GuardDuty

eventNameDescriptionSampleRule
anyCatch-all entry for GuardDuty rules that match the service but not a specific eventName.NN
CreateIPSetCreates a trusted IP set in GuardDuty, which causes GuardDuty to not generate findings for traffic from the listed IP addresses.YY
DeleteDetectorDeletes an Amazon GuardDuty detector, disabling threat detection for the account in the current region.YY
DeleteInvitationsDeletes invitations sent to the current AWS account by specified GuardDuty administrator accounts.YY
DeleteMembersDeletes GuardDuty member accounts, removing them from the administrator account's organization.YY
DeletePublishingDestinationDeletes a publishing destination for GuardDuty findings, stopping export of findings to that destination (e.g. S3 or Security Hub).YY
DeleteThreatIntelSetDeletes a custom threat intelligence set (list of malicious IPs or domains) from a GuardDuty detector.YY
DisassociateFromAdministratorAccountDisassociates the current GuardDuty member account from its administrator account, stopping the administrator from managing GuardDuty for this account.YY
DisassociateMembersDisassociates GuardDuty member accounts from the current administrator account without deleting them.YY
StopMonitoringMembersStops GuardDuty from monitoring the specified member accounts, suspending threat detection for those accounts under the current administrator.YY
UpdateDetectorUpdates an Amazon GuardDuty detector's configuration, such as enabling or disabling data sources or changing the finding publishing frequency.YY
UpdateThreatIntelSetUpdates the name, location, or activation status of a custom threat intelligence set in a GuardDuty detector.YY
AcceptAdministratorInvitationAccepts the invitation to be a member account and get monitored by a GuardDuty administrator account that sent the invitation.NN
AcceptInvitationAccepts the invitation to be monitored by a GuardDuty administrator account.NN
ArchiveFindingsArchives GuardDuty findings that are specified by the list of finding IDs.YY
CreateDetectorCreates a single GuardDuty detector.YN
CreateFilterCreates a filter using the specified finding criteria.YN
CreateInvestigationThis API is currently available as a preview.YN
CreateMalwareProtectionPlanCreates a new Malware Protection plan for the protected resource.YN
CreateMembersCreates member accounts of the current Amazon Web Services account by specifying a list of Amazon Web Services account IDs.NN
CreatePublishingDestinationCreates a publishing destination where you can export your GuardDuty findings.NN
CreateSampleFindingsGenerates sample findings of types specified by the list of finding types.YN
CreateThreatEntitySetCreates a new threat entity set.YN
CreateThreatIntelSetCreates a new ThreatIntelSet.YY
CreateTrustedEntitySetCreates a new trusted entity set.YN
DeclineInvitationsDeclines invitations sent to the current member account by Amazon Web Services accounts specified by their account IDs.NN
DeleteFilterDeletes the filter specified by the filter name.YN
DeleteIPSetDeletes the IPSet specified by the ipSetId.YY
DeleteMalwareProtectionPlanDeletes the Malware Protection plan ID associated with the Malware Protection plan resource.YN
DeleteThreatEntitySetDeletes the threat entity set that is associated with the specified threatEntitySetId.YN
DeleteTrustedEntitySetDeletes the trusted entity set that is associated with the specified trustedEntitySetId.YN
DescribeMalwareScansReturns a list of malware scans.YN
DescribeOrganizationConfigurationReturns information about the account selected as the delegated administrator for GuardDuty.YN
DescribePublishingDestinationReturns information about the publishing destination specified by the provided destinationId.YN
DisableOrganizationAdminAccountRemoves the existing GuardDuty delegated administrator of the organization.YN
DisassociateFromMasterAccountDisassociates the current GuardDuty member account from its administrator account.YN
EnableOrganizationAdminAccountDesignates an Amazon Web Services account within the organization as your GuardDuty delegated administrator.NN
GetAdministratorAccountProvides the details of the GuardDuty administrator account associated with the current GuardDuty member account.YN
GetCoverageStatisticsRetrieves aggregated statistics for your account.YN
GetDetectorRetrieves a GuardDuty detector specified by the detectorId.YN
GetFilterReturns the details of the filter specified by the filter name.YN
GetFindingsDescribes Amazon GuardDuty findings specified by finding IDs.YN
GetFindingsStatisticsLists GuardDuty findings statistics for the specified detector ID.YN
GetInvestigationThis API is currently available as a preview.YN
GetInvitationsCountReturns the count of all GuardDuty membership invitations that were sent to the current member account except the currently accepted invitation.YN
GetIPSetRetrieves the IPSet specified by the ipSetId.YN
GetMalwareProtectionPlanRetrieves the Malware Protection plan details associated with a Malware Protection plan ID.YN
GetMalwareScanRetrieves the detailed information for a specific malware scan.YN
GetMalwareScanSettingsReturns the details of the malware scan settings.YN
GetMasterAccountProvides the details for the GuardDuty administrator account associated with the current GuardDuty member account.YN
GetMemberDetectorsDescribes which data sources are enabled for the member account's detector.YN
GetMembersRetrieves GuardDuty member accounts (of the current GuardDuty administrator account) specified by the account IDs.YN
GetOrganizationStatisticsRetrieves how many active member accounts have each feature enabled within GuardDuty.YN
GetRemainingFreeTrialDaysProvides the number of days left for each data source used in the free trial period.YN
GetThreatEntitySetRetrieves the threat entity set associated with the specified threatEntitySetId.YN
GetThreatIntelSetRetrieves the ThreatIntelSet that is specified by the ThreatIntelSet ID.YN
GetTrustedEntitySetRetrieves the trusted entity set associated with the specified trustedEntitySetId.YN
GetUsageStatisticsLists Amazon GuardDuty usage statistics over the last 30 days for the specified detector ID.YN
InviteMembersInvites Amazon Web Services accounts to become members of an organization administered by the Amazon Web Services account that invokes this API.NN
ListCoverageLists coverage details for your GuardDuty account.YN
ListDetectorsLists detectorIds of all the existing Amazon GuardDuty detector resources.YN
ListFiltersReturns a paginated list of the current filters.YN
ListFindingsLists GuardDuty findings for the specified detector ID.YN
ListInvestigationsThis API is currently available as a preview.YN
ListInvitationsLists all GuardDuty membership invitations that were sent to the current Amazon Web Services account.YN
ListIPSetsLists the IPSets of the GuardDuty service specified by the detector ID.YN
ListMalwareProtectionPlansLists the Malware Protection plan IDs associated with the protected resources in your Amazon Web Services account.YN
ListMalwareScansReturns a list of malware scans.YN
ListMembersLists details about all member accounts for the current GuardDuty administrator account.YN
ListOrganizationAdminAccountsLists the accounts designated as GuardDuty delegated administrators.YN
ListPublishingDestinationsReturns a list of publishing destinations associated with the specified detectorId.YN
ListTagsForResourceLists tags for a resource.YN
ListThreatEntitySetsLists the threat entity sets associated with the specified GuardDuty detector ID.YN
ListThreatIntelSetsLists the ThreatIntelSets of the GuardDuty service specified by the detector ID.YN
ListTrustedEntitySetsLists the trusted entity sets associated with the specified GuardDuty detector ID.YN
SendObjectMalwareScanInitiates a malware scan for a specific S3 object.NN
StartMalwareScanInitiates the malware scan.NN
StartMonitoringMembersTurns on GuardDuty monitoring of the specified member accounts.NN
TagResourceAdds tags to a resource.YN
UnarchiveFindingsUnarchives GuardDuty findings specified by the findingIds.YN
UntagResourceRemoves tags from a resource.YN
UpdateFilterUpdates the filter specified by the filter name.YN
UpdateFindingsFeedbackMarks the specified GuardDuty findings as useful or not useful.YN
UpdateIPSetUpdates the IPSet specified by the IPSet ID.YY
UpdateMalwareProtectionPlanUpdates an existing Malware Protection plan resource.YN
UpdateMalwareScanSettingsUpdates the malware scan settings.YN
UpdateMemberDetectorsContains information on member accounts to be updated.YN
UpdateOrganizationConfigurationConfigures the delegated administrator account with the provided values.YN
UpdatePublishingDestinationUpdates information about the publishing destination specified by the destinationId.YN
UpdateThreatEntitySetUpdates the threat entity set associated with the specified threatEntitySetId.YN
UpdateTrustedEntitySetUpdates the trusted entity set associated with the specified trustedEntitySetId.YN

any: GuardDuty (catch-all)

#
Service
guardduty

Description

Catch-all entry for GuardDuty rules that match the service but not a specific eventName.

