "totalFailedTasks": 0,
          "updatedAt": "2026-06-29T21:00:52Z"
        }
      ],
      "desiredCount": 0,
      "enableECSManagedTags": false,
      "enableExecuteCommand": false,
      "events": [],
      "extendDeploymentTimePeriod": 0,
      "healthCheckGracePeriodSeconds": 0,
      "launchType": "EC2",
      "loadBalancers": [],
      "pendingCount": 0,
      "placementConstraints": [],
      "placementStrategy": [],
      "propagateTags": "NONE",
      "resourceManagementType": "CUSTOMER",
      "runningCount": 0,
      "schedulingStrategy": "REPLICA",
      "serviceArn": "arn:aws:ecs:us-west-1:123456789012:service/dwfix-ecs-cluster/dwfix-svc",
      "serviceName": "dwfix-svc",
      "serviceRegistries": [],
      "status": "ACTIVE",
      "taskDefinition": "arn:aws:ecs:us-west-1:123456789012:task-definition/dwfix-task:1",
      "version": 0
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,D,n cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS Potential Cryptomining via ECS Task Definition Deployment source high: Identifies a principal that, within a short window, both registers an Amazon ECS task definition using a public / non-ECR container image at a high CPU allocation (8 or 16 vCPU) AND launches ECS workloads (RunTask, StartTask, or CreateService). Registering a public miner image at maximum compute and then launching it is the ECS/Fargate cryptocurrency-mining deployment pattern seen after credential compromise. Requiring both the mining-signature registration and a launch by the same principal confirms an actual deployment rather than a standalone (possibly benign) task-definition registration, which sharply reduces false positives from high-compute workloads that are merely registered.T1496↳ also matches RegisterTaskDefinition, RunTask, StartTask

CreateTaskSet

#
Service
ecs

Description

Create a task set in the specified cluster and service.

DeleteAccountSetting

#
Service
ecs

Description

Disables an account setting for a specified user, role, or the root user for an account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "Referenced setting doesn't exist",
  "eventCategory": "Management",
  "eventID": "7c3e90db-90b3-404d-800e-fd9c105a2169",
  "eventName": "DeleteAccountSetting",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T19:23:11Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "334bbdde-7eb0-485b-805d-d879bd3f5073",
  "requestParameters": {
    "dryrun": false,
    "name": "serviceLongArnFormat"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteAttributes

#
Service
ecs

Description

Deletes one or more custom attributes from an Amazon ECS resource.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "Blank target Id found.",
  "eventCategory": "Management",
  "eventID": "434b8ea0-8f0d-4efb-a5c9-9c5ae81b4da7",
  "eventName": "DeleteAttributes",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T19:23:11Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "665bf62c-6395-42ac-ac86-ac732dfbb631",
  "requestParameters": {
    "attributes": [
      {
        "name": "dw-probe"
      }
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteCapacityProvider

#
Service
ecs

Description

Deletes the specified capacity provider.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ClientException",
  "errorMessage": "Failed to get info for provided CapacityProvider",
  "eventCategory": "Management",
  "eventID": "2cbed8a5-0ca3-41ee-8eaa-16f311ca1ecd",
  "eventName": "DeleteCapacityProvider",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T19:23:11Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "54708813-e649-4ad0-b602-553ec070f94e",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteCluster

#
Service
ecs

Description

Deletes the specified cluster.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ClusterNotFoundException",
  "errorMessage": "Cluster not found.",
  "eventCategory": "Management",
  "eventID": "05258c0f-daa8-443b-a997-bff9b75e8d2e",
  "eventName": "DeleteCluster",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T19:23:11Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "c383c74c-24a0-497a-82f7-31ed43d8f66d",
  "requestParameters": {
    "cluster": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteDaemon

#
Service
ecs

Description

Deletes the specified daemon.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "The Daemon ARN is invalid",
  "eventCategory": "Management",
  "eventID": "8316e21f-9540-49c4-af53-9e86879718d9",
  "eventName": "DeleteDaemon",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T19:23:11Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "5b17fb64-00fe-43e2-bd81-455e7a30c0ad",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteDaemonTaskDefinition

#
Service
ecs

Description

Deletes the specified daemon task definition.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "The Daemon Task Definition is invalid",
  "eventCategory": "Management",
  "eventID": "bd7e49bb-6fe5-4d30-8de9-aab90fa78ae1",
  "eventName": "DeleteDaemonTaskDefinition",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T19:23:11Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "3825eaf6-546c-44d8-a706-fc1023445872",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteExpressGatewayService

