GuardDuty
| eventName | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all entry for GuardDuty rules that match the service but not a specific eventName. | N | N |
| Create | Creates a trusted IP set in GuardDuty, which causes GuardDuty to not generate findings for traffic from the listed IP addresses. | Y | Y |
| Delete | Deletes an Amazon GuardDuty detector, disabling threat detection for the account in the current region. | Y | Y |
| Delete | Deletes invitations sent to the current AWS account by specified GuardDuty administrator accounts. | Y | Y |
| Delete | Deletes GuardDuty member accounts, removing them from the administrator account's organization. | Y | Y |
| Delete | Deletes a publishing destination for GuardDuty findings, stopping export of findings to that destination (e.g. S3 or Security Hub). | Y | Y |
| Delete | Deletes a custom threat intelligence set (list of malicious IPs or domains) from a GuardDuty detector. | Y | Y |
| Disassociate | Disassociates the current GuardDuty member account from its administrator account, stopping the administrator from managing GuardDuty for this account. | Y | Y |
| Disassociate | Disassociates GuardDuty member accounts from the current administrator account without deleting them. | Y | Y |
| Stop | Stops GuardDuty from monitoring the specified member accounts, suspending threat detection for those accounts under the current administrator. | Y | Y |
| Update | Updates an Amazon GuardDuty detector's configuration, such as enabling or disabling data sources or changing the finding publishing frequency. | Y | Y |
| Update | Updates the name, location, or activation status of a custom threat intelligence set in a GuardDuty detector. | Y | Y |
| Accept | Accepts the invitation to be a member account and get monitored by a GuardDuty administrator account that sent the invitation. | N | N |
| Accept | Accepts the invitation to be monitored by a GuardDuty administrator account. | N | N |
| Archive | Archives GuardDuty findings that are specified by the list of finding IDs. | Y | Y |
| Create | Creates a single GuardDuty detector. | Y | N |
| Create | Creates a filter using the specified finding criteria. | Y | N |
| Create | This API is currently available as a preview. | Y | N |
| Create | Creates a new Malware Protection plan for the protected resource. | Y | N |
| Create | Creates member accounts of the current Amazon Web Services account by specifying a list of Amazon Web Services account IDs. | N | N |
| Create | Creates a publishing destination where you can export your GuardDuty findings. | N | N |
| Create | Generates sample findings of types specified by the list of finding types. | Y | N |
| Create | Creates a new threat entity set. | Y | N |
| Create | Creates a new ThreatIntelSet. | Y | Y |
| Create | Creates a new trusted entity set. | Y | N |
| Decline | Declines invitations sent to the current member account by Amazon Web Services accounts specified by their account IDs. | N | N |
| Delete | Deletes the filter specified by the filter name. | Y | N |
| Delete | Deletes the IPSet specified by the ipSetId. | Y | Y |
| Delete | Deletes the Malware Protection plan ID associated with the Malware Protection plan resource. | Y | N |
| Delete | Deletes the threat entity set that is associated with the specified threatEntitySetId. | Y | N |
| Delete | Deletes the trusted entity set that is associated with the specified trustedEntitySetId. | Y | N |
| Describe | Returns a list of malware scans. | Y | N |
| Describe | Returns information about the account selected as the delegated administrator for GuardDuty. | Y | N |
| Describe | Returns information about the publishing destination specified by the provided destinationId. | Y | N |
| Disable | Removes the existing GuardDuty delegated administrator of the organization. | Y | N |
| Disassociate | Disassociates the current GuardDuty member account from its administrator account. | Y | N |
| Enable | Designates an Amazon Web Services account within the organization as your GuardDuty delegated administrator. | N | N |
| Get | Provides the details of the GuardDuty administrator account associated with the current GuardDuty member account. | Y | N |
| Get | Retrieves aggregated statistics for your account. | Y | N |
| Get | Retrieves a GuardDuty detector specified by the detectorId. | Y | N |
| Get | Returns the details of the filter specified by the filter name. | Y | N |
| Get | Describes Amazon GuardDuty findings specified by finding IDs. | Y | N |
| Get | Lists GuardDuty findings statistics for the specified detector ID. | Y | N |
| Get | This API is currently available as a preview. | Y | N |
| Get | Returns the count of all GuardDuty membership invitations that were sent to the current member account except the currently accepted invitation. | Y | N |
| Get | Retrieves the IPSet specified by the ipSetId. | Y | N |
| Get | Retrieves the Malware Protection plan details associated with a Malware Protection plan ID. | Y | N |
| Get | Retrieves the detailed information for a specific malware scan. | Y | N |
| Get | Returns the details of the malware scan settings. | Y | N |
| Get | Provides the details for the GuardDuty administrator account associated with the current GuardDuty member account. | Y | N |
| Get | Describes which data sources are enabled for the member account's detector. | Y | N |
| Get | Retrieves GuardDuty member accounts (of the current GuardDuty administrator account) specified by the account IDs. | Y | N |
| Get | Retrieves how many active member accounts have each feature enabled within GuardDuty. | Y | N |
| Get | Provides the number of days left for each data source used in the free trial period. | Y | N |
| Get | Retrieves the threat entity set associated with the specified threatEntitySetId. | Y | N |
| Get | Retrieves the ThreatIntelSet that is specified by the ThreatIntelSet ID. | Y | N |
| Get | Retrieves the trusted entity set associated with the specified trustedEntitySetId. | Y | N |
| Get | Lists Amazon GuardDuty usage statistics over the last 30 days for the specified detector ID. | Y | N |
| Invite | Invites Amazon Web Services accounts to become members of an organization administered by the Amazon Web Services account that invokes this API. | N | N |
| List | Lists coverage details for your GuardDuty account. | Y | N |
| List | Lists detectorIds of all the existing Amazon GuardDuty detector resources. | Y | N |
| List | Returns a paginated list of the current filters. | Y | N |
| List | Lists GuardDuty findings for the specified detector ID. | Y | N |
| List | This API is currently available as a preview. | Y | N |
| List | Lists all GuardDuty membership invitations that were sent to the current Amazon Web Services account. | Y | N |
| List | Lists the IPSets of the GuardDuty service specified by the detector ID. | Y | N |
| List | Lists the Malware Protection plan IDs associated with the protected resources in your Amazon Web Services account. | Y | N |
| List | Returns a list of malware scans. | Y | N |
| List | Lists details about all member accounts for the current GuardDuty administrator account. | Y | N |
| List | Lists the accounts designated as GuardDuty delegated administrators. | Y | N |
| List | Returns a list of publishing destinations associated with the specified detectorId. | Y | N |
| List | Lists tags for a resource. | Y | N |
| List | Lists the threat entity sets associated with the specified GuardDuty detector ID. | Y | N |
| List | Lists the ThreatIntelSets of the GuardDuty service specified by the detector ID. | Y | N |
| List | Lists the trusted entity sets associated with the specified GuardDuty detector ID. | Y | N |
| Send | Initiates a malware scan for a specific S3 object. | N | N |
| Start | Initiates the malware scan. | N | N |
| Start | Turns on GuardDuty monitoring of the specified member accounts. | N | N |
| Tag | Adds tags to a resource. | Y | N |
| Unarchive | Unarchives GuardDuty findings specified by the findingIds. | Y | N |
| Untag | Removes tags from a resource. | Y | N |
| Update | Updates the filter specified by the filter name. | Y | N |
| Update | Marks the specified GuardDuty findings as useful or not useful. | Y | N |
| Update | Updates the IPSet specified by the IPSet ID. | Y | Y |
| Update | Updates an existing Malware Protection plan resource. | Y | N |
| Update | Updates the malware scan settings. | Y | N |
| Update | Contains information on member accounts to be updated. | Y | N |
| Update | Configures the delegated administrator account with the provided values. | Y | N |
| Update | Updates information about the publishing destination specified by the destinationId. | Y | N |
| Update | Updates the threat entity set associated with the specified threatEntitySetId. | Y | N |
| Update | Updates the trusted entity set associated with the specified trustedEntitySetId. | Y | N |
any: GuardDuty (catch-all)
#Description
Catch-all entry for GuardDuty rules that match the service but not a specific eventName.