CreateIPSet

#
Service
guardduty

Description

Creates a trusted IP set in GuardDuty, which causes GuardDuty to not generate findings for traffic from the listed IP addresses.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "35007bd7-546e-49b4-8588-e72c6e94393a",
  "eventName": "CreateIPSet",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T21:47:07Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "a14ae013-ed7e-4e7b-ac2a-c09c3e67923a",
  "requestParameters": {
    "activate": false,
    "clientToken": "a00286a6-81bc-4406-85f0-35671ace2f6b",
    "detectorId": "b4cf8aacc70423c0f45074ed90dd6596",
    "format": "TXT",
    "location": "s3://dwfix-gd-93708318-20260629214658/ipset.txt",
    "name": "dwfix-ipset-20260629214658"
  },
  "responseElements": {
    "ipSetId": "cecf8aacd8c8c2d5818839de35d5dd7a"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,n,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • AWS GuardDuty Detection Suppression source high: Identifies attempts to suppress or blind Amazon GuardDuty without deleting the detector outright. Adversaries with GuardDuty permissions can create or update a trusted IP set (CreateIPSet/UpdateIPSet) so that traffic from listed addresses is never flagged, tamper with the threat intelligence feed used to generate findings (CreateThreatIntelSet/UpdateThreatIntelSet), or soft-disable the detector via UpdateDetector with Enable set to false. All three techniques leave the detector itself intact, evading detections that only look for detector deletion.T1562, T1562.001↳ also matches UpdateDetector, UpdateThreatIntelSet, CreateThreatIntelSet, UpdateIPSet

Panther #

DeleteDetector

#
Service
guardduty

Description

Deletes an Amazon GuardDuty detector, disabling threat detection for the account in the current region.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "c1367a2f-8910-4e64-9256-a854d2e9f37d",
  "eventName": "DeleteDetector",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2022-07-21T20:27:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "111111111111",
  "requestID": "1e832076-d7a8-432b-b0df-54ba62f6b62c",
  "requestParameters": {
    "detectorId": "123"
  },
  "responseElements": {
    "__type": "InvalidInputException",
    "message": "The request is rejected because the parameter detectorId has an invalid value."
  },
  "sourceIPAddress": "67.171.71.185",
  "userAgent": "aws-cli/2.7.3 Python/3.9.13 Darwin/21.5.0 source/x86_64 prompt/off command/guardduty.delete-detector",
  "userIdentity": {
    "accessKeyId": "AKIAYTOGP2RLFLKADUVG",
    "accountId": "111111111111",
    "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli",
    "principalId": "AIDAYTOGP2RLI4PXTGCEU",
    "type": "IAMUser",
    "userName": "gowthamaraj_cli"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aws::errorCode (sigma rule field)eqsuccess1 rulesigma

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

  • AWS GuardDuty Detector Deleted Or Updated source high: Detects successful deletion or disabling of an AWS GuardDuty detector, possibly by an attacker trying to avoid detection of its malicious activities. Upon deletion, GuardDuty stops monitoring the environment and all existing findings are lost. Verify with the user identity that this activity is legitimate.T1685, T1685.002↳ also matches UpdateDetector

Elastic #

  • AWS GuardDuty Detector Deletion source high: Detects the deletion of an Amazon GuardDuty detector. GuardDuty provides continuous monitoring for malicious or unauthorized activity across AWS accounts. Deleting the detector disables this visibility, stopping all threat detection and removing existing findings. Adversaries may delete GuardDuty detectors to impair security monitoring and evade detection during or after an intrusion. This rule identifies successful "DeleteDetector" API calls and can indicate a deliberate defense evasion attempt.T1562, T1562.001

Splunk #

References #

DeleteInvitations

#
Service
guardduty

Description

Deletes invitations sent to the current AWS account by specified GuardDuty administrator accounts.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "852553b3-9383-4582-b3f2-f5904e31e5e3",
  "eventName": "DeleteInvitations",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T19:24:31Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "924da0f7-984d-409b-879c-1ee7c346a010",
  "requestParameters": {
    "accountIds": [
      "dddddddddddd"
    ]
  },
  "responseElements": {
    "__type": "InvalidInputException",
    "message": "The request failed because parameter accountIds has accountId values that are formatted incorrectly.",
    "type": "InvalidInputException"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS GuardDuty Member Account Manipulation source high: Detects attempts to disassociate or manipulate Amazon GuardDuty member accounts within an AWS organization. In multi-account GuardDuty deployments, a delegated administrator account aggregates findings from member accounts. Adversaries may attempt to disassociate member accounts, delete member relationships, stop monitoring members, or delete pending invitations to break this centralized visibility. These actions can be precursors to or alternatives for deleting GuardDuty detectors entirely, allowing attackers to operate undetected in member accounts while the administrator account loses visibility. This rule identifies successful API calls that manipulate GuardDuty member relationships, which are rare in normal operations and warrant immediate investigation.T1562, T1562.001↳ also matches DeleteMembers, DisassociateFromAdministratorAccount, DisassociateMembers, StopMonitoringMembers

DeleteMembers

#
Service
guardduty

Description

Deletes GuardDuty member accounts, removing them from the administrator account's organization.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "64b58c22-3741-463a-bda8-96e86fbcf8f4",
  "eventName": "DeleteMembers",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T19:24:31Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7bef027d-2fa6-4fd1-aa31-fb67cb95038d",
  "requestParameters": {
    "accountIds": [
      "dddddddddddd"
    ],
    "detectorId": "ddddd"
  },
  "responseElements": {
    "__type": "InvalidInputException",
    "message": "The request is rejected because the parameter detectorId has an invalid value.",
    "type": "InvalidInputException"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS GuardDuty Member Account Manipulation source high: Detects attempts to disassociate or manipulate Amazon GuardDuty member accounts within an AWS organization. In multi-account GuardDuty deployments, a delegated administrator account aggregates findings from member accounts. Adversaries may attempt to disassociate member accounts, delete member relationships, stop monitoring members, or delete pending invitations to break this centralized visibility. These actions can be precursors to or alternatives for deleting GuardDuty detectors entirely, allowing attackers to operate undetected in member accounts while the administrator account loses visibility. This rule identifies successful API calls that manipulate GuardDuty member relationships, which are rare in normal operations and warrant immediate investigation.T1562, T1562.001↳ also matches DeleteInvitations, DisassociateFromAdministratorAccount, DisassociateMembers, StopMonitoringMembers

DeletePublishingDestination

#
Service
guardduty

Description

Deletes a publishing destination for GuardDuty findings, stopping export of findings to that destination (e.g. S3 or Security Hub).

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "2bd05e1f-c9c9-469d-bee2-2676aaf493fd",
  "eventName": "DeletePublishingDestination",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T19:24:31Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "111ab1a5-9027-4388-a4f0-c2a9a0544550",
  "requestParameters": {
    "destinationId": "dw-probe",
    "detectorId": "ddddd"
  },
  "responseElements": {
    "__type": "InvalidInputException",
    "message": "The request is rejected because the parameter detectorId has an invalid value.",
    "type": "InvalidInputException"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

DeleteThreatIntelSet

#
Service
guardduty

Description

Deletes a custom threat intelligence set (list of malicious IPs or domains) from a GuardDuty detector.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "755a0b7f-58cb-4bc5-97fb-88c038041b56",
  "eventName": "DeleteThreatIntelSet",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T19:24:32Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "30066e5f-89dd-40a3-a75f-aefd92c884d2",
  "requestParameters": {
    "detectorId": "ddddd",
    "threatIntelSetId": "dw-probe"
  },
  "responseElements": {
    "__type": "InvalidInputException",
    "message": "The request is rejected because the parameter detectorId has an invalid value.",
    "type": "InvalidInputException"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

DisassociateFromAdministratorAccount

#
Service
guardduty

Description

Disassociates the current GuardDuty member account from its administrator account, stopping the administrator from managing GuardDuty for this account.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "7117ed98-6219-4e5f-9272-10ecbd07bd5f",
  "eventName": "DisassociateFromAdministratorAccount",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T19:24:32Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "d3ffcbd3-baee-4b44-b284-e8bfaf69552b",
  "requestParameters": {
    "detectorId": "ddddd"
  },
  "responseElements": {
    "__type": "InvalidInputException",
    "message": "The request is rejected because the parameter detectorId has an invalid value.",
    "type": "InvalidInputException"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS GuardDuty Member Account Manipulation source high: Detects attempts to disassociate or manipulate Amazon GuardDuty member accounts within an AWS organization. In multi-account GuardDuty deployments, a delegated administrator account aggregates findings from member accounts. Adversaries may attempt to disassociate member accounts, delete member relationships, stop monitoring members, or delete pending invitations to break this centralized visibility. These actions can be precursors to or alternatives for deleting GuardDuty detectors entirely, allowing attackers to operate undetected in member accounts while the administrator account loses visibility. This rule identifies successful API calls that manipulate GuardDuty member relationships, which are rare in normal operations and warrant immediate investigation.T1562, T1562.001↳ also matches DeleteInvitations, DeleteMembers, DisassociateMembers, StopMonitoringMembers