#
Service
ecs

Description

Deletes an Express service and removes all associated Amazon Web Services resources.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "ServiceArn is not valid: ARNs must start with 'arn:': dw-probe",
  "eventCategory": "Management",
  "eventID": "1dc4d35e-90e6-48ee-bb67-e47fc414583a",
  "eventName": "DeleteExpressGatewayService",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T19:23:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "a3a77d63-948c-4a82-a010-c8f48d1f0b2c",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteService

#
Service
ecs

Description

Deletes a specified service within a cluster.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ClusterNotFoundException",
  "errorMessage": "Cluster not found.",
  "eventCategory": "Management",
  "eventID": "17aa50e3-80f7-4fbe-944f-71639c9dad9e",
  "eventName": "DeleteService",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T19:23:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "471a6f71-d9a4-49d9-846f-b50c66951e47",
  "requestParameters": {
    "service": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteTaskDefinitions

#
Service
ecs

Description

Deletes one or more task definitions.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "b0a03a20-057a-4000-b915-90e78cbd2eda",
  "eventName": "DeleteTaskDefinitions",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T19:23:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "4c436049-b3ef-4dcc-bbf3-0763105d4b78",
  "requestParameters": {
    "taskDefinitions": [
      "dw-probe"
    ]
  },
  "responseElements": {
    "failures": [
      {
        "arn": "dw-probe",
        "reason": "The specified task definition identifier is invalid. Specify a valid name or ARN and try again."
      }
    ],
    "taskDefinitions": []
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteTaskSet

#
Service
ecs

Description

Deletes a specified task set within a service.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "TaskSet must match ^ecs-svc/\\d{19}$, but was dw-probe",
  "eventCategory": "Management",
  "eventID": "02efa6de-6b33-4299-9cf8-a4e087f87c15",
  "eventName": "DeleteTaskSet",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T19:23:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "57ad4ece-38d2-4ede-ab94-84cd188fb45f",
  "requestParameters": {
    "cluster": "dw-probe",
    "dryrun": false,
    "service": "dw-probe",
    "taskSet": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeregisterContainerInstance

#
Service
ecs

Description

Deregisters an Amazon ECS container instance from the specified cluster.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ClusterNotFoundException",
  "errorMessage": "Cluster not found.",
  "eventCategory": "Management",
  "eventID": "564defc2-cbd9-4d8c-83d5-c9b712137144",
  "eventName": "DeregisterContainerInstance",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T19:23:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "414918fe-a8a8-411d-a75d-7a61a4aea239",
  "requestParameters": {
    "containerInstance": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeregisterTaskDefinition

#
Service
ecs

Description

Deregisters the specified task definition by family and revision.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "Revision is missing",
  "eventCategory": "Management",
  "eventID": "590e49ef-601c-4125-a92a-cde2dc33f7fa",
  "eventName": "DeregisterTaskDefinition",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T19:23:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "a710d6ab-daa4-415a-82ce-bc9cd490aa47",
  "requestParameters": {
    "dryrun": false,
    "taskDefinition": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeCapacityProviders

#
Service
ecs

Description

Describes one or more of your capacity providers.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: ecs:DescribeCapacityProviders on resource: arn:aws:ecs:us-east-1:811596193553:capacity-provider/*",
  "eventID": "b77a1dc0-d737-4108-9cde-a9e8e57c2b30",
  "eventName": "DescribeCapacityProviders",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2020-06-10T05:32:32Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "517912bd1-2d9a-45e8-9e6c-e779f361395c",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "251.105.254.1",
  "userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeClusters

#
Service
ecs

Description

Describes one or more of your clusters.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "eventID": "7dabd9b1-8297-44bd-a4cc-cd0803841f87",
  "eventName": "DescribeClusters",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2020-09-29T17:41:31Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "e539c3fb-be87-4dde-9dc6-d122bfaae012",
  "requestParameters": {
    "clusters": [
      "integrates-cluster"
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "60.219.252.71",
  "userAgent": "aws-cli/1.18.40 Python/3.7.6 Linux/5.8.0-kali1-amd64 botocore/1.15.40",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeContainerInstances

#
Service
ecs

Description

Describes one or more container instances.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ClusterNotFoundException",
  "errorMessage": "Cluster not found.",
  "eventCategory": "Management",
  "eventID": "33e690f7-a050-49bc-a9f6-76d31165def8",
  "eventName": "DescribeContainerInstances",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T18:43:21Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "86250ce2-d1c1-4466-b52f-8cf1d238054b",
  "requestParameters": {
    "containerInstances": [
      "dw-probe"
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeDaemon

#
Service
ecs

Description

Describes the specified daemon.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "Invalid daemon ARN: The Daemon ARN is invalid.",
  "eventCategory": "Management",
  "eventID": "3b87c0b4-4924-4e4e-b764-ac70bce7ea90",
  "eventName": "DescribeDaemon",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T18:43:22Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "22b155cd-9bbe-4822-ad23-c7c8b9cc9622",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeDaemonDeployments

#
Service
ecs

Description

Describes one or more of your daemon deployments.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "The Daemon ARN is invalid",
  "eventCategory": "Management",
  "eventID": "71c53b91-1cc2-4e88-be0f-a4ba21fc1002",
  "eventName": "DescribeDaemonDeployments",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T18:43:22Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "64f30994-477a-40c1-a1cd-20abaf5f6215",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeDaemonRevisions

#
Service
ecs

Description

Describes one or more of your daemon revisions.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "The Daemon ARN is invalid",
  "eventCategory": "Management",
  "eventID": "bfdfa8ae-38dd-4d66-901d-ec72f1ee0494",
  "eventName": "DescribeDaemonRevisions",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T18:43:22Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "75791c54-e6e3-43d0-9f88-9dc5bb65bf9b",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeDaemonTaskDefinition

#
Service
ecs

Description

Describes a daemon task definition.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "arn:aws:ecs:us-west-1:123456789012:daemon-task-definition/dw-probe:* is an invalid identifier.",
  "eventCategory": "Management",
  "eventID": "1eb94f2c-6e1b-4790-b0bb-bc2d943ade80",
  "eventName": "DescribeDaemonTaskDefinition",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T18:43:22Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "d2382030-b681-41e7-ac1c-5d37393347b4",
  "requestParameters": {
    "daemonTaskDefinition": "dw-probe",
    "dryrun": false
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeExpressGatewayService

#
Service
ecs

Description

Retrieves detailed information about an Express service, including current status, configuration, managed infrastructure, and service revisions.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "ServiceArn is not valid: ARNs must start with 'arn:': dw-probe",
  "eventCategory": "Management",
  "eventID": "7d2e627e-bdc9-4bf3-98ac-3abe89c5bf7c",
  "eventName": "DescribeExpressGatewayService",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T18:43:22Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "86b60993-ba76-4590-a9ff-7e565877944a",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeServiceDeployments

#
Service
ecs

Description

Describes one or more of your service deployments.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "The Service ARN provided is invalid.",
  "eventCategory": "Management",
  "eventID": "d42eb6b3-518c-47c4-b646-7b165b803ddf",
  "eventName": "DescribeServiceDeployments",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T18:43:22Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "3a1deced-6b95-4c11-bc62-2656d108f0bf",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeServiceRevisions

#
Service
ecs

Description

Describes one or more service revisions.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "The Service ARN provided is invalid.",
  "eventCategory": "Management",
  "eventID": "a01afe75-fa54-4fa9-aca0-2cfa3646d581",
  "eventName": "DescribeServiceRevisions",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T18:43:23Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "5df83229-19a1-4f9f-a0af-e7e783137391",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeServices

#
Service
ecs

Description

Describes the specified services running in your cluster.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ClusterNotFoundException",
  "errorMessage": "Cluster not found.",
  "eventCategory": "Management",
  "eventID": "4b683b02-dafc-4f06-b3b9-21bc4b3b4181",
  "eventName": "DescribeServices",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T18:43:23Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "d4106f2a-b79b-4f9f-98e0-4ebb9326d58c",
  "requestParameters": {
    "services": [
      "dw-probe"
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeTasks

#
Service
ecs

Description

Describes a specified task or tasks.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ClusterNotFoundException",
  "errorMessage": "Cluster not found.",
  "eventCategory": "Management",
  "eventID": "6c170979-c1cb-46eb-a9f5-b973b9ae684e",
  "eventName": "DescribeTasks",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T18:43:23Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "fd8da77f-62a4-43ed-a288-4e5e1bd6fc01",
  "requestParameters": {
    "tasks": [
      "dw-probe"
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeTaskSets

#
Service
ecs

Description

Describes the task sets in the specified cluster and service.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "TaskSets cannot be empty.",
  "eventCategory": "Management",
  "eventID": "e6e1b512-54ea-4301-b394-3ae7e986f355",
  "eventName": "DescribeTaskSets",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T18:43:23Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "154f6534-2e7b-4e97-bc50-083579abb654",
  "requestParameters": {
    "cluster": "dw-probe",
    "dryrun": false,
    "service": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DiscoverPollEndpoint

#
Service
ecs

Description

This action is only used by the Amazon ECS agent, and it is not intended for use outside of the agent.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/Level6 is not authorized to perform: ecs:DiscoverPollEndpoint on resource: *",
  "eventID": "ce7f634f-8022-465d-8f9b-858c8b4b9dd0",
  "eventName": "DiscoverPollEndpoint",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2019-07-01T18:07:09Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "e59a7af1-aa90-4007-8d19-b3ffcd32d6f9",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "0.52.31.206",
  "userAgent": "Boto3/1.9.86 Python/3.7.3 Linux/5.1.0-parrot1-3t-amd64 Botocore/1.12.170",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