CreateIPSet
#Description
Creates a trusted IP set in GuardDuty, which causes GuardDuty to not generate findings for traffic from the listed IP addresses.
CloudTrail management event, logged by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "35007bd7-546e-49b4-8588-e72c6e94393a",
"eventName": "CreateIPSet",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T21:47:07Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "a14ae013-ed7e-4e7b-ac2a-c09c3e67923a",
"requestParameters": {
"activate": false,
"clientToken": "a00286a6-81bc-4406-85f0-35671ace2f6b",
"detectorId": "b4cf8aacc70423c0f45074ed90dd6596",
"format": "TXT",
"location": "s3://dwfix-gd-93708318-20260629214658/ipset.txt",
"name": "dwfix-ipset-20260629214658"
},
"responseElements": {
"ipSetId": "cecf8aacd8c8c2d5818839de35d5dd7a"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,n,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Sigma #
T1685Elastic #
T1562, T1562.001↳ also matches UpdateDetector, UpdateThreatIntelSet, CreateThreatIntelSet, UpdateIPSet Panther #
T1562↳ also matches UpdateIPSet
DeleteDetector
#Description
Deletes an Amazon GuardDuty detector, disabling threat detection for the account in the current region.
CloudTrail management event, logged by default. Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "c1367a2f-8910-4e64-9256-a854d2e9f37d",
"eventName": "DeleteDetector",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2022-07-21T20:27:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "111111111111",
"requestID": "1e832076-d7a8-432b-b0df-54ba62f6b62c",
"requestParameters": {
"detectorId": "123"
},
"responseElements": {
"__type": "InvalidInputException",
"message": "The request is rejected because the parameter detectorId has an invalid value."
},
"sourceIPAddress": "67.171.71.185",
"userAgent": "aws-cli/2.7.3 Python/3.9.13 Darwin/21.5.0 source/x86_64 prompt/off command/guardduty.delete-detector",
"userIdentity": {
"accessKeyId": "AKIAYTOGP2RLFLKADUVG",
"accountId": "111111111111",
"arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli",
"principalId": "AIDAYTOGP2RLI4PXTGCEU",
"type": "IAMUser",
"userName": "gowthamaraj_cli"
}
}
Common Indicators #
Field Kind Value Rules Vendors aws::errorCode (sigma rule field)eq success1 rule sigma Detection Rules #
Sigma #
T1685, T1685.002↳ also matches UpdateDetector Elastic #
T1562, T1562.001Splunk #
T1685, T1685.002↳ also matches DeleteIPSet References #
DeleteInvitations
#Description
Deletes invitations sent to the current AWS account by specified GuardDuty administrator accounts.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "852553b3-9383-4582-b3f2-f5904e31e5e3",
"eventName": "DeleteInvitations",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T19:24:31Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "924da0f7-984d-409b-879c-1ee7c346a010",
"requestParameters": {
"accountIds": [
"dddddddddddd"
]
},
"responseElements": {
"__type": "InvalidInputException",
"message": "The request failed because parameter accountIds has accountId values that are formatted incorrectly.",
"type": "InvalidInputException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1562, T1562.001↳ also matches DeleteMembers, DisassociateFromAdministratorAccount, DisassociateMembers, StopMonitoringMembers
DeleteMembers
#Description
Deletes GuardDuty member accounts, removing them from the administrator account's organization.
CloudTrail management event, logged by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "64b58c22-3741-463a-bda8-96e86fbcf8f4",
"eventName": "DeleteMembers",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T19:24:31Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7bef027d-2fa6-4fd1-aa31-fb67cb95038d",
"requestParameters": {
"accountIds": [
"dddddddddddd"
],
"detectorId": "ddddd"
},
"responseElements": {
"__type": "InvalidInputException",
"message": "The request is rejected because the parameter detectorId has an invalid value.",
"type": "InvalidInputException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Elastic #
T1562, T1562.001↳ also matches DeleteInvitations, DisassociateFromAdministratorAccount, DisassociateMembers, StopMonitoringMembers
DeletePublishingDestination
#Description
Deletes a publishing destination for GuardDuty findings, stopping export of findings to that destination (e.g. S3 or Security Hub).
CloudTrail management event, logged by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "2bd05e1f-c9c9-469d-bee2-2676aaf493fd",
"eventName": "DeletePublishingDestination",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T19:24:31Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "111ab1a5-9027-4388-a4f0-c2a9a0544550",
"requestParameters": {
"destinationId": "dw-probe",
"detectorId": "ddddd"
},
"responseElements": {
"__type": "InvalidInputException",
"message": "The request is rejected because the parameter detectorId has an invalid value.",
"type": "InvalidInputException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
YARA-L #
T1562
DeleteThreatIntelSet
#Description
Deletes a custom threat intelligence set (list of malicious IPs or domains) from a GuardDuty detector.
CloudTrail management event, logged by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "755a0b7f-58cb-4bc5-97fb-88c038041b56",
"eventName": "DeleteThreatIntelSet",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T19:24:32Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "30066e5f-89dd-40a3-a75f-aefd92c884d2",
"requestParameters": {
"detectorId": "ddddd",
"threatIntelSetId": "dw-probe"
},
"responseElements": {
"__type": "InvalidInputException",
"message": "The request is rejected because the parameter detectorId has an invalid value.",
"type": "InvalidInputException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
YARA-L #
T1562↳ also matches UpdateThreatIntelSet
DisassociateFromAdministratorAccount
#Description
Disassociates the current GuardDuty member account from its administrator account, stopping the administrator from managing GuardDuty for this account.
CloudTrail management event, logged by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "7117ed98-6219-4e5f-9272-10ecbd07bd5f",
"eventName": "DisassociateFromAdministratorAccount",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T19:24:32Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "d3ffcbd3-baee-4b44-b284-e8bfaf69552b",
"requestParameters": {
"detectorId": "ddddd"
},
"responseElements": {
"__type": "InvalidInputException",
"message": "The request is rejected because the parameter detectorId has an invalid value.",
"type": "InvalidInputException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Elastic #
T1562, T1562.001↳ also matches DeleteInvitations, DeleteMembers, DisassociateMembers, StopMonitoringMembers
DisassociateMembers
#Description
Disassociates GuardDuty member accounts from the current administrator account without deleting them.
CloudTrail management event, logged by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "127746f7-9999-4423-a3cf-f250d014e6df",
"eventName": "DisassociateMembers",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T19:24:32Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "4a07a6e7-7939-47cc-a94b-73157c439204",
"requestParameters": {
"accountIds": [
"dddddddddddd"
],
"detectorId": "ddddd"
},
"responseElements": {
"__type": "InvalidInputException",
"message": "The request is rejected because the parameter detectorId has an invalid value.",
"type": "InvalidInputException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Elastic #
T1562, T1562.001↳ also matches DeleteInvitations, DeleteMembers, DisassociateFromAdministratorAccount, StopMonitoringMembers
StopMonitoringMembers
#Description
Stops GuardDuty from monitoring the specified member accounts, suspending threat detection for those accounts under the current administrator.
CloudTrail management event, logged by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "62aa8b6f-84db-4730-ba0a-3df5ff96e82c",
"eventName": "StopMonitoringMembers",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T19:24:32Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "4b9f8311-73a3-4aa3-b3aa-264e522eac7c",
"requestParameters": {
"accountIds": [
"dddddddddddd"
],
"detectorId": "ddddd"
},
"responseElements": {
"__type": "InvalidInputException",
"message": "The request is rejected because the parameter detectorId has an invalid value.",
"type": "InvalidInputException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Elastic #
T1562, T1562.001↳ also matches DeleteInvitations, DeleteMembers, DisassociateFromAdministratorAccount, DisassociateMembers
UpdateDetector
#Description
Updates an Amazon GuardDuty detector's configuration, such as enabling or disabling data sources or changing the finding publishing frequency.