DisassociateMembers

#
Service
guardduty

Description

Disassociates GuardDuty member accounts from the current administrator account without deleting them.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "127746f7-9999-4423-a3cf-f250d014e6df",
  "eventName": "DisassociateMembers",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T19:24:32Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "4a07a6e7-7939-47cc-a94b-73157c439204",
  "requestParameters": {
    "accountIds": [
      "dddddddddddd"
    ],
    "detectorId": "ddddd"
  },
  "responseElements": {
    "__type": "InvalidInputException",
    "message": "The request is rejected because the parameter detectorId has an invalid value.",
    "type": "InvalidInputException"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS GuardDuty Member Account Manipulation source high: Detects attempts to disassociate or manipulate Amazon GuardDuty member accounts within an AWS organization. In multi-account GuardDuty deployments, a delegated administrator account aggregates findings from member accounts. Adversaries may attempt to disassociate member accounts, delete member relationships, stop monitoring members, or delete pending invitations to break this centralized visibility. These actions can be precursors to or alternatives for deleting GuardDuty detectors entirely, allowing attackers to operate undetected in member accounts while the administrator account loses visibility. This rule identifies successful API calls that manipulate GuardDuty member relationships, which are rare in normal operations and warrant immediate investigation.T1562, T1562.001↳ also matches DeleteInvitations, DeleteMembers, DisassociateFromAdministratorAccount, StopMonitoringMembers

StopMonitoringMembers

#
Service
guardduty

Description

Stops GuardDuty from monitoring the specified member accounts, suspending threat detection for those accounts under the current administrator.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "62aa8b6f-84db-4730-ba0a-3df5ff96e82c",
  "eventName": "StopMonitoringMembers",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T19:24:32Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "4b9f8311-73a3-4aa3-b3aa-264e522eac7c",
  "requestParameters": {
    "accountIds": [
      "dddddddddddd"
    ],
    "detectorId": "ddddd"
  },
  "responseElements": {
    "__type": "InvalidInputException",
    "message": "The request is rejected because the parameter detectorId has an invalid value.",
    "type": "InvalidInputException"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS GuardDuty Member Account Manipulation source high: Detects attempts to disassociate or manipulate Amazon GuardDuty member accounts within an AWS organization. In multi-account GuardDuty deployments, a delegated administrator account aggregates findings from member accounts. Adversaries may attempt to disassociate member accounts, delete member relationships, stop monitoring members, or delete pending invitations to break this centralized visibility. These actions can be precursors to or alternatives for deleting GuardDuty detectors entirely, allowing attackers to operate undetected in member accounts while the administrator account loses visibility. This rule identifies successful API calls that manipulate GuardDuty member relationships, which are rare in normal operations and warrant immediate investigation.T1562, T1562.001↳ also matches DeleteInvitations, DeleteMembers, DisassociateFromAdministratorAccount, DisassociateMembers

UpdateDetector

#
Service
guardduty

Description

Updates an Amazon GuardDuty detector's configuration, such as enabling or disabling data sources or changing the finding publishing frequency.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "b3cc2353-774e-4ef5-87d9-8c1777030c37",
  "eventName": "UpdateDetector",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T19:24:32Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7089af84-87b5-442d-b876-a1ec5f7c6ab2",
  "requestParameters": {
    "detectorId": "ddddd"
  },
  "responseElements": {
    "__type": "InvalidInputException",
    "message": "The request is rejected because the parameter detectorId has an invalid value.",
    "type": "InvalidInputException"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aws::errorCode (sigma rule field)eqsuccess1 rulesigma

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

  • AWS GuardDuty Detector Deleted Or Updated source high: Detects successful deletion or disabling of an AWS GuardDuty detector, possibly by an attacker trying to avoid detection of its malicious activities. Upon deletion, GuardDuty stops monitoring the environment and all existing findings are lost. Verify with the user identity that this activity is legitimate.T1685, T1685.002↳ also matches DeleteDetector

Elastic #

  • AWS GuardDuty Detection Suppression source high: Identifies attempts to suppress or blind Amazon GuardDuty without deleting the detector outright. Adversaries with GuardDuty permissions can create or update a trusted IP set (CreateIPSet/UpdateIPSet) so that traffic from listed addresses is never flagged, tamper with the threat intelligence feed used to generate findings (CreateThreatIntelSet/UpdateThreatIntelSet), or soft-disable the detector via UpdateDetector with Enable set to false. All three techniques leave the detector itself intact, evading detections that only look for detector deletion.T1562, T1562.001↳ also matches CreateIPSet, UpdateThreatIntelSet, CreateThreatIntelSet, UpdateIPSet

Kusto #

YARA-L #

Panther #

UpdateThreatIntelSet

#
Service
guardduty

Description

Updates the name, location, or activation status of a custom threat intelligence set in a GuardDuty detector.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "609e006d-ccde-4be0-9dc5-944d2904472d",
  "eventName": "UpdateThreatIntelSet",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T19:24:32Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "6dad5a5c-f72d-4b6e-83ea-d1722e9dcb03",
  "requestParameters": {
    "detectorId": "ddddd",
    "threatIntelSetId": "dw-probe"
  },
  "responseElements": {
    "__type": "InvalidInputException",
    "message": "The request is rejected because the parameter detectorId has an invalid value.",
    "type": "InvalidInputException"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS GuardDuty Detection Suppression source high: Identifies attempts to suppress or blind Amazon GuardDuty without deleting the detector outright. Adversaries with GuardDuty permissions can create or update a trusted IP set (CreateIPSet/UpdateIPSet) so that traffic from listed addresses is never flagged, tamper with the threat intelligence feed used to generate findings (CreateThreatIntelSet/UpdateThreatIntelSet), or soft-disable the detector via UpdateDetector with Enable set to false. All three techniques leave the detector itself intact, evading detections that only look for detector deletion.T1562, T1562.001↳ also matches CreateIPSet, UpdateDetector, CreateThreatIntelSet, UpdateIPSet

YARA-L #

AcceptAdministratorInvitation

#
Service
guardduty

Description

Accepts the invitation to be a member account and get monitored by a GuardDuty administrator account that sent the invitation.

AcceptInvitation

#
Service
guardduty

Description

Accepts the invitation to be monitored by a GuardDuty administrator account.

ArchiveFindings

#
Service
guardduty

Description

Archives GuardDuty findings that are specified by the list of finding IDs.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "c6d3e6c2-57c5-4cf8-a9a3-929312ca7ef4",
  "eventName": "ArchiveFindings",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T21:47:30Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "123d3d39-1627-43d1-af15-81ec0b6f9805",
  "requestParameters": {
    "detectorId": "b4cf8aacc70423c0f45074ed90dd6596",
    "findingIds": [
      "6284b9ced79340799b78b237804a8964"
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,n,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

  • AWS Macie Disabled/Updated source medium: Amazon Macie is a data security and data privacy service to discover and protect sensitive data. Security teams use Macie to detect open S3 Buckets that could have potentially sensitive data in it along with policy violations, such as missing Encryption. If an attacker disables Macie, it could potentially hide data exfiltration.T1562

CreateDetector

#
Service
guardduty

Description

Creates a single GuardDuty detector.

Example CloudTrail Event #

{
  "awsRegion": "us-east-2",
  "eventCategory": "Management",
  "eventID": "fbba89ea-383b-464d-ae8a-ef1b918b8241",
  "eventName": "CreateDetector",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2021-07-07T13:20:38Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "797507667711",
  "requestID": "9c0fc41e-b8d6-4bcd-bd52-4a154845912b",
  "requestParameters": {
    "clientToken": "e58412d6-1c57-4e84-b993-c00f2d38f70c",
    "enable": true
  },
  "responseElements": {
    "detectorId": "68bd40905393a0a5aa40bbec31f1af0a"
  },
  "sourceIPAddress": "213.205.197.162",
  "userAgent": "aws-internal/3 aws-sdk-java/1.11.1030 Linux/5.4.116-64.217.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.292-b10 java/1.8.0_292 vendor/Oracle_Corporation cfg/retry-mode/legacy",
  "userIdentity": {
    "accessKeyId": "ASIA3TLZJI375VVUVWIG",
    "accountId": "797507667711",
    "arn": "arn:aws:iam::797507667711:user/bruce",
    "principalId": "AIDA3TLZJI372XH6M2Q25",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-07-07T11:45:11Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bruce"
  }
}

References #

CreateFilter

#
Service
guardduty

Description

Creates a filter using the specified finding criteria.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "03020b9a-eab4-4684-967b-fe430f621d6f",
  "eventName": "CreateFilter",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T21:47:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "9743ae2a-4a11-4d8b-986d-eef4713e04cb",
  "requestParameters": {
    "action": "NOOP",
    "clientToken": "6ba6b51e-1ce0-4218-9925-a1a462358c79",
    "description": "dwfix test filter",
    "detectorId": "b4cf8aacc70423c0f45074ed90dd6596",
    "findingCriteria": {
      "criterion": {
        "region": {
          "equals": [
            "us-west-1"
          ]
        }
      }
    },
    "name": "dwfix-gd-filter-20260629214658",
    "rank": 1
  },
  "responseElements": {
    "name": "dwfix-gd-filter-20260629214658"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,n,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateInvestigation

