AWS Systems Manager

eventNameDescriptionSampleRule
anyCatch-all entry for AWS Systems Manager rules that match the service but not a specific eventName.NN
CreateAssociationCreates an association between a managed node and a Systems Manager document, defining the configuration state to apply.YY
CreateDocumentCreates a Systems Manager document that defines the actions to perform on managed nodes.YY
DescribeInstancePatchesRetrieves information about the patches on a specific managed node and their states relative to the patch baseline.YY
GetInventoryQueries the Systems Manager inventory, returning aggregated data about managed nodes based on specified filters.YY
GetInventorySchemaReturns a list of the metadata types currently available to populate a Systems Manager inventory.YY
GetParameterRetrieves the value of a single parameter from Systems Manager Parameter Store.YY
GetParametersRetrieves the values of one or more parameters from Systems Manager Parameter Store.YY
ListCommandsLists the commands sent to managed nodes in the current account and region.YY
ListInventoryEntriesLists the inventory entries for a specified managed node and inventory type.YY
RegisterManagedInstanceRegisters an on-premises server or virtual machine with Systems Manager so it can be managed as a managed node.NY
SendCommandRuns a Systems Manager document on one or more managed nodes, executing the specified commands or scripts.YY
StartSessionInitiates a connection to a managed node through AWS Systems Manager Session Manager.YY
AddTagsToResourceAdds or overwrites one or more tags for the specified resource.YN
AssociateOpsItemRelatedItemAssociates a related item to a Systems Manager OpsCenter OpsItem.NN
CancelCommandAttempts to cancel the command specified by the Command ID.YN
CancelMaintenanceWindowExecutionStops a maintenance window execution that is already in progress and cancels any tasks in the window that haven't already starting running.YN
CreateActivationGenerates an activation code and activation ID you can use to register your on-premises servers, edge devices, or virtual machine (VM) with Amazon Web Services Systems Manager.YN
CreateAssociationBatchAssociates the specified Amazon Web Services Systems Manager document (SSM document) with the specified managed nodes or targets.YN
CreateMaintenanceWindowCreates a new maintenance window.YN
CreateOpsItemCreates a new OpsItem.YN
CreateOpsMetadataIf you create a new application in Application Manager, Amazon Web Services Systems Manager calls this API operation to specify information about the new application, including the application type.YN
CreatePatchBaselineCreates a patch baseline.YN
CreateResourceDataSyncA resource data sync helps you view data from multiple sources in a single location.NN
DeleteActivationDeletes an activation.YN
DeleteAssociationDisassociates the specified Amazon Web Services Systems Manager document (SSM document) from the specified managed node.YN
DeleteDocumentDeletes the Amazon Web Services Systems Manager document (SSM document) and all managed node associations to the document.YN
DeleteInventoryDelete a custom inventory type or the data associated with a custom Inventory type.YN
DeleteMaintenanceWindowDeletes a maintenance window.YN
DeleteOpsItemDelete an OpsItem.YN
DeleteOpsMetadataDelete OpsMetadata related to an application.NN
DeleteParameterDelete a parameter from the system.YN
DeleteParametersDelete a list of parameters.YN
DeletePatchBaselineDeletes a patch baseline.NN
DeleteResourceDataSyncDeletes a resource data sync configuration.YN
DeleteResourcePolicyDeletes a Systems Manager resource policy.NN
DeregisterManagedInstanceRemoves the server or virtual machine from the list of registered servers.YN
DeregisterPatchBaselineForPatchGroupRemoves a patch group from a patch baseline.NN
DeregisterTargetFromMaintenanceWindowRemoves a target from a maintenance window.YN
DeregisterTaskFromMaintenanceWindowRemoves a task from a maintenance window.YN
DescribeActivationsDescribes details about the activation, such as the date and time the activation was created, its expiration date, the Identity and Access Management (IAM) role assigned to the managed nodes in the activation, and the number of nodes regist.YN
DescribeAssociationDescribes the association for the specified target or managed node.YN
DescribeAssociationExecutionsViews all executions for a specific association ID.YN