CloudTrail management event, logged by default. Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "b3cc2353-774e-4ef5-87d9-8c1777030c37",
"eventName": "UpdateDetector",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T19:24:32Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7089af84-87b5-442d-b876-a1ec5f7c6ab2",
"requestParameters": {
"detectorId": "ddddd"
},
"responseElements": {
"__type": "InvalidInputException",
"message": "The request is rejected because the parameter detectorId has an invalid value.",
"type": "InvalidInputException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Common Indicators #
Field Kind Value Rules Vendors aws::errorCode (sigma rule field)eq success1 rule sigma Detection Rules #
Sigma #
T1685, T1685.002↳ also matches DeleteDetector Elastic #
T1562, T1562.001↳ also matches CreateIPSet, UpdateThreatIntelSet, CreateThreatIntelSet, UpdateIPSet Kusto #
T1562YARA-L #
T1562Panther #
T1562
UpdateThreatIntelSet
#Description
Updates the name, location, or activation status of a custom threat intelligence set in a GuardDuty detector.
CloudTrail management event, logged by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "609e006d-ccde-4be0-9dc5-944d2904472d",
"eventName": "UpdateThreatIntelSet",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T19:24:32Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "6dad5a5c-f72d-4b6e-83ea-d1722e9dcb03",
"requestParameters": {
"detectorId": "ddddd",
"threatIntelSetId": "dw-probe"
},
"responseElements": {
"__type": "InvalidInputException",
"message": "The request is rejected because the parameter detectorId has an invalid value.",
"type": "InvalidInputException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Elastic #
T1562, T1562.001↳ also matches CreateIPSet, UpdateDetector, CreateThreatIntelSet, UpdateIPSet YARA-L #
T1562↳ also matches DeleteThreatIntelSet
AcceptAdministratorInvitation
#Description
Accepts the invitation to be a member account and get monitored by a GuardDuty administrator account that sent the invitation.
AcceptInvitation
#Description
Accepts the invitation to be monitored by a GuardDuty administrator account.
ArchiveFindings
#Description
Archives GuardDuty findings that are specified by the list of finding IDs.
CloudTrail management event, logged by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "c6d3e6c2-57c5-4cf8-a9a3-929312ca7ef4",
"eventName": "ArchiveFindings",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T21:47:30Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "123d3d39-1627-43d1-af15-81ec0b6f9805",
"requestParameters": {
"detectorId": "b4cf8aacc70423c0f45074ed90dd6596",
"findingIds": [
"6284b9ced79340799b78b237804a8964"
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,n,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Panther #
T1562
CreateDetector
#Description
Creates a single GuardDuty detector.
Example CloudTrail Event #
{
"awsRegion": "us-east-2",
"eventCategory": "Management",
"eventID": "fbba89ea-383b-464d-ae8a-ef1b918b8241",
"eventName": "CreateDetector",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2021-07-07T13:20:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "797507667711",
"requestID": "9c0fc41e-b8d6-4bcd-bd52-4a154845912b",
"requestParameters": {
"clientToken": "e58412d6-1c57-4e84-b993-c00f2d38f70c",
"enable": true
},
"responseElements": {
"detectorId": "68bd40905393a0a5aa40bbec31f1af0a"
},
"sourceIPAddress": "213.205.197.162",
"userAgent": "aws-internal/3 aws-sdk-java/1.11.1030 Linux/5.4.116-64.217.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.292-b10 java/1.8.0_292 vendor/Oracle_Corporation cfg/retry-mode/legacy",
"userIdentity": {
"accessKeyId": "ASIA3TLZJI375VVUVWIG",
"accountId": "797507667711",
"arn": "arn:aws:iam::797507667711:user/bruce",
"principalId": "AIDA3TLZJI372XH6M2Q25",
"sessionContext": {
"attributes": {
"creationDate": "2021-07-07T11:45:11Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bruce"
}
}
References #
CreateFilter
#Description
Creates a filter using the specified finding criteria.
CloudTrail management event, logged by default.Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "03020b9a-eab4-4684-967b-fe430f621d6f",
"eventName": "CreateFilter",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T21:47:19Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "9743ae2a-4a11-4d8b-986d-eef4713e04cb",
"requestParameters": {
"action": "NOOP",
"clientToken": "6ba6b51e-1ce0-4218-9925-a1a462358c79",
"description": "dwfix test filter",
"detectorId": "b4cf8aacc70423c0f45074ed90dd6596",
"findingCriteria": {
"criterion": {
"region": {
"equals": [
"us-west-1"
]
}
}
},
"name": "dwfix-gd-filter-20260629214658",
"rank": 1
},
"responseElements": {
"name": "dwfix-gd-filter-20260629214658"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,n,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateInvestigation
#Description
This API is currently available as a preview.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "03e009a5-2e97-4146-8d7a-dcb81a4708ed",
"eventName": "CreateInvestigation",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T21:47:36Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "58aca665-7fd2-4c2b-9f00-e5300dfc774c",
"requestParameters": {
"clientToken": "14575ca1-1e9d-4c87-ae8f-9061d7369b61",
"detectorId": "b4cf8aacc70423c0f45074ed90dd6596",
"triggerPrompt": "Investigate finding 6284b9ced79340799b78b237804a8964"
},
"responseElements": {
"__type": "InvalidInputException",
"message": "The request is rejected because the Investigation API is not available in region ACCESS_DENIED.",
"type": "InvalidInputException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,n,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateMalwareProtectionPlan
#Description
Creates a new Malware Protection plan for the protected resource.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "05f9e058-cdc8-4d3a-b6df-837c2d5bc6d0",
"eventName": "CreateMalwareProtectionPlan",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T21:48:06Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "86584900-f2e3-405d-b52c-e138ca7746af",
"requestParameters": {
"clientToken": "176d5d60-1d81-44ee-ac8f-9a01cd6df4f5",
"protectedResource": {
"s3Bucket": {
"bucketName": "dwfix-gd-93708318-20260629214658"
}
},
"role": "arn:aws:iam::123456789012:role/dwfix-gd-mprot-20260629214658"
},
"responseElements": {
"__type": "InvalidInputException",
"message": "The request was rejected because the provided IAM role does not have the required S3 bucket notification permissions to verify and enable S3 EventBridge event delivery.",
"type": "InvalidInputException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,n,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateMembers
#Description
Creates member accounts of the current Amazon Web Services account by specifying a list of Amazon Web Services account IDs.
CreatePublishingDestination
#Description
Creates a publishing destination where you can export your GuardDuty findings.