#
Service
guardduty

Description

This API is currently available as a preview.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "03e009a5-2e97-4146-8d7a-dcb81a4708ed",
  "eventName": "CreateInvestigation",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T21:47:36Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "58aca665-7fd2-4c2b-9f00-e5300dfc774c",
  "requestParameters": {
    "clientToken": "14575ca1-1e9d-4c87-ae8f-9061d7369b61",
    "detectorId": "b4cf8aacc70423c0f45074ed90dd6596",
    "triggerPrompt": "Investigate finding 6284b9ced79340799b78b237804a8964"
  },
  "responseElements": {
    "__type": "InvalidInputException",
    "message": "The request is rejected because the Investigation API is not available in region ACCESS_DENIED.",
    "type": "InvalidInputException"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,n,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateMalwareProtectionPlan

#
Service
guardduty

Description

Creates a new Malware Protection plan for the protected resource.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "05f9e058-cdc8-4d3a-b6df-837c2d5bc6d0",
  "eventName": "CreateMalwareProtectionPlan",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T21:48:06Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "86584900-f2e3-405d-b52c-e138ca7746af",
  "requestParameters": {
    "clientToken": "176d5d60-1d81-44ee-ac8f-9a01cd6df4f5",
    "protectedResource": {
      "s3Bucket": {
        "bucketName": "dwfix-gd-93708318-20260629214658"
      }
    },
    "role": "arn:aws:iam::123456789012:role/dwfix-gd-mprot-20260629214658"
  },
  "responseElements": {
    "__type": "InvalidInputException",
    "message": "The request was rejected because the provided IAM role does not have the required S3 bucket notification permissions to verify and enable S3 EventBridge event delivery.",
    "type": "InvalidInputException"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,n,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateMembers

#
Service
guardduty

Description

Creates member accounts of the current Amazon Web Services account by specifying a list of Amazon Web Services account IDs.

CreatePublishingDestination

#
Service
guardduty

Description

Creates a publishing destination where you can export your GuardDuty findings.

CreateSampleFindings

#
Service
guardduty

Description

Generates sample findings of types specified by the list of finding types.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "645d40b6-dce8-4707-8e0a-fc0863fea7f5",
  "eventName": "CreateSampleFindings",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T21:47:20Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "4ed029b4-ff81-4689-b1c0-2ccea1158a0c",
  "requestParameters": {
    "detectorId": "b4cf8aacc70423c0f45074ed90dd6596",
    "findingTypes": [
      "Recon:EC2/PortProbeUnprotectedPort"
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,n,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateThreatEntitySet

#
Service
guardduty

Description

Creates a new threat entity set.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "cddc4c86-5abe-4810-a416-ba6f062123b4",
  "eventName": "CreateThreatEntitySet",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T21:47:11Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "dcf0d0dd-d3a2-4a92-abbd-20414de4416b",
  "requestParameters": {
    "activate": false,
    "clientToken": "6dedb0bc-4994-44c0-8828-1da221038993",
    "detectorId": "b4cf8aacc70423c0f45074ed90dd6596",
    "format": "TXT",
    "location": "s3://dwfix-gd-93708318-20260629214658/threatentity.txt",
    "name": "dwfix-te-20260629214658"
  },
  "responseElements": {
    "threatEntitySetId": "131984d77b8542118632a68229764926"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,n,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateThreatIntelSet

#
Service
guardduty

Description

Creates a new ThreatIntelSet.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "6fcd1753-0126-4d1e-b834-64734be17441",
  "eventName": "CreateThreatIntelSet",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T21:47:09Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "2f830e0e-b656-4ebc-8725-87b23bb855f8",
  "requestParameters": {
    "activate": false,
    "clientToken": "1680d744-d14b-42f8-be4e-65fb74fa9c4f",
    "detectorId": "b4cf8aacc70423c0f45074ed90dd6596",
    "format": "TXT",
    "location": "s3://dwfix-gd-93708318-20260629214658/threatintel.txt",
    "name": "dwfix-ti-20260629214658"
  },
  "responseElements": {
    "threatIntelSetId": "8ecf8aacdb7eb624459e77b4a95877eb"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,n,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS GuardDuty Detection Suppression source high: Identifies attempts to suppress or blind Amazon GuardDuty without deleting the detector outright. Adversaries with GuardDuty permissions can create or update a trusted IP set (CreateIPSet/UpdateIPSet) so that traffic from listed addresses is never flagged, tamper with the threat intelligence feed used to generate findings (CreateThreatIntelSet/UpdateThreatIntelSet), or soft-disable the detector via UpdateDetector with Enable set to false. All three techniques leave the detector itself intact, evading detections that only look for detector deletion.T1562, T1562.001↳ also matches CreateIPSet, UpdateDetector, UpdateThreatIntelSet, UpdateIPSet

CreateTrustedEntitySet

#
Service
guardduty

Description

Creates a new trusted entity set.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "c30dfd88-7f0a-460f-836e-5d8b9d05c11d",
  "eventName": "CreateTrustedEntitySet",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T21:47:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "4598d75f-2ea5-4920-b20a-8c4974cdfc94",
  "requestParameters": {
    "activate": false,
    "clientToken": "4732c686-89e8-429a-80b4-ce463811f06e",
    "detectorId": "b4cf8aacc70423c0f45074ed90dd6596",
    "format": "TXT",
    "location": "s3://dwfix-gd-93708318-20260629214658/trustedentity.txt",
    "name": "dwfix-trs-20260629214658"
  },
  "responseElements": {
    "trustedEntitySetId": "f40980f48c504693b29c496f43e5ed01"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,n,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeclineInvitations

#
Service
guardduty

Description

Declines invitations sent to the current member account by Amazon Web Services accounts specified by their account IDs.

DeleteFilter

#
Service
guardduty

Description

Deletes the filter specified by the filter name.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "1fc59d07-b797-4c56-aafb-6b846271ef0a",
  "eventName": "DeleteFilter",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T19:24:32Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "b73811e1-f397-4ca7-8b78-c4f687ae6d46",
  "requestParameters": {
    "detectorId": "ddddd",
    "filterName": "dw-probe"
  },
  "responseElements": {
    "__type": "InvalidInputException",
    "message": "The request is rejected because the parameter detectorId has an invalid value.",
    "type": "InvalidInputException"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteIPSet

#
Service
guardduty

Description

Deletes the IPSet specified by the ipSetId.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "884dc529-d98f-4529-bfa1-8cdd6c06d02f",
  "eventName": "DeleteIPSet",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2022-07-26T23:14:57Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "111111111111",
  "requestID": "70d36916-4ce7-4b6e-9226-9da47d58d554",
  "requestParameters": {
    "detectorId": "11111",
    "ipSetId": "1111"
  },
  "responseElements": {
    "__type": "InvalidInputException",
    "message": "The request is rejected because the parameter detectorId has an invalid value."
  },
  "sourceIPAddress": "142.254.89.27",
  "userAgent": "aws-cli/2.0.62 Python/3.9.2 Darwin/21.5.0 source/x86_64 command/guardduty.delete-ip-set",
  "userIdentity": {
    "accessKeyId": "AKIAYTOGP2RLKQ3U2PDY",
    "accountId": "111111111111",
    "arn": "arn:aws:iam::111111111111:user/bhavin_cli",
    "principalId": "AIDAYTOGP2RLEHRX5YWNV",
    "type": "IAMUser",
    "userName": "bhavin_cli"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

References #

DeleteMalwareProtectionPlan

#
Service
guardduty

Description

Deletes the Malware Protection plan ID associated with the Malware Protection plan resource.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "e939ec4a-5e22-4439-9de3-d43ebcb012c7",
  "eventName": "DeleteMalwareProtectionPlan",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T19:24:32Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "1d193e6c-84f4-4451-b9d0-b1ed16a50275",
  "requestParameters": {
    "malwareProtectionPlanId": "dw-probe"
  },
  "responseElements": {
    "__type": "InvalidInputException",
    "message": "The request is rejected because an invalid or out-of-range value is specified as an input parameter.",
    "type": "InvalidInputException"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteThreatEntitySet

#
Service
guardduty

Description

Deletes the threat entity set that is associated with the specified threatEntitySetId.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "d38ee750-736f-4314-8666-58fff25ce2ad",
  "eventName": "DeleteThreatEntitySet",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T19:24:33Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "3859fd19-a3ca-47c8-95c3-297ec5c7b47d",
  "requestParameters": {
    "detectorId": "ddddd",
    "threatEntitySetId": "dw-probe"
  },
  "responseElements": {
    "__type": "InvalidInputException",
    "message": "The request is rejected because the parameter detectorId has an invalid value.",
    "type": "InvalidInputException"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteTrustedEntitySet

#
Service
guardduty

Description

Deletes the trusted entity set that is associated with the specified trustedEntitySetId.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "4fd89a1d-486b-4e01-98f2-f1fe92fa1b58",
  "eventName": "DeleteTrustedEntitySet",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T19:24:34Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "1972df45-2170-42e6-8acf-97dc537ccf2b",
  "requestParameters": {
    "detectorId": "ddddd",
    "trustedEntitySetId": "dw-probe"
  },
  "responseElements": {
    "__type": "InvalidInputException",
    "message": "The request is rejected because the parameter detectorId has an invalid value.",
    "type": "InvalidInputException"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeMalwareScans

#
Service
guardduty

Description

Returns a list of malware scans.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "e90d7eb8-2ff6-4de4-b606-f279c94d746a",
  "eventName": "DescribeMalwareScans",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T18:44:29Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "27aaf42c-2505-421c-bdab-e1e43705730a",
  "requestParameters": {
    "detectorId": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeOrganizationConfiguration

#
Service
guardduty

Description

Returns information about the account selected as the delegated administrator for GuardDuty.