ExecuteCommand

#
Service
ecs

Description

Runs a command remotely on a container within a task.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "4719a671-746a-41cf-9103-3186f92ae8e1",
  "eventSource": "ecs.amazonaws.com",
  "eventName": "ExecuteCommand",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "6373ab4e-25be-4bec-b7ec-8a3c57aa759f",
  "userAgent": "aws-cli/2.36.9 md/awscrt#0.36.0 ua/2.1 os/macos#25.5.0 md/arch#arm64 lang/python#3.14.6 md/pyimpl#CPython m/r,Z,s,b,E cfg/retry-mode#standard md/installer#source sid/e8a8b2780908 md/prompt#off md/command#ecs.execute-command",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-east-1.amazonaws.com"
  }
}

GetTaskProtection

#
Service
ecs

Description

Retrieves the protection status of tasks in an Amazon ECS service.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "Tasks cannot be empty.",
  "eventCategory": "Management",
  "eventID": "cce27ba5-9b52-4e81-80f8-ec018c78de02",
  "eventName": "GetTaskProtection",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T18:43:23Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "03e88781-b8ca-4778-b85e-2875643470c1",
  "requestParameters": {
    "cluster": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListAccountSettings

#
Service
ecs

Description

Lists the account settings for a specified principal.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "eventID": "87b514926-22a2-4871-a9f2-d79b335fda25",
  "eventName": "ListAccountSettings",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2019-04-19T16:48:40Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "fc1a9a83-62c2-11e9-b5d0-562119b9fb2a3",
  "requestParameters": {
    "effectiveSettings": false,
    "maxResults": 0
  },
  "responseElements": {
    "settings": []
  },
  "sourceIPAddress": "231.255.215.126",
  "userAgent": "aws-cli/1.16.130 Python/2.7.15rc1 Linux/4.15.0-47-generic botocore/1.12.120",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

ListAttributes

#
Service
ecs

Description

Lists the attributes for Amazon ECS resources within a specified target type and cluster.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:sts::811596193553:assumed-role/flaws/i-aa2d3b42e5c6e801a is not authorized to perform: ecs:ListAttributes on resource: arn:aws:ecs:us-east-1:811596193553:cluster/default",
  "eventID": "60fc5914-d939-4345-afe8-227442e27b418",
  "eventName": "ListAttributes",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2020-06-11T22:12:09Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "c619856ca-0322-423a-92f0-b41031",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "251.105.254.1",
  "userAgent": "aws-cli/1.18.69 Python/3.8.3 Linux/5.4.0-2-amd64 botocore/1.16.26",
  "userIdentity": {
    "accessKeyId": "ASIAZIBB65UBUK3VOAC5",
    "accountId": "811596193553",
    "arn": "arn:aws:sts::811596193553:assumed-role/flaws/i-aa2d3b42e5c6e801a",
    "principalId": "AROACW5CSA8C8WHOB3O7Q:i-aa2d3b42e5c6e801a",
    "sessionContext": {
      "attributes": {
        "creationDate": "2020-06-11T20:53:09Z",
        "mfaAuthenticated": "false"
      },
      "ec2RoleDelivery": "1.0",
      "sessionIssuer": {
        "accountId": "811596193553",
        "arn": "arn:aws:iam::811596193553:role/flaws",
        "principalId": "AROACW5CSA8C8WHOB3O7Q",
        "type": "Role",
        "userName": "flaws"
      },
      "webIdFederationData": {}
    },
    "type": "AssumedRole"
  }
}

References #

ListClusters

#
Service
ecs

Description

Returns a list of existing clusters.

Example CloudTrail Event #

{
  "awsRegion": "us-east-2",
  "eventCategory": "Management",
  "eventID": "bc44e1ec-ca0e-4733-8d9d-82aac08e9cbd",
  "eventName": "ListClusters",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2021-07-07T18:45:02Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "797507667711",
  "requestID": "bdd0c007-f639-4f15-a480-35e1e08941f3",
  "requestParameters": {
    "maxResults": 100
  },
  "responseElements": null,
  "sourceIPAddress": "213.205.197.211",
  "userAgent": "console.amazonaws.com",
  "userIdentity": {
    "accessKeyId": "ASIA3TLZJI37ZMAX6DUQ",
    "accountId": "797507667711",
    "arn": "arn:aws:iam::797507667711:user/bruce",
    "principalId": "AIDA3TLZJI372XH6M2Q25",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-07-07T11:45:11Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bruce"
  }
}