CreateSampleFindings
#Description
Generates sample findings of types specified by the list of finding types.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "645d40b6-dce8-4707-8e0a-fc0863fea7f5",
"eventName": "CreateSampleFindings",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T21:47:20Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "4ed029b4-ff81-4689-b1c0-2ccea1158a0c",
"requestParameters": {
"detectorId": "b4cf8aacc70423c0f45074ed90dd6596",
"findingTypes": [
"Recon:EC2/PortProbeUnprotectedPort"
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,n,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateThreatEntitySet
#Description
Creates a new threat entity set.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "cddc4c86-5abe-4810-a416-ba6f062123b4",
"eventName": "CreateThreatEntitySet",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T21:47:11Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "dcf0d0dd-d3a2-4a92-abbd-20414de4416b",
"requestParameters": {
"activate": false,
"clientToken": "6dedb0bc-4994-44c0-8828-1da221038993",
"detectorId": "b4cf8aacc70423c0f45074ed90dd6596",
"format": "TXT",
"location": "s3://dwfix-gd-93708318-20260629214658/threatentity.txt",
"name": "dwfix-te-20260629214658"
},
"responseElements": {
"threatEntitySetId": "131984d77b8542118632a68229764926"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,n,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateThreatIntelSet
#Description
Creates a new ThreatIntelSet.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "6fcd1753-0126-4d1e-b834-64734be17441",
"eventName": "CreateThreatIntelSet",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T21:47:09Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "2f830e0e-b656-4ebc-8725-87b23bb855f8",
"requestParameters": {
"activate": false,
"clientToken": "1680d744-d14b-42f8-be4e-65fb74fa9c4f",
"detectorId": "b4cf8aacc70423c0f45074ed90dd6596",
"format": "TXT",
"location": "s3://dwfix-gd-93708318-20260629214658/threatintel.txt",
"name": "dwfix-ti-20260629214658"
},
"responseElements": {
"threatIntelSetId": "8ecf8aacdb7eb624459e77b4a95877eb"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,n,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1562, T1562.001↳ also matches CreateIPSet, UpdateDetector, UpdateThreatIntelSet, UpdateIPSet
CreateTrustedEntitySet
#Description
Creates a new trusted entity set.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "c30dfd88-7f0a-460f-836e-5d8b9d05c11d",
"eventName": "CreateTrustedEntitySet",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T21:47:19Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "4598d75f-2ea5-4920-b20a-8c4974cdfc94",
"requestParameters": {
"activate": false,
"clientToken": "4732c686-89e8-429a-80b4-ce463811f06e",
"detectorId": "b4cf8aacc70423c0f45074ed90dd6596",
"format": "TXT",
"location": "s3://dwfix-gd-93708318-20260629214658/trustedentity.txt",
"name": "dwfix-trs-20260629214658"
},
"responseElements": {
"trustedEntitySetId": "f40980f48c504693b29c496f43e5ed01"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,n,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeclineInvitations
#Description
Declines invitations sent to the current member account by Amazon Web Services accounts specified by their account IDs.
DeleteFilter
#Description
Deletes the filter specified by the filter name.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "1fc59d07-b797-4c56-aafb-6b846271ef0a",
"eventName": "DeleteFilter",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T19:24:32Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "b73811e1-f397-4ca7-8b78-c4f687ae6d46",
"requestParameters": {
"detectorId": "ddddd",
"filterName": "dw-probe"
},
"responseElements": {
"__type": "InvalidInputException",
"message": "The request is rejected because the parameter detectorId has an invalid value.",
"type": "InvalidInputException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteIPSet
#Description
Deletes the IPSet specified by the ipSetId.
CloudTrail management event, logged by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "884dc529-d98f-4529-bfa1-8cdd6c06d02f",
"eventName": "DeleteIPSet",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2022-07-26T23:14:57Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "111111111111",
"requestID": "70d36916-4ce7-4b6e-9226-9da47d58d554",
"requestParameters": {
"detectorId": "11111",
"ipSetId": "1111"
},
"responseElements": {
"__type": "InvalidInputException",
"message": "The request is rejected because the parameter detectorId has an invalid value."
},
"sourceIPAddress": "142.254.89.27",
"userAgent": "aws-cli/2.0.62 Python/3.9.2 Darwin/21.5.0 source/x86_64 command/guardduty.delete-ip-set",
"userIdentity": {
"accessKeyId": "AKIAYTOGP2RLKQ3U2PDY",
"accountId": "111111111111",
"arn": "arn:aws:iam::111111111111:user/bhavin_cli",
"principalId": "AIDAYTOGP2RLEHRX5YWNV",
"type": "IAMUser",
"userName": "bhavin_cli"
}
}
Detection Rules #
Splunk #
T1685, T1685.002↳ also matches DeleteDetector References #
DeleteMalwareProtectionPlan
#Description
Deletes the Malware Protection plan ID associated with the Malware Protection plan resource.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "e939ec4a-5e22-4439-9de3-d43ebcb012c7",
"eventName": "DeleteMalwareProtectionPlan",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T19:24:32Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "1d193e6c-84f4-4451-b9d0-b1ed16a50275",
"requestParameters": {
"malwareProtectionPlanId": "dw-probe"
},
"responseElements": {
"__type": "InvalidInputException",
"message": "The request is rejected because an invalid or out-of-range value is specified as an input parameter.",
"type": "InvalidInputException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteThreatEntitySet
#Description
Deletes the threat entity set that is associated with the specified threatEntitySetId.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "d38ee750-736f-4314-8666-58fff25ce2ad",
"eventName": "DeleteThreatEntitySet",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T19:24:33Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "3859fd19-a3ca-47c8-95c3-297ec5c7b47d",
"requestParameters": {
"detectorId": "ddddd",
"threatEntitySetId": "dw-probe"
},
"responseElements": {
"__type": "InvalidInputException",
"message": "The request is rejected because the parameter detectorId has an invalid value.",
"type": "InvalidInputException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteTrustedEntitySet
#Description
Deletes the trusted entity set that is associated with the specified trustedEntitySetId.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "4fd89a1d-486b-4e01-98f2-f1fe92fa1b58",
"eventName": "DeleteTrustedEntitySet",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T19:24:34Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "1972df45-2170-42e6-8acf-97dc537ccf2b",
"requestParameters": {
"detectorId": "ddddd",
"trustedEntitySetId": "dw-probe"
},
"responseElements": {
"__type": "InvalidInputException",
"message": "The request is rejected because the parameter detectorId has an invalid value.",
"type": "InvalidInputException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeMalwareScans
#Description
Returns a list of malware scans.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "e90d7eb8-2ff6-4de4-b606-f279c94d746a",
"eventName": "DescribeMalwareScans",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T18:44:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "27aaf42c-2505-421c-bdab-e1e43705730a",
"requestParameters": {
"detectorId": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeOrganizationConfiguration
#Description
Returns information about the account selected as the delegated administrator for GuardDuty.
Example CloudTrail Event #
{
"awsRegion": "us-east-2",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "657a9a9a-e28e-4361-af54-d195f812257c",
"eventName": "DescribeOrganizationConfiguration",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2021-07-07T13:20:59Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "797507667711",
"requestID": "91cbf893-cd88-4dc8-a6c5-4c510cacc3bb",
"requestParameters": {
"detectorId": "68bd40905393a0a5aa40bbec31f1af0a"
},
"responseElements": null,
"sourceIPAddress": "213.205.197.162",
"userAgent": "aws-internal/3 aws-sdk-java/1.11.1030 Linux/5.4.116-64.217.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.292-b10 java/1.8.0_292 vendor/Oracle_Corporation cfg/retry-mode/legacy",
"userIdentity": {
"accessKeyId": "ASIA3TLZJI375VVUVWIG",
"accountId": "797507667711",
"arn": "arn:aws:iam::797507667711:user/bruce",
"principalId": "AIDA3TLZJI372XH6M2Q25",
"sessionContext": {
"attributes": {
"creationDate": "2021-07-07T11:45:11Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bruce"
}
}
References #
DescribePublishingDestination
#Description
Returns information about the publishing destination specified by the provided destinationId.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "e07e840d-84dc-407e-8b1b-e195af49acbf",
"eventName": "DescribePublishingDestination",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T18:44:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "5641bd1e-3f79-4d6b-a37a-ecd36fc5a440",
"requestParameters": {
"destinationId": "dw-probe",
"detectorId": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisableOrganizationAdminAccount
#Description
Removes the existing GuardDuty delegated administrator of the organization.