Example CloudTrail Event #

{
  "awsRegion": "us-east-2",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "657a9a9a-e28e-4361-af54-d195f812257c",
  "eventName": "DescribeOrganizationConfiguration",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2021-07-07T13:20:59Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "797507667711",
  "requestID": "91cbf893-cd88-4dc8-a6c5-4c510cacc3bb",
  "requestParameters": {
    "detectorId": "68bd40905393a0a5aa40bbec31f1af0a"
  },
  "responseElements": null,
  "sourceIPAddress": "213.205.197.162",
  "userAgent": "aws-internal/3 aws-sdk-java/1.11.1030 Linux/5.4.116-64.217.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.292-b10 java/1.8.0_292 vendor/Oracle_Corporation cfg/retry-mode/legacy",
  "userIdentity": {
    "accessKeyId": "ASIA3TLZJI375VVUVWIG",
    "accountId": "797507667711",
    "arn": "arn:aws:iam::797507667711:user/bruce",
    "principalId": "AIDA3TLZJI372XH6M2Q25",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-07-07T11:45:11Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bruce"
  }
}

References #

DescribePublishingDestination

#
Service
guardduty

Description

Returns information about the publishing destination specified by the provided destinationId.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "e07e840d-84dc-407e-8b1b-e195af49acbf",
  "eventName": "DescribePublishingDestination",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T18:44:29Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "5641bd1e-3f79-4d6b-a37a-ecd36fc5a440",
  "requestParameters": {
    "destinationId": "dw-probe",
    "detectorId": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisableOrganizationAdminAccount

#
Service
guardduty

Description

Removes the existing GuardDuty delegated administrator of the organization.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "8aac0f81-2260-474f-a2da-386eca2fafd0",
  "eventName": "DisableOrganizationAdminAccount",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T19:24:34Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "c5b7d593-cb6c-4892-ac36-448dabec1dfd",
  "requestParameters": {
    "adminAccountId": "dw-probe"
  },
  "responseElements": {
    "__type": "InvalidInputException",
    "message": "The request failed because the 'accountId' was formatted incorrectly.",
    "type": "InvalidInputException"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisassociateFromMasterAccount

#
Service
guardduty

Description

Disassociates the current GuardDuty member account from its administrator account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "75cdfc1d-d1ac-47aa-8b1f-c7a876b32dc9",
  "eventName": "DisassociateFromMasterAccount",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T19:24:34Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "101d3db8-c936-4b22-94fc-85068c8b5a23",
  "requestParameters": {
    "detectorId": "ddddd"
  },
  "responseElements": {
    "__type": "InvalidInputException",
    "message": "The request is rejected because the parameter detectorId has an invalid value.",
    "type": "InvalidInputException"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

EnableOrganizationAdminAccount

#
Service
guardduty

Description

Designates an Amazon Web Services account within the organization as your GuardDuty delegated administrator.

GetAdministratorAccount

#
Service
guardduty

Description

Provides the details of the GuardDuty administrator account associated with the current GuardDuty member account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "3d1fbc63-76fd-4dc3-9268-d60f6aa42922",
  "eventName": "GetAdministratorAccount",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T18:44:29Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "ad894af6-5a16-4c5b-a6dc-1f3b2b16849a",
  "requestParameters": {
    "detectorId": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetCoverageStatistics

#
Service
guardduty

Description

Retrieves aggregated statistics for your account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "b731e337-2dc1-477c-9b20-573b675d23d6",
  "eventName": "GetCoverageStatistics",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T18:44:29Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "c22a274c-48cf-43b5-8679-f6151522c2dc",
  "requestParameters": {
    "detectorId": "ddddd",
    "statisticsType": [
      "COUNT_BY_RESOURCE_TYPE"
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetDetector

#
Service
guardduty

Description

Retrieves a GuardDuty detector specified by the detectorId.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "3c13a8db-cbdf-431f-bdff-bf3dc049d04c",
  "eventName": "GetDetector",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2023-07-10T12:28:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "90fcd013-eb6d-4fcd-b36c-6ff36f630e67",
  "requestParameters": {
    "detectorId": "6ec1aa76c9c3020a93af9e89a5a3a439"
  },
  "responseElements": null,
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "RDS Console, aws-internal/3 aws-sdk-java/1.11.975 Linux/5.10.184-153.731.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.242-b08 java/1.8.0_242 vendor/Oracle_Corporation cfg/retry-mode/legacy",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCS5BLNV76",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:27:45Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

GetFilter

#
Service
guardduty

Description

Returns the details of the filter specified by the filter name.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "8e33a58d-2254-41ee-b6e5-d844c60f780f",
  "eventName": "GetFilter",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T18:44:29Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "fc76edb9-90b2-4778-b32c-c201b9f0492e",
  "requestParameters": {
    "detectorId": "ddddd",
    "filterName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetFindings

#
Service
guardduty

Description

Describes Amazon GuardDuty findings specified by finding IDs.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "e0a43cd4-98ee-42af-ad29-e132f3be0e91",
  "eventName": "GetFindings",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2023-07-10T12:28:29Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "aead15d4-b208-4341-b4ec-65a96227161d",
  "requestParameters": {
    "detectorId": "6ec1aa76c9c3020a93af9e89a5a3a439",
    "findingIds": []
  },
  "responseElements": null,
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "RDS Console, aws-internal/3 aws-sdk-java/1.11.975 Linux/5.10.184-153.731.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.242-b08 java/1.8.0_242 vendor/Oracle_Corporation cfg/retry-mode/legacy",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCS5BLNV76",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:27:45Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

GetFindingsStatistics

#
Service
guardduty

Description

Lists GuardDuty findings statistics for the specified detector ID.

Example CloudTrail Event #

{
  "awsRegion": "us-east-2",
  "eventCategory": "Management",
  "eventID": "e12fbff5-675c-4375-9ec0-eeb66a50eda4",
  "eventName": "GetFindingsStatistics",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2021-07-07T13:21:09Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "797507667711",
  "requestID": "560cb49a-f6f9-45d6-83df-ad0583a46496",
  "requestParameters": {
    "detectorId": "68bd40905393a0a5aa40bbec31f1af0a",
    "findingCriteria": {
      "criterion": {
        "service.archived": {
          "eq": [
            false,
            false
          ]
        }
      }
    },
    "findingStatisticTypes": [
      "COUNT_BY_SEVERITY"
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "213.205.197.162",
  "userAgent": "aws-internal/3 aws-sdk-java/1.11.1030 Linux/5.4.116-64.217.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.292-b10 java/1.8.0_292 vendor/Oracle_Corporation cfg/retry-mode/legacy",
  "userIdentity": {
    "accessKeyId": "ASIA3TLZJI375VVUVWIG",
    "accountId": "797507667711",
    "arn": "arn:aws:iam::797507667711:user/bruce",
    "principalId": "AIDA3TLZJI372XH6M2Q25",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-07-07T11:45:11Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bruce"
  }
}

References #

GetInvestigation

#
Service
guardduty

Description

This API is currently available as a preview.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "c4d0433c-c779-4343-954b-854e504cbad0",
  "eventName": "GetInvestigation",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T18:44:29Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "c1a913fe-ed6f-4428-a4f4-51e640935a96",
  "requestParameters": {
    "detectorId": "ddddd",
    "investigationId": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetInvitationsCount

#
Service
guardduty

Description

Returns the count of all GuardDuty membership invitations that were sent to the current member account except the currently accepted invitation.