References #

ListContainerInstances

#
Service
ecs

Description

Returns a list of container instances in a specified cluster.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "InternalFailure",
  "errorMessage": "An unknown error occurred",
  "eventID": "49a9dfa0-9a4a-41c9-8dbd-e87007350f0e",
  "eventName": "ListContainerInstances",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2018-10-17T20:15:30Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.04",
  "recipientAccountId": "811596193553",
  "requestID": "420249b57-d249-11e8-957c-f80a39444a44",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "9.245.1.85",
  "userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

ListDaemonDeployments

#
Service
ecs

Description

Returns a list of daemon deployments for a specified daemon.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "The Daemon ARN is invalid",
  "eventCategory": "Management",
  "eventID": "08a2ca07-87b6-4928-b38f-eeb31aea3721",
  "eventName": "ListDaemonDeployments",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T18:43:23Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "c02c7605-05ff-4803-813b-37de6f0641ac",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListDaemons

#
Service
ecs

Description

Returns a list of daemons.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "58230dd3-cc46-4deb-b874-36fbdb490cea",
  "eventName": "ListDaemons",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T18:31:55Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "56a08f09-750e-4b27-a0bf-948cb2cd1b60",
  "requestParameters": {
    "dryrun": false
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListDaemonTaskDefinitions

#
Service
ecs

Description

Returns a list of daemon task definitions that are registered to your account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "0f6f3230-8a2a-4da1-88eb-af5f12e48ef2",
  "eventName": "ListDaemonTaskDefinitions",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T18:31:55Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "e6b5e809-d35d-4a9c-b6ef-2dcf28eb8dbf",
  "requestParameters": {
    "dryrun": false,
    "status": "ACTIVE"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListServiceDeployments

#
Service
ecs

Description

This operation lists all the service deployments that meet the specified filter criteria.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ClusterNotFoundException",
  "errorMessage": "Cluster not found.",
  "eventCategory": "Management",
  "eventID": "1dcd1739-3297-4ca3-bcbb-e6721c1d9fc1",
  "eventName": "ListServiceDeployments",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T18:43:24Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "1adf2772-9ffc-4195-9b03-b86ddfac6773",
  "requestParameters": {
    "service": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListServices

#
Service
ecs

Description

Returns a list of services.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "ClientException",
  "errorMessage": "Cluster not found.",
  "eventID": "46b1e314-ec1c-40fa-864a-6758b10a425f",
  "eventName": "ListServices",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2019-08-29T05:01:17Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "aca10a93-18ff-40b6-abeb-cc3369e403b1",
  "requestParameters": {
    "cluster": "level3"
  },
  "responseElements": null,
  "sourceIPAddress": "90.7.123.193",
  "userAgent": "aws-cli/1.16.152 Python/2.7.15 Darwin/18.5.0 botocore/1.12.142",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

ListServicesByNamespace

#
Service
ecs

Description

This operation lists all of the services that are associated with a Cloud Map namespace.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "AccessDenied",
  "errorMessage": "Invalid Request",
  "eventCategory": "Management",
  "eventID": "2f3490d1-d432-4167-9a0a-9ea87b52107a",
  "eventName": "ListServicesByNamespace",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T18:43:24Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "2f72c5ce-f5bb-451c-99f3-f09e8e99bfcb",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListTagsForResource

#
Service
ecs

Description

List the tags for an Amazon ECS resource.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "The ARN provided is invalid.",
  "eventCategory": "Management",
  "eventID": "67411ea0-f919-480e-a69b-cc479cae90c9",
  "eventName": "ListTagsForResource",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T18:43:24Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "8f4a2bfc-97ff-442d-b511-1dcb6636867c",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListTaskDefinitionFamilies

#
Service
ecs

Description

Returns a list of task definition families that are registered to your account.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "524186-31a3-4e8b-b1c7-fab22bc0b69d",
  "eventName": "ListTaskDefinitionFamilies",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2018-10-17T20:15:31Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.04",
  "recipientAccountId": "811596193553",
  "requestID": "65edf85d-d249-11e8-8391-1574daafb174",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "9.245.1.85",
  "userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

ListTaskDefinitions

#
Service
ecs

Description

Returns a list of task definitions that are registered to your account.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "50a7298b-488d-4f70-b05c-75c73f58f595",
  "eventName": "ListTaskDefinitions",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2018-10-17T20:15:32Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.04",
  "recipientAccountId": "811596193553",
  "requestID": "68879e-d249-11e8-8391-1574daafb174",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "9.245.1.85",
  "userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