CloudTrail management event, logged by default.Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "8aac0f81-2260-474f-a2da-386eca2fafd0",
"eventName": "DisableOrganizationAdminAccount",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T19:24:34Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "c5b7d593-cb6c-4892-ac36-448dabec1dfd",
"requestParameters": {
"adminAccountId": "dw-probe"
},
"responseElements": {
"__type": "InvalidInputException",
"message": "The request failed because the 'accountId' was formatted incorrectly.",
"type": "InvalidInputException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisassociateFromMasterAccount
#Description
Disassociates the current GuardDuty member account from its administrator account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "75cdfc1d-d1ac-47aa-8b1f-c7a876b32dc9",
"eventName": "DisassociateFromMasterAccount",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T19:24:34Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "101d3db8-c936-4b22-94fc-85068c8b5a23",
"requestParameters": {
"detectorId": "ddddd"
},
"responseElements": {
"__type": "InvalidInputException",
"message": "The request is rejected because the parameter detectorId has an invalid value.",
"type": "InvalidInputException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
EnableOrganizationAdminAccount
#Description
Designates an Amazon Web Services account within the organization as your GuardDuty delegated administrator.
GetAdministratorAccount
#Description
Provides the details of the GuardDuty administrator account associated with the current GuardDuty member account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "3d1fbc63-76fd-4dc3-9268-d60f6aa42922",
"eventName": "GetAdministratorAccount",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T18:44:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "ad894af6-5a16-4c5b-a6dc-1f3b2b16849a",
"requestParameters": {
"detectorId": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetCoverageStatistics
#Description
Retrieves aggregated statistics for your account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "b731e337-2dc1-477c-9b20-573b675d23d6",
"eventName": "GetCoverageStatistics",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T18:44:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "c22a274c-48cf-43b5-8679-f6151522c2dc",
"requestParameters": {
"detectorId": "ddddd",
"statisticsType": [
"COUNT_BY_RESOURCE_TYPE"
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetDetector
#Description
Retrieves a GuardDuty detector specified by the detectorId.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "3c13a8db-cbdf-431f-bdff-bf3dc049d04c",
"eventName": "GetDetector",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2023-07-10T12:28:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "90fcd013-eb6d-4fcd-b36c-6ff36f630e67",
"requestParameters": {
"detectorId": "6ec1aa76c9c3020a93af9e89a5a3a439"
},
"responseElements": null,
"sourceIPAddress": "10.8.8.10",
"userAgent": "RDS Console, aws-internal/3 aws-sdk-java/1.11.975 Linux/5.10.184-153.731.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.242-b08 java/1.8.0_242 vendor/Oracle_Corporation cfg/retry-mode/legacy",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCS5BLNV76",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:27:45Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
GetFilter
#Description
Returns the details of the filter specified by the filter name.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "8e33a58d-2254-41ee-b6e5-d844c60f780f",
"eventName": "GetFilter",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T18:44:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "fc76edb9-90b2-4778-b32c-c201b9f0492e",
"requestParameters": {
"detectorId": "ddddd",
"filterName": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetFindings
#Description
Describes Amazon GuardDuty findings specified by finding IDs.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "e0a43cd4-98ee-42af-ad29-e132f3be0e91",
"eventName": "GetFindings",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2023-07-10T12:28:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "aead15d4-b208-4341-b4ec-65a96227161d",
"requestParameters": {
"detectorId": "6ec1aa76c9c3020a93af9e89a5a3a439",
"findingIds": []
},
"responseElements": null,
"sourceIPAddress": "10.8.8.10",
"userAgent": "RDS Console, aws-internal/3 aws-sdk-java/1.11.975 Linux/5.10.184-153.731.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.242-b08 java/1.8.0_242 vendor/Oracle_Corporation cfg/retry-mode/legacy",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCS5BLNV76",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:27:45Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
GetFindingsStatistics
#Description
Lists GuardDuty findings statistics for the specified detector ID.
Example CloudTrail Event #
{
"awsRegion": "us-east-2",
"eventCategory": "Management",
"eventID": "e12fbff5-675c-4375-9ec0-eeb66a50eda4",
"eventName": "GetFindingsStatistics",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2021-07-07T13:21:09Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "797507667711",
"requestID": "560cb49a-f6f9-45d6-83df-ad0583a46496",
"requestParameters": {
"detectorId": "68bd40905393a0a5aa40bbec31f1af0a",
"findingCriteria": {
"criterion": {
"service.archived": {
"eq": [
false,
false
]
}
}
},
"findingStatisticTypes": [
"COUNT_BY_SEVERITY"
]
},
"responseElements": null,
"sourceIPAddress": "213.205.197.162",
"userAgent": "aws-internal/3 aws-sdk-java/1.11.1030 Linux/5.4.116-64.217.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.292-b10 java/1.8.0_292 vendor/Oracle_Corporation cfg/retry-mode/legacy",
"userIdentity": {
"accessKeyId": "ASIA3TLZJI375VVUVWIG",
"accountId": "797507667711",
"arn": "arn:aws:iam::797507667711:user/bruce",
"principalId": "AIDA3TLZJI372XH6M2Q25",
"sessionContext": {
"attributes": {
"creationDate": "2021-07-07T11:45:11Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bruce"
}
}
References #
GetInvestigation
#Description
This API is currently available as a preview.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "c4d0433c-c779-4343-954b-854e504cbad0",
"eventName": "GetInvestigation",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T18:44:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "c1a913fe-ed6f-4428-a4f4-51e640935a96",
"requestParameters": {
"detectorId": "ddddd",
"investigationId": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetInvitationsCount
#Description
Returns the count of all GuardDuty membership invitations that were sent to the current member account except the currently accepted invitation.
Example CloudTrail Event #
{
"awsRegion": "us-east-2",
"eventCategory": "Management",
"eventID": "49527f70-53c3-42e9-a698-c6db5b794331",
"eventName": "GetInvitationsCount",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2021-07-07T13:21:08Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "797507667711",
"requestID": "0c4edd21-341a-470d-9b59-19c890961047",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "213.205.197.162",
"userAgent": "aws-internal/3 aws-sdk-java/1.11.1030 Linux/5.4.116-64.217.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.292-b10 java/1.8.0_292 vendor/Oracle_Corporation cfg/retry-mode/legacy",
"userIdentity": {
"accessKeyId": "ASIA3TLZJI375VVUVWIG",
"accountId": "797507667711",
"arn": "arn:aws:iam::797507667711:user/bruce",
"principalId": "AIDA3TLZJI372XH6M2Q25",
"sessionContext": {
"attributes": {
"creationDate": "2021-07-07T11:45:11Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bruce"
}
}
References #
GetIPSet
#Description
Retrieves the IPSet specified by the ipSetId.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "2c87c340-7b10-42cf-900e-d8ca0e7546c3",
"eventName": "GetIPSet",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T18:44:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "ff2abb2a-83aa-4f5c-ac47-5bb394570078",
"requestParameters": {
"detectorId": "ddddd",
"ipSetId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetMalwareProtectionPlan
#Description
Retrieves the Malware Protection plan details associated with a Malware Protection plan ID.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "a7b79457-4339-4ce2-9623-06e75bf2675d",
"eventName": "GetMalwareProtectionPlan",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T18:44:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "a7ecbad0-fd20-4781-b781-b1cdf1789ee7",
"requestParameters": {
"malwareProtectionPlanId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetMalwareScan
#Description
Retrieves the detailed information for a specific malware scan.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "35aeff19-07b8-40d2-93a3-a19bcf74d41b",
"eventName": "GetMalwareScan",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T18:44:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "74104690-1b07-43c3-909c-09bb8138f7b9",
"requestParameters": {
"scanId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetMalwareScanSettings
#Description
Returns the details of the malware scan settings.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "ed395bec-0ba2-497d-952d-acdf9f097154",
"eventName": "GetMalwareScanSettings",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T18:44:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "f8ae7cbf-70af-44e9-af5d-97c4594f91fe",
"requestParameters": {
"detectorId": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetMasterAccount
#Description
Provides the details for the GuardDuty administrator account associated with the current GuardDuty member account.