Example CloudTrail Event #

{
  "awsRegion": "us-east-2",
  "eventCategory": "Management",
  "eventID": "49527f70-53c3-42e9-a698-c6db5b794331",
  "eventName": "GetInvitationsCount",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2021-07-07T13:21:08Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "797507667711",
  "requestID": "0c4edd21-341a-470d-9b59-19c890961047",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "213.205.197.162",
  "userAgent": "aws-internal/3 aws-sdk-java/1.11.1030 Linux/5.4.116-64.217.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.292-b10 java/1.8.0_292 vendor/Oracle_Corporation cfg/retry-mode/legacy",
  "userIdentity": {
    "accessKeyId": "ASIA3TLZJI375VVUVWIG",
    "accountId": "797507667711",
    "arn": "arn:aws:iam::797507667711:user/bruce",
    "principalId": "AIDA3TLZJI372XH6M2Q25",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-07-07T11:45:11Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bruce"
  }
}

References #

GetIPSet

#
Service
guardduty

Description

Retrieves the IPSet specified by the ipSetId.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "2c87c340-7b10-42cf-900e-d8ca0e7546c3",
  "eventName": "GetIPSet",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T18:44:29Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "ff2abb2a-83aa-4f5c-ac47-5bb394570078",
  "requestParameters": {
    "detectorId": "ddddd",
    "ipSetId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetMalwareProtectionPlan

#
Service
guardduty

Description

Retrieves the Malware Protection plan details associated with a Malware Protection plan ID.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "a7b79457-4339-4ce2-9623-06e75bf2675d",
  "eventName": "GetMalwareProtectionPlan",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T18:44:29Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "a7ecbad0-fd20-4781-b781-b1cdf1789ee7",
  "requestParameters": {
    "malwareProtectionPlanId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetMalwareScan

#
Service
guardduty

Description

Retrieves the detailed information for a specific malware scan.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "35aeff19-07b8-40d2-93a3-a19bcf74d41b",
  "eventName": "GetMalwareScan",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T18:44:29Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "74104690-1b07-43c3-909c-09bb8138f7b9",
  "requestParameters": {
    "scanId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetMalwareScanSettings

#
Service
guardduty

Description

Returns the details of the malware scan settings.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "ed395bec-0ba2-497d-952d-acdf9f097154",
  "eventName": "GetMalwareScanSettings",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T18:44:29Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "f8ae7cbf-70af-44e9-af5d-97c4594f91fe",
  "requestParameters": {
    "detectorId": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetMasterAccount

#
Service
guardduty

Description

Provides the details for the GuardDuty administrator account associated with the current GuardDuty member account.

Example CloudTrail Event #

{
  "awsRegion": "us-east-2",
  "eventCategory": "Management",
  "eventID": "b256e96b-7fe9-45a4-8058-22742b05b44d",
  "eventName": "GetMasterAccount",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2021-07-07T13:21:02Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "797507667711",
  "requestID": "22f53f5c-0def-41e0-ae70-2d6d0b94e887",
  "requestParameters": {
    "detectorId": "68bd40905393a0a5aa40bbec31f1af0a"
  },
  "responseElements": null,
  "sourceIPAddress": "213.205.197.162",
  "userAgent": "aws-internal/3 aws-sdk-java/1.11.1030 Linux/5.4.116-64.217.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.292-b10 java/1.8.0_292 vendor/Oracle_Corporation cfg/retry-mode/legacy",
  "userIdentity": {
    "accessKeyId": "ASIA3TLZJI375VVUVWIG",
    "accountId": "797507667711",
    "arn": "arn:aws:iam::797507667711:user/bruce",
    "principalId": "AIDA3TLZJI372XH6M2Q25",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-07-07T11:45:11Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bruce"
  }
}

References #

GetMemberDetectors

#
Service
guardduty

Description

Describes which data sources are enabled for the member account's detector.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "1eb1712d-7295-42ea-b2e8-74b8b46eade9",
  "eventName": "GetMemberDetectors",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T18:44:29Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "7eb3fd59-0724-4d79-8f56-2298e427327a",
  "requestParameters": {
    "accountIds": [
      "dddddddddddd"
    ],
    "detectorId": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetMembers

#
Service
guardduty

Description

Retrieves GuardDuty member accounts (of the current GuardDuty administrator account) specified by the account IDs.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "64ae35cf-4eee-48d1-8cee-bf29f7d25c48",
  "eventName": "GetMembers",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T18:44:29Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "155d0f4a-45a9-4808-bc0b-a2c2c6dfbd21",
  "requestParameters": {
    "accountIds": [
      "dddddddddddd"
    ],
    "detectorId": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetOrganizationStatistics

#
Service
guardduty

Description

Retrieves how many active member accounts have each feature enabled within GuardDuty.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "4b166202-5fa9-4afb-aec1-5fe7d3c7944a",
  "eventName": "GetOrganizationStatistics",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T18:32:16Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "96b2a765-929a-45ac-8d58-7794aeaed5af",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetRemainingFreeTrialDays

#
Service
guardduty

Description

Provides the number of days left for each data source used in the free trial period.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "64ba3a4b-bd96-4702-a784-ec86c2c18110",
  "eventName": "GetRemainingFreeTrialDays",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T18:44:29Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "d3f33e14-7005-446a-9b56-b9d59244cd6b",
  "requestParameters": {
    "accountIds": [
      "dddddddddddd"
    ],
    "detectorId": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetThreatEntitySet

#
Service
guardduty

Description

Retrieves the threat entity set associated with the specified threatEntitySetId.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "965deff0-8e0a-4eed-9066-aecc506d2bc5",
  "eventName": "GetThreatEntitySet",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T18:44:30Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "1b9226c6-ddb1-4943-9360-c04da502526c",
  "requestParameters": {
    "detectorId": "ddddd",
    "threatEntitySetId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetThreatIntelSet

#
Service
guardduty

Description

Retrieves the ThreatIntelSet that is specified by the ThreatIntelSet ID.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "ff822b8f-9929-4b92-9c2f-363b20ddb51d",
  "eventName": "GetThreatIntelSet",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T18:44:31Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "d73be009-1897-4062-baa4-38b95c3808fd",
  "requestParameters": {
    "detectorId": "ddddd",
    "threatIntelSetId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetTrustedEntitySet

#
Service
guardduty

Description

Retrieves the trusted entity set associated with the specified trustedEntitySetId.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "38a1475c-d59b-4ad9-8fde-3b4d356630ab",
  "eventName": "GetTrustedEntitySet",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T18:44:31Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "26269101-6c7c-45dd-a874-5857126f8d26",
  "requestParameters": {
    "detectorId": "ddddd",
    "trustedEntitySetId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetUsageStatistics

#
Service
guardduty

Description

Lists Amazon GuardDuty usage statistics over the last 30 days for the specified detector ID.

Example CloudTrail Event #

{
  "awsRegion": "us-east-2",
  "eventCategory": "Management",
  "eventID": "32a32184-235f-4621-aa64-552002a16c7a",
  "eventName": "GetUsageStatistics",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2021-07-07T13:20:45Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "797507667711",
  "requestID": "bad0a20d-3115-41c1-822e-e0c3b1b389bb",
  "requestParameters": {
    "detectorId": "68bd40905393a0a5aa40bbec31f1af0a",
    "maxResults": 6,
    "usageCriteria": {
      "dataSources": [
        "S3_LOGS"
      ]
    },
    "usageStatisticsType": "TOP_RESOURCES"
  },
  "responseElements": null,
  "sourceIPAddress": "213.205.197.162",
  "userAgent": "aws-internal/3 aws-sdk-java/1.11.1030 Linux/5.4.116-64.217.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.292-b10 java/1.8.0_292 vendor/Oracle_Corporation cfg/retry-mode/legacy",
  "userIdentity": {
    "accessKeyId": "ASIA3TLZJI375VVUVWIG",
    "accountId": "797507667711",
    "arn": "arn:aws:iam::797507667711:user/bruce",
    "principalId": "AIDA3TLZJI372XH6M2Q25",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-07-07T11:45:11Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bruce"
  }
}

References #

InviteMembers

#
Service
guardduty

Description

Invites Amazon Web Services accounts to become members of an organization administered by the Amazon Web Services account that invokes this API.

ListCoverage

#
Service
guardduty

Description

Lists coverage details for your GuardDuty account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "83fa5f78-9346-4941-a61d-8ff468ca16cf",
  "eventName": "ListCoverage",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T18:44:31Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "b24884e6-4bb2-4b4f-95b7-bb05c28be0f3",
  "requestParameters": {
    "detectorId": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListDetectors

#
Service
guardduty

Description

Lists detectorIds of all the existing Amazon GuardDuty detector resources.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "f7a5aa5b-75ca-4c02-b3f2-f4945ccab547",
  "eventName": "ListDetectors",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2023-07-10T12:28:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "f75eaa1e-7b9b-4e3e-8545-706a3fa60f66",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "RDS Console, aws-internal/3 aws-sdk-java/1.11.975 Linux/5.10.184-153.731.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.242-b08 java/1.8.0_242 vendor/Oracle_Corporation cfg/retry-mode/legacy",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCS5BLNV76",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:27:45Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

ListFilters

#
Service
guardduty

Description

Returns a paginated list of the current filters.