ListTasks

#
Service
ecs

Description

Returns a list of tasks.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "eventCategory": "Management",
  "eventID": "e6c7bcf0-8f2c-4099-a12f-823d52573d21",
  "eventName": "ListTasks",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2021-04-13T13:31:55Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "760111141337",
  "requestID": "cd8bf989-f3f2-44b6-8ddf-7151a7f6ae3f",
  "requestParameters": {
    "cluster": "arn:aws:ecs:us-west-2:760111141337:cluster/default"
  },
  "responseElements": null,
  "sourceIPAddress": "95.9.125.40",
  "userAgent": "Boto3/1.14.6 Python/3.9.4 Darwin/20.3.0 Botocore/1.17.6",
  "userIdentity": {
    "accessKeyId": "AKIAYTOGP2RLIXX7QSZR",
    "accountId": "760111141337",
    "arn": "arn:aws:iam::760111141337:user/cloudmapper",
    "principalId": "AIDAYTOGP2RLK32EB7QZV",
    "type": "IAMUser",
    "userName": "cloudmapper"
  }
}

References #

PutAccountSetting

#
Service
ecs

Description

Modifies an account setting.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "Invalid setting 'value'",
  "eventCategory": "Management",
  "eventID": "e5dd9bb0-2981-4056-bae7-b5e0197a7e78",
  "eventName": "PutAccountSetting",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T21:00:52Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7158af48-f0a9-42df-b424-db571362f3f2",
  "requestParameters": {
    "name": "tagResourceAuthorization",
    "value": "enabled"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,D,n cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

PutAccountSettingDefault

#
Service
ecs

Description

Modifies an account setting for all users on an account for whom no individual account setting has been specified.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "Invalid setting 'value'",
  "eventCategory": "Management",
  "eventID": "a8bdd9fd-7c55-4aa1-a93c-7626929d9e39",
  "eventName": "PutAccountSettingDefault",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T21:00:52Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "39243815-463a-48d3-b90d-34888d2b991f",
  "requestParameters": {
    "name": "tagResourceAuthorization",
    "value": "enabled"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,b,D,n cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

PutAttributes

#
Service
ecs

Description

Create or update an attribute on an Amazon ECS resource.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "e6f2afc3-810c-48ae-afa7-0234497c60ea",
  "eventSource": "ecs.amazonaws.com",
  "eventName": "PutAttributes",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "b7539f2b-2827-46d9-997d-47def540bc5c",
  "userAgent": "aws-sdk-java/2.46.11 md/io#sync md/http#Apache5 ua/2.1 api/ECS#2.46.x os/Linux#6.1.176-223.369.amzn2023.x86_64 lang/java#25.0.3 md/OpenJDK_64-Bit_Server_VM#25.0.3+9-LTS md/vendor#Azul_Systems__Inc. md/en_US md/kotlin/1.9.25-release-852 m/D,AJ,h,k",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-east-1.amazonaws.com"
  }
}

PutClusterCapacityProviders

#
Service
ecs

Description

Modifies the available capacity providers and the default capacity provider strategy for a cluster.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "Unable to assume the service linked role. Please verify that the ECS service linked role exists.",
  "eventCategory": "Management",
  "eventID": "60105d0d-2459-4887-9462-7efaeae10f37",
  "eventName": "PutClusterCapacityProviders",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T20:07:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "8703165b-3288-4d0a-88eb-1fc09d0e128f",
  "requestParameters": {
    "capacityProviders": [],
    "cluster": "dwfix-cluster",
    "defaultCapacityProviderStrategy": [],
    "dryrun": false
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

RegisterContainerInstance

#
Service
ecs

Description

This action is only used by the Amazon ECS agent, and it is not intended for use outside of the agent.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "4f6b713b-778b-412a-9a55-8cbfd1677a1b",
  "eventSource": "ecs.amazonaws.com",
  "eventName": "RegisterContainerInstance",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "5ccdc635-5ced-44bd-aafc-c1415a3c8853",
  "userAgent": "Amazon ECS Agent - v1.34.0 (ca7e020f) (windows) (+http://aws.amazon.com/ecs/)",
  "errorCode": "AccessDenied",
  "tlsDetails": {
    "tlsVersion": "TLSv1.2",
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ecs.us-east-1.amazonaws.com"
  }
}

RegisterDaemonTaskDefinition

#
Service
ecs

Description

Registers a new daemon task definition from the supplied family and containerDefinitions.