Example CloudTrail Event #
{
"awsRegion": "us-east-2",
"eventCategory": "Management",
"eventID": "b256e96b-7fe9-45a4-8058-22742b05b44d",
"eventName": "GetMasterAccount",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2021-07-07T13:21:02Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "797507667711",
"requestID": "22f53f5c-0def-41e0-ae70-2d6d0b94e887",
"requestParameters": {
"detectorId": "68bd40905393a0a5aa40bbec31f1af0a"
},
"responseElements": null,
"sourceIPAddress": "213.205.197.162",
"userAgent": "aws-internal/3 aws-sdk-java/1.11.1030 Linux/5.4.116-64.217.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.292-b10 java/1.8.0_292 vendor/Oracle_Corporation cfg/retry-mode/legacy",
"userIdentity": {
"accessKeyId": "ASIA3TLZJI375VVUVWIG",
"accountId": "797507667711",
"arn": "arn:aws:iam::797507667711:user/bruce",
"principalId": "AIDA3TLZJI372XH6M2Q25",
"sessionContext": {
"attributes": {
"creationDate": "2021-07-07T11:45:11Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bruce"
}
}
References #
GetMemberDetectors
#Description
Describes which data sources are enabled for the member account's detector.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "1eb1712d-7295-42ea-b2e8-74b8b46eade9",
"eventName": "GetMemberDetectors",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T18:44:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "7eb3fd59-0724-4d79-8f56-2298e427327a",
"requestParameters": {
"accountIds": [
"dddddddddddd"
],
"detectorId": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetMembers
#Description
Retrieves GuardDuty member accounts (of the current GuardDuty administrator account) specified by the account IDs.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "64ae35cf-4eee-48d1-8cee-bf29f7d25c48",
"eventName": "GetMembers",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T18:44:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "155d0f4a-45a9-4808-bc0b-a2c2c6dfbd21",
"requestParameters": {
"accountIds": [
"dddddddddddd"
],
"detectorId": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetOrganizationStatistics
#Description
Retrieves how many active member accounts have each feature enabled within GuardDuty.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "4b166202-5fa9-4afb-aec1-5fe7d3c7944a",
"eventName": "GetOrganizationStatistics",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T18:32:16Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "96b2a765-929a-45ac-8d58-7794aeaed5af",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetRemainingFreeTrialDays
#Description
Provides the number of days left for each data source used in the free trial period.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "64ba3a4b-bd96-4702-a784-ec86c2c18110",
"eventName": "GetRemainingFreeTrialDays",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T18:44:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "d3f33e14-7005-446a-9b56-b9d59244cd6b",
"requestParameters": {
"accountIds": [
"dddddddddddd"
],
"detectorId": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetThreatEntitySet
#Description
Retrieves the threat entity set associated with the specified threatEntitySetId.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "965deff0-8e0a-4eed-9066-aecc506d2bc5",
"eventName": "GetThreatEntitySet",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T18:44:30Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "1b9226c6-ddb1-4943-9360-c04da502526c",
"requestParameters": {
"detectorId": "ddddd",
"threatEntitySetId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetThreatIntelSet
#Description
Retrieves the ThreatIntelSet that is specified by the ThreatIntelSet ID.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "ff822b8f-9929-4b92-9c2f-363b20ddb51d",
"eventName": "GetThreatIntelSet",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T18:44:31Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "d73be009-1897-4062-baa4-38b95c3808fd",
"requestParameters": {
"detectorId": "ddddd",
"threatIntelSetId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetTrustedEntitySet
#Description
Retrieves the trusted entity set associated with the specified trustedEntitySetId.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "38a1475c-d59b-4ad9-8fde-3b4d356630ab",
"eventName": "GetTrustedEntitySet",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T18:44:31Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "26269101-6c7c-45dd-a874-5857126f8d26",
"requestParameters": {
"detectorId": "ddddd",
"trustedEntitySetId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetUsageStatistics
#Description
Lists Amazon GuardDuty usage statistics over the last 30 days for the specified detector ID.
Example CloudTrail Event #
{
"awsRegion": "us-east-2",
"eventCategory": "Management",
"eventID": "32a32184-235f-4621-aa64-552002a16c7a",
"eventName": "GetUsageStatistics",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2021-07-07T13:20:45Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "797507667711",
"requestID": "bad0a20d-3115-41c1-822e-e0c3b1b389bb",
"requestParameters": {
"detectorId": "68bd40905393a0a5aa40bbec31f1af0a",
"maxResults": 6,
"usageCriteria": {
"dataSources": [
"S3_LOGS"
]
},
"usageStatisticsType": "TOP_RESOURCES"
},
"responseElements": null,
"sourceIPAddress": "213.205.197.162",
"userAgent": "aws-internal/3 aws-sdk-java/1.11.1030 Linux/5.4.116-64.217.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.292-b10 java/1.8.0_292 vendor/Oracle_Corporation cfg/retry-mode/legacy",
"userIdentity": {
"accessKeyId": "ASIA3TLZJI375VVUVWIG",
"accountId": "797507667711",
"arn": "arn:aws:iam::797507667711:user/bruce",
"principalId": "AIDA3TLZJI372XH6M2Q25",
"sessionContext": {
"attributes": {
"creationDate": "2021-07-07T11:45:11Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bruce"
}
}
References #
InviteMembers
#Description
Invites Amazon Web Services accounts to become members of an organization administered by the Amazon Web Services account that invokes this API.
ListCoverage
#Description
Lists coverage details for your GuardDuty account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "83fa5f78-9346-4941-a61d-8ff468ca16cf",
"eventName": "ListCoverage",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T18:44:31Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "b24884e6-4bb2-4b4f-95b7-bb05c28be0f3",
"requestParameters": {
"detectorId": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListDetectors
#Description
Lists detectorIds of all the existing Amazon GuardDuty detector resources.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "f7a5aa5b-75ca-4c02-b3f2-f4945ccab547",
"eventName": "ListDetectors",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2023-07-10T12:28:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "f75eaa1e-7b9b-4e3e-8545-706a3fa60f66",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "10.8.8.10",
"userAgent": "RDS Console, aws-internal/3 aws-sdk-java/1.11.975 Linux/5.10.184-153.731.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.242-b08 java/1.8.0_242 vendor/Oracle_Corporation cfg/retry-mode/legacy",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCS5BLNV76",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:27:45Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
ListFilters
#Description
Returns a paginated list of the current filters.
Example CloudTrail Event #
{
"awsRegion": "us-east-2",
"eventCategory": "Management",
"eventID": "3f88e11e-3890-4205-b215-cfbdf0e004a3",
"eventName": "ListFilters",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2021-07-07T13:21:08Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "797507667711",
"requestID": "e181823e-abd4-4f2e-8f54-d6aecbe1c33e",
"requestParameters": {
"detectorId": "68bd40905393a0a5aa40bbec31f1af0a",
"maxResults": "50"
},
"responseElements": null,
"sourceIPAddress": "213.205.197.162",
"userAgent": "aws-internal/3 aws-sdk-java/1.11.1030 Linux/5.4.116-64.217.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.292-b10 java/1.8.0_292 vendor/Oracle_Corporation cfg/retry-mode/legacy",
"userIdentity": {
"accessKeyId": "ASIA3TLZJI375VVUVWIG",
"accountId": "797507667711",
"arn": "arn:aws:iam::797507667711:user/bruce",
"principalId": "AIDA3TLZJI372XH6M2Q25",
"sessionContext": {
"attributes": {
"creationDate": "2021-07-07T11:45:11Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bruce"
}
}
References #
ListFindings
#Description
Lists GuardDuty findings for the specified detector ID.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "5ea74f78-9511-4c09-8834-69a33df4d5ae",
"eventName": "ListFindings",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2023-07-10T12:28:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "f3147dd6-c804-483c-bd38-532dab01ec04",
"requestParameters": {
"detectorId": "6ec1aa76c9c3020a93af9e89a5a3a439",
"findingCriteria": {
"criterion": {
"resource.resourceType": {
"eq": [
"RDSDBInstance"
]
},
"updatedAt": {
"greaterThanOrEqual": 1688905708576
}
}
}
},
"responseElements": null,
"sourceIPAddress": "10.8.8.10",
"userAgent": "RDS Console, aws-internal/3 aws-sdk-java/1.11.975 Linux/5.4.247-168.349.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.242-b08 java/1.8.0_242 vendor/Oracle_Corporation cfg/retry-mode/legacy",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCS5BLNV76",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:27:45Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
ListInvestigations
#Description
This API is currently available as a preview.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "ff0e97c7-844c-4195-9c64-ffaaba05aa82",
"eventName": "ListInvestigations",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T18:44:31Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "7717b38a-d000-4170-a216-61a36279ad9a",
"requestParameters": {
"detectorId": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListInvitations
#Description
Lists all GuardDuty membership invitations that were sent to the current Amazon Web Services account.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "3dbb1e74-39af-4c13-a702-c64dd757c98c",
"eventName": "ListInvitations",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2018-10-17T20:15:05Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "561f7da3-d249-11e8-8afa-9531e20ec550",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "9.245.1.85",
"userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
ListIPSets
#Description
Lists the IPSets of the GuardDuty service specified by the detector ID.