Example CloudTrail Event #

{
  "awsRegion": "us-east-2",
  "eventCategory": "Management",
  "eventID": "3f88e11e-3890-4205-b215-cfbdf0e004a3",
  "eventName": "ListFilters",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2021-07-07T13:21:08Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "797507667711",
  "requestID": "e181823e-abd4-4f2e-8f54-d6aecbe1c33e",
  "requestParameters": {
    "detectorId": "68bd40905393a0a5aa40bbec31f1af0a",
    "maxResults": "50"
  },
  "responseElements": null,
  "sourceIPAddress": "213.205.197.162",
  "userAgent": "aws-internal/3 aws-sdk-java/1.11.1030 Linux/5.4.116-64.217.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.292-b10 java/1.8.0_292 vendor/Oracle_Corporation cfg/retry-mode/legacy",
  "userIdentity": {
    "accessKeyId": "ASIA3TLZJI375VVUVWIG",
    "accountId": "797507667711",
    "arn": "arn:aws:iam::797507667711:user/bruce",
    "principalId": "AIDA3TLZJI372XH6M2Q25",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-07-07T11:45:11Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bruce"
  }
}

References #

ListFindings

#
Service
guardduty

Description

Lists GuardDuty findings for the specified detector ID.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "5ea74f78-9511-4c09-8834-69a33df4d5ae",
  "eventName": "ListFindings",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2023-07-10T12:28:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "f3147dd6-c804-483c-bd38-532dab01ec04",
  "requestParameters": {
    "detectorId": "6ec1aa76c9c3020a93af9e89a5a3a439",
    "findingCriteria": {
      "criterion": {
        "resource.resourceType": {
          "eq": [
            "RDSDBInstance"
          ]
        },
        "updatedAt": {
          "greaterThanOrEqual": 1688905708576
        }
      }
    }
  },
  "responseElements": null,
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "RDS Console, aws-internal/3 aws-sdk-java/1.11.975 Linux/5.4.247-168.349.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.242-b08 java/1.8.0_242 vendor/Oracle_Corporation cfg/retry-mode/legacy",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCS5BLNV76",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:27:45Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

ListInvestigations

#
Service
guardduty

Description

This API is currently available as a preview.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "ff0e97c7-844c-4195-9c64-ffaaba05aa82",
  "eventName": "ListInvestigations",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T18:44:31Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "7717b38a-d000-4170-a216-61a36279ad9a",
  "requestParameters": {
    "detectorId": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListInvitations

#
Service
guardduty

Description

Lists all GuardDuty membership invitations that were sent to the current Amazon Web Services account.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "3dbb1e74-39af-4c13-a702-c64dd757c98c",
  "eventName": "ListInvitations",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2018-10-17T20:15:05Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "readOnly": true,
  "recipientAccountId": "811596193553",
  "requestID": "561f7da3-d249-11e8-8afa-9531e20ec550",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "9.245.1.85",
  "userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

ListIPSets

#
Service
guardduty

Description

Lists the IPSets of the GuardDuty service specified by the detector ID.

Example CloudTrail Event #

{
  "awsRegion": "us-east-2",
  "eventCategory": "Management",
  "eventID": "d4dfdc6d-b830-477a-81dd-d61d3fe274fd",
  "eventName": "ListIPSets",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2021-07-07T13:20:53Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "797507667711",
  "requestID": "d02ed4f5-2619-4dc1-bb5b-1a6ee13419c2",
  "requestParameters": {
    "detectorId": "68bd40905393a0a5aa40bbec31f1af0a",
    "maxResults": "10"
  },
  "responseElements": null,
  "sourceIPAddress": "213.205.197.162",
  "userAgent": "aws-internal/3 aws-sdk-java/1.11.1030 Linux/5.4.116-64.217.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.292-b10 java/1.8.0_292 vendor/Oracle_Corporation cfg/retry-mode/legacy",
  "userIdentity": {
    "accessKeyId": "ASIA3TLZJI375VVUVWIG",
    "accountId": "797507667711",
    "arn": "arn:aws:iam::797507667711:user/bruce",
    "principalId": "AIDA3TLZJI372XH6M2Q25",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-07-07T11:45:11Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bruce"
  }
}

References #

ListMalwareProtectionPlans

#
Service
guardduty

Description

Lists the Malware Protection plan IDs associated with the protected resources in your Amazon Web Services account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "31a05b9a-d517-445a-ae3b-d3d06dd08217",
  "eventName": "ListMalwareProtectionPlans",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T18:32:16Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "a7b49736-d0b6-4945-b457-5f410497f9e9",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListMalwareScans

#
Service
guardduty

Description

Returns a list of malware scans.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "6a3a5c03-44b3-41d4-ac9a-548497570de3",
  "eventName": "ListMalwareScans",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T18:32:16Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "8f466861-7765-4377-b8ee-36f909a30321",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListMembers

#
Service
guardduty

Description

Lists details about all member accounts for the current GuardDuty administrator account.

Example CloudTrail Event #

{
  "awsRegion": "us-east-2",
  "eventCategory": "Management",
  "eventID": "b517874a-7025-46c2-80d2-86ad6db5016f",
  "eventName": "ListMembers",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2021-07-07T13:21:02Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "797507667711",
  "requestID": "7f35d686-e26e-4311-a258-3a7d24261183",
  "requestParameters": {
    "detectorId": "68bd40905393a0a5aa40bbec31f1af0a",
    "maxResults": "50",
    "onlyAssociated": "false"
  },
  "responseElements": null,
  "sourceIPAddress": "213.205.197.162",
  "userAgent": "aws-internal/3 aws-sdk-java/1.11.1030 Linux/5.4.116-64.217.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.292-b10 java/1.8.0_292 vendor/Oracle_Corporation cfg/retry-mode/legacy",
  "userIdentity": {
    "accessKeyId": "ASIA3TLZJI375VVUVWIG",
    "accountId": "797507667711",
    "arn": "arn:aws:iam::797507667711:user/bruce",
    "principalId": "AIDA3TLZJI372XH6M2Q25",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-07-07T11:45:11Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bruce"
  }
}

References #

ListOrganizationAdminAccounts

#
Service
guardduty

Description

Lists the accounts designated as GuardDuty delegated administrators.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "eventID": "8c7b7ea0-cdc4-4bdc-a66e-834d8ecd93ae",
  "eventName": "ListOrganizationAdminAccounts",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2020-06-10T05:32:29Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "readOnly": true,
  "recipientAccountId": "811596193553",
  "requestID": "560c8608-242b-4256-b2f2-dea341a6662f",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "251.105.254.1",
  "userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

ListPublishingDestinations

#
Service
guardduty

Description

Returns a list of publishing destinations associated with the specified detectorId.

Example CloudTrail Event #

{
  "awsRegion": "us-east-2",
  "eventCategory": "Management",
  "eventID": "9457e0b9-7877-41cf-b3a0-85e3c2aece6a",
  "eventName": "ListPublishingDestinations",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2021-07-07T13:21:08Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "797507667711",
  "requestID": "03ff54ac-a19c-46e6-8075-f529bf045a08",
  "requestParameters": {
    "detectorId": "68bd40905393a0a5aa40bbec31f1af0a"
  },
  "responseElements": null,
  "sourceIPAddress": "213.205.197.162",
  "userAgent": "aws-internal/3 aws-sdk-java/1.11.1030 Linux/5.4.116-64.217.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.292-b10 java/1.8.0_292 vendor/Oracle_Corporation cfg/retry-mode/legacy",
  "userIdentity": {
    "accessKeyId": "ASIA3TLZJI375VVUVWIG",
    "accountId": "797507667711",
    "arn": "arn:aws:iam::797507667711:user/bruce",
    "principalId": "AIDA3TLZJI372XH6M2Q25",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-07-07T11:45:11Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bruce"
  }
}

References #

ListTagsForResource

#
Service
guardduty

Description

Lists tags for a resource.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "9ec6b099-aa8b-4452-842d-dc1c97e7cc6b",
  "eventName": "ListTagsForResource",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T18:44:31Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "6cdbc116-629f-4ede-96e6-175cc4846c8c",
  "requestParameters": {
    "resourceArn": "arn:aws:iam::123456789012:role/dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListThreatEntitySets

#
Service
guardduty

Description

Lists the threat entity sets associated with the specified GuardDuty detector ID.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "5d6705e7-4246-4397-a50a-05b0f9c9c1ec",
  "eventName": "ListThreatEntitySets",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T18:44:31Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "4539ea52-a4aa-43ed-a95d-eda1dedbbead",
  "requestParameters": {
    "detectorId": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListThreatIntelSets

#
Service
guardduty

Description

Lists the ThreatIntelSets of the GuardDuty service specified by the detector ID.

Example CloudTrail Event #

{
  "awsRegion": "us-east-2",
  "eventCategory": "Management",
  "eventID": "5e5fe12f-4df6-4fff-baf7-3f1a5a7c72c7",
  "eventName": "ListThreatIntelSets",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2021-07-07T13:20:53Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "797507667711",
  "requestID": "53f90def-51d0-456f-9dd0-0fe5a44690bc",
  "requestParameters": {
    "detectorId": "68bd40905393a0a5aa40bbec31f1af0a",
    "maxResults": "10"
  },
  "responseElements": null,
  "sourceIPAddress": "213.205.197.162",
  "userAgent": "aws-internal/3 aws-sdk-java/1.11.1030 Linux/5.4.116-64.217.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.292-b10 java/1.8.0_292 vendor/Oracle_Corporation cfg/retry-mode/legacy",
  "userIdentity": {
    "accessKeyId": "ASIA3TLZJI375VVUVWIG",
    "accountId": "797507667711",
    "arn": "arn:aws:iam::797507667711:user/bruce",
    "principalId": "AIDA3TLZJI372XH6M2Q25",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-07-07T11:45:11Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bruce"
  }
}

References #

ListTrustedEntitySets

#
Service
guardduty

Description

Lists the trusted entity sets associated with the specified GuardDuty detector ID.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "836d350d-23ad-4510-8e6a-cede98110336",
  "eventName": "ListTrustedEntitySets",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T18:44:31Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "ca3b8655-ccf6-4cd4-97b8-e1c56a5c4425",
  "requestParameters": {
    "detectorId": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

SendObjectMalwareScan

#
Service
guardduty

Description

Initiates a malware scan for a specific S3 object.

