AWS Shield

eventNameDescriptionSampleRule
anyCatch-all entry for AWS Shield rules that match the service but not a specific eventName.NN
AssociateDRTLogBucketAuthorizes the Shield Response Team (SRT) to access the specified Amazon S3 bucket containing log data such as Application Load Balancer access logs, CloudFront logs, or logs from third party sources. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
AssociateDRTRoleAuthorizes the Shield Response Team (SRT) using the specified role, to access your Amazon Web Services account to assist with DDoS attack mitigation during potential attacks. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
AssociateHealthCheckAdds health-based detection to the Shield Advanced protection for a resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
AssociateProactiveEngagementDetailsInitializes proactive engagement and sets the list of contacts for the Shield Response Team (SRT) to use. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateProtectionEnables Shield Advanced for a specific Amazon Web Services resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateProtectionGroupCreates a grouping of protected resources so they can be handled as a collective. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateSubscriptionActivates Shield Advanced for an account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteProtectionDeletes an Shield Advanced Protection. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteProtectionGroupRemoves the specified protection group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteSubscriptionRemoves Shield Advanced from an account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeAttackDescribes the details of a DDoS attack. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeAttackStatisticsProvides information about the number and type of attacks Shield has detected in the last year for all resources that belong to your account, regardless of whether you've defined Shield protections for them. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeDRTAccessReturns the current role and list of Amazon S3 log buckets used by the Shield Response Team (SRT) to access your Amazon Web Services account while assisting with attack mitigation. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeEmergencyContactSettingsA list of email addresses and phone numbers that the Shield Response Team (SRT) can use to contact you if you have proactive engagement enabled, for escalations to the SRT and to initiate proactive customer support.YN
DescribeProtectionLists the details of a Protection object. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeProtectionGroupReturns the specification for the specified protection group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeSubscriptionProvides details about the Shield Advanced subscription for an account.YN
DisableApplicationLayerAutomaticResponseDisable the Shield Advanced automatic application layer DDoS mitigation feature for the protected resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DisableProactiveEngagementRemoves authorization from the Shield Response Team (SRT) to notify contacts about escalations to the SRT and to initiate proactive customer support. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DisassociateDRTLogBucketRemoves the Shield Response Team's (SRT) access to the specified Amazon S3 bucket containing the logs that you shared previously. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DisassociateDRTRoleRemoves the Shield Response Team's (SRT) access to your Amazon Web Services account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DisassociateHealthCheckRemoves health-based detection from the Shield Advanced protection for a resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
EnableApplicationLayerAutomaticResponseEnable the Shield Advanced automatic application layer DDoS mitigation for the protected resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
EnableProactiveEngagementAuthorizes the Shield Response Team (SRT) to use email and phone to notify contacts about escalations to the SRT and to initiate proactive customer support. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetSubscriptionStateReturns the SubscriptionState, either Active or Inactive. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListAttacksReturns all ongoing DDoS attacks or all DDoS attacks during a specified time period. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListProtectionGroupsRetrieves ProtectionGroup objects for the account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListProtectionsRetrieves Protection objects for the account.YN
ListResourcesInProtectionGroupRetrieves the resources that are included in the protection group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListTagsForResourceGets information about Amazon Web Services tags for a specified Amazon Resource Name (ARN) in Shield. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
TagResourceAdds or updates tags for a resource in Shield. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UntagResourceRemoves tags from a resource in Shield. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateApplicationLayerAutomaticResponseUpdates an existing Shield Advanced automatic application layer DDoS mitigation configuration for the specified resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateEmergencyContactSettingsUpdates the details of the list of email addresses and phone numbers that the Shield Response Team (SRT) can use to contact you if you have proactive engagement enabled, for escalations to the SRT and to initiate proactive customer support. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateProtectionGroupUpdates an existing protection group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateSubscriptionUpdates the details of an existing subscription. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN

any: AWS Shield (catch-all)

#
Service
shield

Description

Catch-all entry for AWS Shield rules that match the service but not a specific eventName.