Example CloudTrail Event #
{
"awsRegion": "us-east-2",
"eventCategory": "Management",
"eventID": "d4dfdc6d-b830-477a-81dd-d61d3fe274fd",
"eventName": "ListIPSets",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2021-07-07T13:20:53Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "797507667711",
"requestID": "d02ed4f5-2619-4dc1-bb5b-1a6ee13419c2",
"requestParameters": {
"detectorId": "68bd40905393a0a5aa40bbec31f1af0a",
"maxResults": "10"
},
"responseElements": null,
"sourceIPAddress": "213.205.197.162",
"userAgent": "aws-internal/3 aws-sdk-java/1.11.1030 Linux/5.4.116-64.217.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.292-b10 java/1.8.0_292 vendor/Oracle_Corporation cfg/retry-mode/legacy",
"userIdentity": {
"accessKeyId": "ASIA3TLZJI375VVUVWIG",
"accountId": "797507667711",
"arn": "arn:aws:iam::797507667711:user/bruce",
"principalId": "AIDA3TLZJI372XH6M2Q25",
"sessionContext": {
"attributes": {
"creationDate": "2021-07-07T11:45:11Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bruce"
}
}
References #
ListMalwareProtectionPlans
#Description
Lists the Malware Protection plan IDs associated with the protected resources in your Amazon Web Services account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "31a05b9a-d517-445a-ae3b-d3d06dd08217",
"eventName": "ListMalwareProtectionPlans",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T18:32:16Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "a7b49736-d0b6-4945-b457-5f410497f9e9",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListMalwareScans
#Description
Returns a list of malware scans.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "6a3a5c03-44b3-41d4-ac9a-548497570de3",
"eventName": "ListMalwareScans",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T18:32:16Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "8f466861-7765-4377-b8ee-36f909a30321",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListMembers
#Description
Lists details about all member accounts for the current GuardDuty administrator account.
Example CloudTrail Event #
{
"awsRegion": "us-east-2",
"eventCategory": "Management",
"eventID": "b517874a-7025-46c2-80d2-86ad6db5016f",
"eventName": "ListMembers",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2021-07-07T13:21:02Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "797507667711",
"requestID": "7f35d686-e26e-4311-a258-3a7d24261183",
"requestParameters": {
"detectorId": "68bd40905393a0a5aa40bbec31f1af0a",
"maxResults": "50",
"onlyAssociated": "false"
},
"responseElements": null,
"sourceIPAddress": "213.205.197.162",
"userAgent": "aws-internal/3 aws-sdk-java/1.11.1030 Linux/5.4.116-64.217.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.292-b10 java/1.8.0_292 vendor/Oracle_Corporation cfg/retry-mode/legacy",
"userIdentity": {
"accessKeyId": "ASIA3TLZJI375VVUVWIG",
"accountId": "797507667711",
"arn": "arn:aws:iam::797507667711:user/bruce",
"principalId": "AIDA3TLZJI372XH6M2Q25",
"sessionContext": {
"attributes": {
"creationDate": "2021-07-07T11:45:11Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bruce"
}
}
References #
ListOrganizationAdminAccounts
#Description
Lists the accounts designated as GuardDuty delegated administrators.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"eventID": "8c7b7ea0-cdc4-4bdc-a66e-834d8ecd93ae",
"eventName": "ListOrganizationAdminAccounts",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2020-06-10T05:32:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "560c8608-242b-4256-b2f2-dea341a6662f",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "251.105.254.1",
"userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
ListPublishingDestinations
#Description
Returns a list of publishing destinations associated with the specified detectorId.
Example CloudTrail Event #
{
"awsRegion": "us-east-2",
"eventCategory": "Management",
"eventID": "9457e0b9-7877-41cf-b3a0-85e3c2aece6a",
"eventName": "ListPublishingDestinations",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2021-07-07T13:21:08Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "797507667711",
"requestID": "03ff54ac-a19c-46e6-8075-f529bf045a08",
"requestParameters": {
"detectorId": "68bd40905393a0a5aa40bbec31f1af0a"
},
"responseElements": null,
"sourceIPAddress": "213.205.197.162",
"userAgent": "aws-internal/3 aws-sdk-java/1.11.1030 Linux/5.4.116-64.217.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.292-b10 java/1.8.0_292 vendor/Oracle_Corporation cfg/retry-mode/legacy",
"userIdentity": {
"accessKeyId": "ASIA3TLZJI375VVUVWIG",
"accountId": "797507667711",
"arn": "arn:aws:iam::797507667711:user/bruce",
"principalId": "AIDA3TLZJI372XH6M2Q25",
"sessionContext": {
"attributes": {
"creationDate": "2021-07-07T11:45:11Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bruce"
}
}
References #
ListThreatEntitySets
#Description
Lists the threat entity sets associated with the specified GuardDuty detector ID.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "5d6705e7-4246-4397-a50a-05b0f9c9c1ec",
"eventName": "ListThreatEntitySets",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T18:44:31Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "4539ea52-a4aa-43ed-a95d-eda1dedbbead",
"requestParameters": {
"detectorId": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListThreatIntelSets
#Description
Lists the ThreatIntelSets of the GuardDuty service specified by the detector ID.
Example CloudTrail Event #
{
"awsRegion": "us-east-2",
"eventCategory": "Management",
"eventID": "5e5fe12f-4df6-4fff-baf7-3f1a5a7c72c7",
"eventName": "ListThreatIntelSets",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2021-07-07T13:20:53Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "797507667711",
"requestID": "53f90def-51d0-456f-9dd0-0fe5a44690bc",
"requestParameters": {
"detectorId": "68bd40905393a0a5aa40bbec31f1af0a",
"maxResults": "10"
},
"responseElements": null,
"sourceIPAddress": "213.205.197.162",
"userAgent": "aws-internal/3 aws-sdk-java/1.11.1030 Linux/5.4.116-64.217.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.292-b10 java/1.8.0_292 vendor/Oracle_Corporation cfg/retry-mode/legacy",
"userIdentity": {
"accessKeyId": "ASIA3TLZJI375VVUVWIG",
"accountId": "797507667711",
"arn": "arn:aws:iam::797507667711:user/bruce",
"principalId": "AIDA3TLZJI372XH6M2Q25",
"sessionContext": {
"attributes": {
"creationDate": "2021-07-07T11:45:11Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bruce"
}
}
References #
ListTrustedEntitySets
#Description
Lists the trusted entity sets associated with the specified GuardDuty detector ID.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "836d350d-23ad-4510-8e6a-cede98110336",
"eventName": "ListTrustedEntitySets",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T18:44:31Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "ca3b8655-ccf6-4cd4-97b8-e1c56a5c4425",
"requestParameters": {
"detectorId": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
SendObjectMalwareScan
#Description
Initiates a malware scan for a specific S3 object.