StartMalwareScan

#
Service
guardduty

Description

Initiates the malware scan.

StartMonitoringMembers

#
Service
guardduty

Description

Turns on GuardDuty monitoring of the specified member accounts.

TagResource

#
Service
guardduty

Description

Adds tags to a resource.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "0af9e7b6-b59a-4325-a6b4-215cfa892c0a",
  "eventName": "TagResource",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T21:47:37Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "366a9bb1-510d-48bc-82d7-03ab6a346098",
  "requestParameters": {
    "resourceArn": "arn:aws:guardduty:us-west-1:123456789012:detector/b4cf8aacc70423c0f45074ed90dd6596",
    "tags": {
      "dwfix-test": "gd"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,n,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UnarchiveFindings

#
Service
guardduty

Description

Unarchives GuardDuty findings specified by the findingIds.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "6ba96504-e9b5-453a-a9aa-01774e93dbd6",
  "eventName": "UnarchiveFindings",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T21:47:31Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "33f91e44-5851-425b-b89d-a6d949de10a6",
  "requestParameters": {
    "detectorId": "b4cf8aacc70423c0f45074ed90dd6596",
    "findingIds": [
      "6284b9ced79340799b78b237804a8964"
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,n,b,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UntagResource

#
Service
guardduty

Description

Removes tags from a resource.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "c1f7abb1-1884-4869-9899-2d3016a859ab",
  "eventName": "UntagResource",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T19:24:34Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "b20a6693-44f6-461c-9fd2-56ca1cc9f980",
  "requestParameters": {
    "resourceArn": "arn:aws:iam::123456789012:role/dw-probe",
    "tagKeys": "ddddd"
  },
  "responseElements": {
    "message": "Invalid input resource arn: expected vendor guardduty"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateFilter

#
Service
guardduty

Description

Updates the filter specified by the filter name.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "7c0e881c-5fd5-4985-b012-02e2269d887b",
  "eventName": "UpdateFilter",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T19:24:34Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "2543428e-1c19-4c12-a497-6bcb0c89655b",
  "requestParameters": {
    "detectorId": "ddddd",
    "filterName": "dw-probe"
  },
  "responseElements": {
    "__type": "InvalidInputException",
    "message": "The request is rejected because the parameter detectorId has an invalid value.",
    "type": "InvalidInputException"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateFindingsFeedback

#
Service
guardduty

Description

Marks the specified GuardDuty findings as useful or not useful.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "8517b2cd-446b-4cd0-b6f5-a8bd2b4f0384",
  "eventName": "UpdateFindingsFeedback",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T19:24:34Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "67460748-c313-4ffd-ac2d-c4a933e3630c",
  "requestParameters": {
    "detectorId": "ddddd",
    "feedback": "USEFUL",
    "findingIds": [
      "ddddd"
    ]
  },
  "responseElements": {
    "__type": "InvalidInputException",
    "message": "The request is rejected because the parameter detectorId has an invalid value.",
    "type": "InvalidInputException"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateIPSet

#
Service
guardduty

Description

Updates the IPSet specified by the IPSet ID.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "c27389e7-ccb4-4361-9e83-c6314f6c3e30",
  "eventName": "UpdateIPSet",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T19:24:34Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "e8edbf22-ab42-4b62-9717-5156dbf44e12",
  "requestParameters": {
    "detectorId": "ddddd",
    "ipSetId": "dw-probe"
  },
  "responseElements": {
    "__type": "InvalidInputException",
    "message": "The request is rejected because the parameter detectorId has an invalid value.",
    "type": "InvalidInputException"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS GuardDuty Detection Suppression source high: Identifies attempts to suppress or blind Amazon GuardDuty without deleting the detector outright. Adversaries with GuardDuty permissions can create or update a trusted IP set (CreateIPSet/UpdateIPSet) so that traffic from listed addresses is never flagged, tamper with the threat intelligence feed used to generate findings (CreateThreatIntelSet/UpdateThreatIntelSet), or soft-disable the detector via UpdateDetector with Enable set to false. All three techniques leave the detector itself intact, evading detections that only look for detector deletion.T1562, T1562.001↳ also matches CreateIPSet, UpdateDetector, UpdateThreatIntelSet, CreateThreatIntelSet

Panther #

UpdateMalwareProtectionPlan

#
Service
guardduty

Description

Updates an existing Malware Protection plan resource.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "f388af2c-0e58-4738-9e83-62e945959754",
  "eventName": "UpdateMalwareProtectionPlan",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T19:24:34Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "617c5e04-e333-411e-afa4-aba44c6fdfdd",
  "requestParameters": {
    "malwareProtectionPlanId": "dw-probe"
  },
  "responseElements": {
    "__type": "InvalidInputException",
    "message": "The request is rejected because an invalid or out-of-range value is specified as an input parameter.",
    "type": "InvalidInputException"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateMalwareScanSettings

#
Service
guardduty

Description

Updates the malware scan settings.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "7b310caf-a72c-4b01-a0cd-ff585c87b928",
  "eventName": "UpdateMalwareScanSettings",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T19:24:34Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "a9d6a9bb-1fce-41fa-ad97-1b474090a974",
  "requestParameters": {
    "detectorId": "ddddd"
  },
  "responseElements": {
    "__type": "InvalidInputException",
    "message": "The request is rejected because the parameter detectorId has an invalid value.",
    "type": "InvalidInputException"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateMemberDetectors

#
Service
guardduty

Description

Contains information on member accounts to be updated.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "dfdd53e8-8c38-4496-9e2b-690ea6ff9729",
  "eventName": "UpdateMemberDetectors",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T19:24:35Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "1c9df014-ca0b-4a21-bc44-1a349b9778d3",
  "requestParameters": {
    "accountIds": [
      "dddddddddddd"
    ],
    "detectorId": "ddddd"
  },
  "responseElements": {
    "__type": "InvalidInputException",
    "message": "The request is rejected because the parameter detectorId has an invalid value.",
    "type": "InvalidInputException"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateOrganizationConfiguration

#
Service
guardduty

Description

Configures the delegated administrator account with the provided values.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "b5f53d37-e0e9-446e-8233-c36d26f75e54",
  "eventName": "UpdateOrganizationConfiguration",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T19:24:35Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "ab74f184-6eac-48d0-99d4-9a15a8faeb0f",
  "requestParameters": {
    "detectorId": "ddddd"
  },
  "responseElements": {
    "__type": "InvalidInputException",
    "message": "The request is rejected because the parameter detectorId has an invalid value.",
    "type": "InvalidInputException"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdatePublishingDestination

#
Service
guardduty

Description

Updates information about the publishing destination specified by the destinationId.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "63cf1832-b87d-4963-8b98-320e1acdb0e7",
  "eventName": "UpdatePublishingDestination",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T19:24:35Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "bcf85a8f-ad44-4366-8831-f7baca6daa53",
  "requestParameters": {
    "destinationId": "dw-probe",
    "detectorId": "ddddd"
  },
  "responseElements": {
    "__type": "InvalidInputException",
    "message": "The request is rejected because an invalid or out-of-range value is specified as an input parameter.",
    "type": "InvalidInputException"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateThreatEntitySet

#
Service
guardduty

Description

Updates the threat entity set associated with the specified threatEntitySetId.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "626150a3-e80c-40e9-bab5-8baaf28fa5ee",
  "eventName": "UpdateThreatEntitySet",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T19:24:36Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "2efbeb5e-bd58-4ba8-b976-72907746f350",
  "requestParameters": {
    "detectorId": "ddddd",
    "threatEntitySetId": "dw-probe"
  },
  "responseElements": {
    "__type": "InvalidInputException",
    "message": "The request is rejected because the parameter detectorId has an invalid value.",
    "type": "InvalidInputException"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateTrustedEntitySet

#
Service
guardduty

Description

Updates the trusted entity set associated with the specified trustedEntitySetId.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "BadRequestException",
  "eventCategory": "Management",
  "eventID": "cb96e170-c4b2-4719-a956-dfabd35b2e54",
  "eventName": "UpdateTrustedEntitySet",
  "eventSource": "guardduty.amazonaws.com",
  "eventTime": "2026-06-29T19:24:37Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "de001375-fb69-4ad7-9a84-d46ec1b8beac",
  "requestParameters": {
    "detectorId": "ddddd",
    "trustedEntitySetId": "dw-probe"
  },
  "responseElements": {
    "__type": "InvalidInputException",
    "message": "The request is rejected because the parameter detectorId has an invalid value.",
    "type": "InvalidInputException"
  },
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}