AssociateDRTLogBucket

#
Service
shield

Description

Authorizes the Shield Response Team (SRT) to access the specified Amazon S3 bucket containing log data such as Application Load Balancer access logs, CloudFront logs, or logs from third party sources. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

AssociateDRTRole

#
Service
shield

Description

Authorizes the Shield Response Team (SRT) using the specified role, to access your Amazon Web Services account to assist with DDoS attack mitigation during potential attacks. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

AssociateHealthCheck

#
Service
shield

Description

Adds health-based detection to the Shield Advanced protection for a resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

AssociateProactiveEngagementDetails

#
Service
shield

Description

Initializes proactive engagement and sets the list of contacts for the Shield Response Team (SRT) to use. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateProtection

#
Service
shield

Description

Enables Shield Advanced for a specific Amazon Web Services resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateProtectionGroup

#
Service
shield

Description

Creates a grouping of protected resources so they can be handled as a collective. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateSubscription

#
Service
shield

Description

Activates Shield Advanced for an account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteProtection

#
Service
shield

Description

Deletes an Shield Advanced Protection. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteProtectionGroup

#
Service
shield

Description

Removes the specified protection group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteSubscription

#
Service
shield

Description

Removes Shield Advanced from an account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeAttack

#
Service
shield

Description

Describes the details of a DDoS attack. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeAttackStatistics

#
Service
shield

Description

Provides information about the number and type of attacks Shield has detected in the last year for all resources that belong to your account, regardless of whether you've defined Shield protections for them. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeDRTAccess

#
Service
shield

Description

Returns the current role and list of Amazon S3 log buckets used by the Shield Response Team (SRT) to access your Amazon Web Services account while assisting with attack mitigation. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "03a532ae-2b9d-4c1d-b327-41fca7651550",
  "eventSource": "shield.amazonaws.com",
  "eventName": "DescribeDRTAccess",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "apiVersion": "AWSShield_20160616",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "7c529025-c80c-4975-8d27-15bfea6cb648",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/shield#1.26.0 m/E",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

DescribeEmergencyContactSettings

#
Service
shield

Description

A list of email addresses and phone numbers that the Shield Response Team (SRT) can use to contact you if you have proactive engagement enabled, for escalations to the SRT and to initiate proactive customer support.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::111111111111:user/cloudsploit is not authorized to perform: shield:DescribeEmergencyContactSettings on resource: arn:aws:shield::111111111111:subscription/*",
  "eventCategory": "Management",
  "eventID": "a183dbd3-3d3f-4085-9b00-2d212288276a",
  "eventName": "DescribeEmergencyContactSettings",
  "eventSource": "shield.amazonaws.com",
  "eventTime": "2021-04-13T11:35:34Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "111111111111",
  "requestID": "3b9ac0cf-a831-4d87-ae7a-d185d7678706",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "95.90.195.80",
  "userAgent": "aws-sdk-nodejs/2.885.0 linux/v14.16.1 callback",
  "userIdentity": {
    "accessKeyId": "AKIAYTOGP2RLGBSBSMH2",
    "accountId": "111111111111",
    "arn": "arn:aws:iam::111111111111:user/cloudsploit",
    "principalId": "AIDAYTOGP2RLMDEPWZWMJ",
    "type": "IAMUser",
    "userName": "cloudsploit"
  }
}

References #

DescribeProtection

#
Service
shield

Description

Lists the details of a Protection object. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "3a86df3e-7995-4b2b-bd65-07705fc03366",
  "eventSource": "shield.amazonaws.com",
  "eventName": "DescribeProtection",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "apiVersion": "AWSShield_20160616",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "2fa81186-33a6-453d-90dc-6f3b63d27331",
  "userAgent": "elbv2.k8s.aws/v3.2.2",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

DescribeProtectionGroup

#
Service
shield

Description

Returns the specification for the specified protection group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeSubscription

#
Service
shield

Description

Provides details about the Shield Advanced subscription for an account.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::111111111111:user/cloudsploit is not authorized to perform: shield:DescribeSubscription on resource: arn:aws:shield::111111111111:subscription/*",
  "eventCategory": "Management",
  "eventID": "1e5594be-1f4b-4d85-86ca-6163e92c5a4b",
  "eventName": "DescribeSubscription",
  "eventSource": "shield.amazonaws.com",
  "eventTime": "2021-04-13T11:35:34Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "111111111111",
  "requestID": "3f67914c-1f17-40d5-b4bf-d3eb11046a1d",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "95.90.195.80",
  "userAgent": "aws-sdk-nodejs/2.885.0 linux/v14.16.1 callback",
  "userIdentity": {
    "accessKeyId": "AKIAYTOGP2RLGBSBSMH2",
    "accountId": "111111111111",
    "arn": "arn:aws:iam::111111111111:user/cloudsploit",
    "principalId": "AIDAYTOGP2RLMDEPWZWMJ",
    "type": "IAMUser",
    "userName": "cloudsploit"
  }
}