StartMalwareScan
#Description
Initiates the malware scan.
StartMonitoringMembers
#Description
Turns on GuardDuty monitoring of the specified member accounts.
TagResource
#Description
Adds tags to a resource.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "0af9e7b6-b59a-4325-a6b4-215cfa892c0a",
"eventName": "TagResource",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T21:47:37Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "366a9bb1-510d-48bc-82d7-03ab6a346098",
"requestParameters": {
"resourceArn": "arn:aws:guardduty:us-west-1:123456789012:detector/b4cf8aacc70423c0f45074ed90dd6596",
"tags": {
"dwfix-test": "gd"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,n,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UnarchiveFindings
#Description
Unarchives GuardDuty findings specified by the findingIds.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "6ba96504-e9b5-453a-a9aa-01774e93dbd6",
"eventName": "UnarchiveFindings",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T21:47:31Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "33f91e44-5851-425b-b89d-a6d949de10a6",
"requestParameters": {
"detectorId": "b4cf8aacc70423c0f45074ed90dd6596",
"findingIds": [
"6284b9ced79340799b78b237804a8964"
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,n,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UntagResource
#Description
Removes tags from a resource.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "c1f7abb1-1884-4869-9899-2d3016a859ab",
"eventName": "UntagResource",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T19:24:34Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "b20a6693-44f6-461c-9fd2-56ca1cc9f980",
"requestParameters": {
"resourceArn": "arn:aws:iam::123456789012:role/dw-probe",
"tagKeys": "ddddd"
},
"responseElements": {
"message": "Invalid input resource arn: expected vendor guardduty"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateFilter
#Description
Updates the filter specified by the filter name.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "7c0e881c-5fd5-4985-b012-02e2269d887b",
"eventName": "UpdateFilter",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T19:24:34Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "2543428e-1c19-4c12-a497-6bcb0c89655b",
"requestParameters": {
"detectorId": "ddddd",
"filterName": "dw-probe"
},
"responseElements": {
"__type": "InvalidInputException",
"message": "The request is rejected because the parameter detectorId has an invalid value.",
"type": "InvalidInputException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateFindingsFeedback
#Description
Marks the specified GuardDuty findings as useful or not useful.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "8517b2cd-446b-4cd0-b6f5-a8bd2b4f0384",
"eventName": "UpdateFindingsFeedback",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T19:24:34Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "67460748-c313-4ffd-ac2d-c4a933e3630c",
"requestParameters": {
"detectorId": "ddddd",
"feedback": "USEFUL",
"findingIds": [
"ddddd"
]
},
"responseElements": {
"__type": "InvalidInputException",
"message": "The request is rejected because the parameter detectorId has an invalid value.",
"type": "InvalidInputException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateIPSet
#Description
Updates the IPSet specified by the IPSet ID.
CloudTrail management event, logged by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "c27389e7-ccb4-4361-9e83-c6314f6c3e30",
"eventName": "UpdateIPSet",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T19:24:34Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "e8edbf22-ab42-4b62-9717-5156dbf44e12",
"requestParameters": {
"detectorId": "ddddd",
"ipSetId": "dw-probe"
},
"responseElements": {
"__type": "InvalidInputException",
"message": "The request is rejected because the parameter detectorId has an invalid value.",
"type": "InvalidInputException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Elastic #
T1562, T1562.001↳ also matches CreateIPSet, UpdateDetector, UpdateThreatIntelSet, CreateThreatIntelSet Panther #
T1562↳ also matches CreateIPSet
UpdateMalwareProtectionPlan
#Description
Updates an existing Malware Protection plan resource.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "f388af2c-0e58-4738-9e83-62e945959754",
"eventName": "UpdateMalwareProtectionPlan",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T19:24:34Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "617c5e04-e333-411e-afa4-aba44c6fdfdd",
"requestParameters": {
"malwareProtectionPlanId": "dw-probe"
},
"responseElements": {
"__type": "InvalidInputException",
"message": "The request is rejected because an invalid or out-of-range value is specified as an input parameter.",
"type": "InvalidInputException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateMalwareScanSettings
#Description
Updates the malware scan settings.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "7b310caf-a72c-4b01-a0cd-ff585c87b928",
"eventName": "UpdateMalwareScanSettings",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T19:24:34Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "a9d6a9bb-1fce-41fa-ad97-1b474090a974",
"requestParameters": {
"detectorId": "ddddd"
},
"responseElements": {
"__type": "InvalidInputException",
"message": "The request is rejected because the parameter detectorId has an invalid value.",
"type": "InvalidInputException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateMemberDetectors
#Description
Contains information on member accounts to be updated.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "dfdd53e8-8c38-4496-9e2b-690ea6ff9729",
"eventName": "UpdateMemberDetectors",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T19:24:35Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "1c9df014-ca0b-4a21-bc44-1a349b9778d3",
"requestParameters": {
"accountIds": [
"dddddddddddd"
],
"detectorId": "ddddd"
},
"responseElements": {
"__type": "InvalidInputException",
"message": "The request is rejected because the parameter detectorId has an invalid value.",
"type": "InvalidInputException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateOrganizationConfiguration
#Description
Configures the delegated administrator account with the provided values.
CloudTrail management event, logged by default.Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "b5f53d37-e0e9-446e-8233-c36d26f75e54",
"eventName": "UpdateOrganizationConfiguration",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T19:24:35Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "ab74f184-6eac-48d0-99d4-9a15a8faeb0f",
"requestParameters": {
"detectorId": "ddddd"
},
"responseElements": {
"__type": "InvalidInputException",
"message": "The request is rejected because the parameter detectorId has an invalid value.",
"type": "InvalidInputException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdatePublishingDestination
#Description
Updates information about the publishing destination specified by the destinationId.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "63cf1832-b87d-4963-8b98-320e1acdb0e7",
"eventName": "UpdatePublishingDestination",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T19:24:35Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "bcf85a8f-ad44-4366-8831-f7baca6daa53",
"requestParameters": {
"destinationId": "dw-probe",
"detectorId": "ddddd"
},
"responseElements": {
"__type": "InvalidInputException",
"message": "The request is rejected because an invalid or out-of-range value is specified as an input parameter.",
"type": "InvalidInputException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateThreatEntitySet
#Description
Updates the threat entity set associated with the specified threatEntitySetId.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "626150a3-e80c-40e9-bab5-8baaf28fa5ee",
"eventName": "UpdateThreatEntitySet",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T19:24:36Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "2efbeb5e-bd58-4ba8-b976-72907746f350",
"requestParameters": {
"detectorId": "ddddd",
"threatEntitySetId": "dw-probe"
},
"responseElements": {
"__type": "InvalidInputException",
"message": "The request is rejected because the parameter detectorId has an invalid value.",
"type": "InvalidInputException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateTrustedEntitySet
#Description
Updates the trusted entity set associated with the specified trustedEntitySetId.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "BadRequestException",
"eventCategory": "Management",
"eventID": "cb96e170-c4b2-4719-a956-dfabd35b2e54",
"eventName": "UpdateTrustedEntitySet",
"eventSource": "guardduty.amazonaws.com",
"eventTime": "2026-06-29T19:24:37Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "de001375-fb69-4ad7-9a84-d46ec1b8beac",
"requestParameters": {
"detectorId": "ddddd",
"trustedEntitySetId": "dw-probe"
},
"responseElements": {
"__type": "InvalidInputException",
"message": "The request is rejected because the parameter detectorId has an invalid value.",
"type": "InvalidInputException"
},
"sourceIPAddress": "203.0.113.5",
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}