StartTask

#
Service
ecs

Description

Starts a new task from the specified task definition on the specified container instance or instances.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "91dcb6e1-4697-48fe-bd7c-71ea782f5ed5",
  "eventSource": "ecs.amazonaws.com",
  "eventName": "StartTask",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "33a1cd16-b713-4ba3-9313-d88f8375e75c",
  "userAgent": "aws-sdk-java/2.46.11 md/io#sync md/http#Apache5 ua/2.1 api/ECS#2.46.x os/Linux#6.1.176-223.369.amzn2023.x86_64 lang/java#25.0.3 md/OpenJDK_64-Bit_Server_VM#25.0.3+9-LTS md/vendor#Azul_Systems__Inc. md/en_US md/kotlin/1.9.25-release-852 m/D,AJ,h,k",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-east-1.amazonaws.com"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS Potential Cryptomining via ECS Task Definition Deployment source high: Identifies a principal that, within a short window, both registers an Amazon ECS task definition using a public / non-ECR container image at a high CPU allocation (8 or 16 vCPU) AND launches ECS workloads (RunTask, StartTask, or CreateService). Registering a public miner image at maximum compute and then launching it is the ECS/Fargate cryptocurrency-mining deployment pattern seen after credential compromise. Requiring both the mining-signature registration and a launch by the same principal confirms an actual deployment rather than a standalone (possibly benign) task-definition registration, which sharply reduces false positives from high-compute workloads that are merely registered.T1496↳ also matches RegisterTaskDefinition, RunTask, CreateService

StopServiceDeployment

#
Service
ecs

Description

Stops an ongoing service deployment.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "The ServiceDeployment ARN is invalid.",
  "eventCategory": "Management",
  "eventID": "246f7238-8018-473d-9a6d-30573a3f96e3",
  "eventName": "StopServiceDeployment",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T19:23:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "e044d85c-9f24-43d8-9f5e-2fdfa322e313",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

StopTask

#
Service
ecs

Description

Stops a running task.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ClusterNotFoundException",
  "errorMessage": "Cluster not found.",
  "eventCategory": "Management",
  "eventID": "f1f95d54-2da1-48fe-b13b-d87f593dddb3",
  "eventName": "StopTask",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T19:23:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "ee3cd25f-4191-4e27-863c-e5a690b0be8d",
  "requestParameters": {
    "task": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

SubmitAttachmentStateChanges

#
Service
ecs

Description

This action is only used by the Amazon ECS agent, and it is not intended for use outside of the agent.

SubmitContainerStateChange

#
Service
ecs

Description

This action is only used by the Amazon ECS agent, and it is not intended for use outside of the agent.

SubmitTaskStateChange

#
Service
ecs

Description

This action is only used by the Amazon ECS agent, and it is not intended for use outside of the agent.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "c4a81364-9c5e-4249-a1d6-c4fb4c0a204d",
  "eventSource": "ecs.amazonaws.com",
  "eventName": "SubmitTaskStateChange",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "0d1fdc3d-8e16-44c1-8a16-3f817918fec1",
  "userAgent": "Amazon ECS Agent - v1.105.1 (8dfceca6) (windows; WINDOWS_SERVER_2025_CORE) (+http://aws.amazon.com/ecs/)",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-east-1.amazonaws.com"
  }
}

TagResource

#
Service
ecs

Description

Associates the specified tags to a resource with the specified resourceArn.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "fbeeebe5-4ec6-48e4-be68-8044d99b0a5b",
  "eventName": "TagResource",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T20:07:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7bf62895-7dde-45c3-aca6-c1f89dc12ab4",
  "requestParameters": {
    "resourceArn": "arn:aws:ecs:us-west-1:123456789012:cluster/dwfix-cluster",
    "tags": [
      {
        "key": "dw",
        "value": "f"
      }
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UntagResource

#
Service
ecs

Description

Deletes specified tags from a resource.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "The ARN provided is invalid.",
  "eventCategory": "Management",
  "eventID": "77afc919-194d-4567-a04e-ae88154355c2",
  "eventName": "UntagResource",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T19:23:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "b10d7b58-5191-4b4f-8346-67a469d711ee",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateCapacityProvider

#
Service
ecs

Description

Modifies the parameters for a capacity provider.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "One of autoScalingGroupProvider or managedInstancesProvider must be specified.",
  "eventCategory": "Management",
  "eventID": "b0914053-ca95-4ffd-82ca-0d5e0febfd2e",
  "eventName": "UpdateCapacityProvider",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T19:23:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "45334fef-4177-4b51-b948-1a648e2a619e",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateCluster

#
Service
ecs

Description

Updates the cluster.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ClusterNotFoundException",
  "errorMessage": "Cluster not found.",
  "eventCategory": "Management",
  "eventID": "7677cbf2-54dd-45fa-85ed-2441b4eecd95",
  "eventName": "UpdateCluster",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T19:23:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "5e0e13b6-c4c1-46e0-ace5-27bc1d09ec65",
  "requestParameters": {
    "cluster": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateClusterSettings

#
Service
ecs

Description

Modifies the settings to use for a cluster.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ClusterNotFoundException",
  "errorMessage": "Cluster not found.",
  "eventCategory": "Management",
  "eventID": "051893f9-6fcc-4759-9f7b-f46a83a402c0",
  "eventName": "UpdateClusterSettings",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T19:23:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "1cee5e1e-5409-4036-9d7c-82f9dca0f752",
  "requestParameters": {
    "cluster": "dw-probe",
    "settings": [
      {}
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateContainerAgent

#
Service
ecs

Description

Updates the Amazon ECS container agent on a specified container instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "ContainerInstanceId must match ^[a-f0-9-]{1,36}$",
  "eventCategory": "Management",
  "eventID": "badd2cfd-c6c2-423f-80a9-10e51ad3ef21",
  "eventName": "UpdateContainerAgent",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T19:23:14Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "30223df6-c429-41ec-9f92-ca538dfdb68d",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateContainerInstancesState

#
Service
ecs

Description

Modifies the status of an Amazon ECS container instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ClusterNotFoundException",
  "errorMessage": "Cluster not found.",
  "eventCategory": "Management",
  "eventID": "d613c559-1441-4788-a60d-cb9f2dfdc79c",
  "eventName": "UpdateContainerInstancesState",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T19:23:14Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "843eef47-f963-44cf-83cb-7fc4fcddd273",
  "requestParameters": {
    "containerInstances": [
      "dw-probe"
    ],
    "status": "ACTIVE"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateDaemon

#
Service
ecs

Description

Updates the specified daemon.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "Invalid daemon ARN: The Daemon ARN is invalid.",
  "eventCategory": "Management",
  "eventID": "ac3a0772-4e3f-4ba7-a213-69d7eecfc1c6",
  "eventName": "UpdateDaemon",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T19:23:14Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "ff9155c7-8bda-4d39-b6b9-6b9f72a08565",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateExpressGatewayService

#
Service
ecs

Description

Updates an existing Express service configuration.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "The Service ARN provided is invalid.",
  "eventCategory": "Management",
  "eventID": "3f958c0e-b59a-4721-bc4e-3c226c57acc3",
  "eventName": "UpdateExpressGatewayService",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T19:23:14Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "84498646-2fec-405b-a8cb-babec62ab62c",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateService

#
Service
ecs

Description

Modifies the parameters of a service.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ClusterNotFoundException",
  "errorMessage": "Cluster not found.",
  "eventCategory": "Management",
  "eventID": "abec09c4-9537-4301-a001-1fc2fe7a8879",
  "eventName": "UpdateService",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T19:23:14Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "ec3cfb78-5c32-401b-b4d0-d214105abf4a",
  "requestParameters": {
    "dryrun": false,
    "forceNewDeployment": false,
    "service": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateServicePrimaryTaskSet

#
Service
ecs

Description

Modifies which task set in a service is the primary task set.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "PrimaryTaskSet must match ^ecs-svc/\\d{19}$, but was dw-probe",
  "eventCategory": "Management",
  "eventID": "0826f4fa-07c0-4ccf-8b4c-1fd313b819f1",
  "eventName": "UpdateServicePrimaryTaskSet",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T19:23:14Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "fa6f8d9d-b4b1-43b2-ab5e-163b0516aca4",
  "requestParameters": {
    "cluster": "dw-probe",
    "primaryTaskSet": "dw-probe",
    "service": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateTaskProtection

#
Service
ecs

Description

Updates the protection status of a task.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ClusterNotFoundException",
  "errorMessage": "Cluster not found.",
  "eventCategory": "Management",
  "eventID": "ceed55c1-0424-46ae-9c1e-202ddb858a11",
  "eventName": "UpdateTaskProtection",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T19:23:15Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "cb1adfe7-ff2a-4eee-8b34-78d4a47bb163",
  "requestParameters": {
    "cluster": "dw-probe",
    "protectionEnabled": false,
    "tasks": [
      "dw-probe"
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateTaskSet

#
Service
ecs

Description

Modifies a task set.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "TaskSet must match ^ecs-svc/\\d{19}$, but was dw-probe",
  "eventCategory": "Management",
  "eventID": "ee45f349-c355-43b9-8db6-bc1955be76cc",
  "eventName": "UpdateTaskSet",
  "eventSource": "ecs.amazonaws.com",
  "eventTime": "2026-06-29T19:23:15Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "d8e1df86-f06c-4fc6-ae18-c564559d56e6",
  "requestParameters": {
    "cluster": "dw-probe",
    "dryrun": false,
    "scale": {
      "value": 0.0
    },
    "service": "dw-probe",
    "taskSet": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ecs.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

TaskCreated

#
Service
ecs

Description

TaskCreated recorded by CloudTrail for Amazon Elastic Container Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "83f0b2a3-1716-40dc-830b-e682109d1fc6",
  "eventSource": "ecs.amazonaws.com",
  "eventName": "TaskCreated",
  "awsRegion": "us-east-1",
  "eventType": "AwsServiceEvent",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "b48dd815-0f71-4559-9c09-69b72a57c36f",
  "userAgent": "ecs.amazonaws.com"
}