References #

DisableApplicationLayerAutomaticResponse

#
Service
shield

Description

Disable the Shield Advanced automatic application layer DDoS mitigation feature for the protected resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DisableProactiveEngagement

#
Service
shield

Description

Removes authorization from the Shield Response Team (SRT) to notify contacts about escalations to the SRT and to initiate proactive customer support. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DisassociateDRTLogBucket

#
Service
shield

Description

Removes the Shield Response Team's (SRT) access to the specified Amazon S3 bucket containing the logs that you shared previously. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DisassociateDRTRole

#
Service
shield

Description

Removes the Shield Response Team's (SRT) access to your Amazon Web Services account. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DisassociateHealthCheck

#
Service
shield

Description

Removes health-based detection from the Shield Advanced protection for a resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

EnableApplicationLayerAutomaticResponse

#
Service
shield

Description

Enable the Shield Advanced automatic application layer DDoS mitigation for the protected resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

EnableProactiveEngagement

#
Service
shield

Description

Authorizes the Shield Response Team (SRT) to use email and phone to notify contacts about escalations to the SRT and to initiate proactive customer support. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetSubscriptionState

#
Service
shield

Description

Returns the SubscriptionState, either Active or Inactive. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "9d64bec2-cb41-42b8-88f1-64a4b8a2e14e",
  "eventSource": "shield.amazonaws.com",
  "eventName": "GetSubscriptionState",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "apiVersion": "AWSShield_20160616",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "9b04a7da-2a4e-4eb6-b88a-6714158a69fc",
  "userAgent": "elbv2.k8s.aws/v3.2.2",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

ListAttacks

#
Service
shield

Description

Returns all ongoing DDoS attacks or all DDoS attacks during a specified time period. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListProtectionGroups

#
Service
shield

Description

Retrieves ProtectionGroup objects for the account. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "8c967bf5-d50e-44e9-91ed-ff054f8613d3",
  "eventSource": "shield.amazonaws.com",
  "eventName": "ListProtectionGroups",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "apiVersion": "AWSShield_20160616",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "bd5073a9-e41c-4d84-87db-10388c0a2036",
  "userAgent": "config.amazonaws.com",
  "errorCode": "ResourceNotFoundException"
}

ListProtections

#
Service
shield

Description

Retrieves Protection objects for the account.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::731544447609:user/cloudsploit is not authorized to perform: shield:ListProtections on resource: arn:aws:shield::731544447609:protection/*",
  "eventCategory": "Management",
  "eventID": "3c23b0da-bca7-43e2-9fc0-82dd25155cd5",
  "eventName": "ListProtections",
  "eventSource": "shield.amazonaws.com",
  "eventTime": "2021-04-13T11:35:34Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "731544447609",
  "requestID": "3672f580-d2e8-4e7f-a7ed-2a6947234636",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "34.12.134.20",
  "userAgent": "aws-sdk-nodejs/2.885.0 linux/v14.16.1 callback",
  "userIdentity": {
    "accessKeyId": "AKIAYTOGP2RLGBSBSMH2",
    "accountId": "731544447609",
    "arn": "arn:aws:iam::731544447609:user/cloudsploit",
    "principalId": "AIDAYTOGP2RLMDEPWZWMJ",
    "type": "IAMUser",
    "userName": "cloudsploit"
  }
}

References #

ListResourcesInProtectionGroup

#
Service
shield

Description

Retrieves the resources that are included in the protection group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListTagsForResource

#
Service
shield

Description

Gets information about Amazon Web Services tags for a specified Amazon Resource Name (ARN) in Shield. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

TagResource

#
Service
shield

Description

Adds or updates tags for a resource in Shield. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UntagResource

#
Service
shield

Description

Removes tags from a resource in Shield. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateApplicationLayerAutomaticResponse

#
Service
shield

Description

Updates an existing Shield Advanced automatic application layer DDoS mitigation configuration for the specified resource. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateEmergencyContactSettings

#
Service
shield

Description

Updates the details of the list of email addresses and phone numbers that the Shield Response Team (SRT) can use to contact you if you have proactive engagement enabled, for escalations to the SRT and to initiate proactive customer support. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateProtectionGroup

#
Service
shield

Description

Updates an existing protection group. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateSubscription

#
Service
shield

Description

Updates the details of an existing subscription. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.