DescribeAssociationExecutionTargetsViews information about a specific execution of a specific association.YN
DescribeAutomationExecutionsProvides details about all active and terminated Automation executions.YN
DescribeAutomationStepExecutionsInformation about all active and terminated step executions in an Automation workflow.YN
DescribeAvailablePatchesLists all patches eligible to be included in a patch baseline.YN
DescribeDocumentDescribes the specified Amazon Web Services Systems Manager document (SSM document).YN
DescribeDocumentPermissionDescribes the permissions for a Amazon Web Services Systems Manager document (SSM document).YN
DescribeEffectiveInstanceAssociationsAll associations for the managed nodes.YN
DescribeEffectivePatchesForPatchBaselineRetrieves the current effective patches (the patch and the approval state) for the specified patch baseline.NN
DescribeInstanceAssociationsStatusThe status of the associations for the managed nodes.YN
DescribeInstanceInformationProvides information about one or more of your managed nodes, including the operating system platform, SSM Agent version, association status, and IP address.YY
DescribeInstancePatchStatesRetrieves the high-level patch state of one or more managed nodes.NN
DescribeInstancePatchStatesForPatchGroupRetrieves the high-level patch state for the managed nodes in the specified patch group.YN
DescribeInstancePropertiesAn API operation used by the Systems Manager console to display information about Systems Manager managed nodes.YN
DescribeInventoryDeletionsDescribes a specific delete inventory operation.YN
DescribeMaintenanceWindowExecutionsLists the executions of a maintenance window.YN
DescribeMaintenanceWindowExecutionTaskInvocationsRetrieves the individual task executions (one per target) for a particular task run as part of a maintenance window execution.YN
DescribeMaintenanceWindowExecutionTasksFor a given maintenance window execution, lists the tasks that were run.YN
DescribeMaintenanceWindowsRetrieves the maintenance windows in an Amazon Web Services account.YN
DescribeMaintenanceWindowScheduleRetrieves information about upcoming executions of a maintenance window.YN
DescribeMaintenanceWindowsForTargetRetrieves information about the maintenance window targets or tasks that a managed node is associated with.YN
DescribeMaintenanceWindowTargetsLists the targets registered with the maintenance window.YN
DescribeMaintenanceWindowTasksLists the tasks in a maintenance window.YN
DescribeOpsItemsQuery a set of OpsItems.YN
DescribeParametersLists the parameters in your Amazon Web Services account or the parameters shared with you when you enable the Shared option.YN
DescribePatchBaselinesLists the patch baselines in your Amazon Web Services account.YN
DescribePatchGroupsLists all patch groups that have been registered with patch baselines.YN
DescribePatchGroupStateReturns high-level aggregated patch compliance state information for a patch group.YN
DescribePatchPropertiesLists the properties of available patches organized by product, product family, classification, severity, and other properties of available patches.YN
DescribeSessionsRetrieves a list of all active sessions (both connected and disconnected) or terminated sessions from the past 30 days.YN
DisassociateOpsItemRelatedItemDeletes the association between an OpsItem and a related item.NN
GetAccessTokenReturns a credentials set to be used with just-in-time node access.NN
GetAutomationExecutionGet detailed information about a particular Automation execution.YN
GetCalendarStateGets the state of a Amazon Web Services Systems Manager change calendar at the current time or a specified time.YN
GetCommandInvocationReturns detailed information about command execution for an invocation or plugin.YN
GetConnectionStatusRetrieves the Session Manager connection status for a managed node to determine whether it is running and ready to receive Session Manager connections.NN
GetDefaultPatchBaselineRetrieves the default patch baseline.YN
GetDeployablePatchSnapshotForInstanceRetrieves the current snapshot for the patch baseline the managed node uses.NN
GetDocumentGets the contents of the specified Amazon Web Services Systems Manager document (SSM document).YN
GetExecutionPreviewInitiates the process of retrieving an existing preview that shows the effects that running a specified Automation runbook would have on the targeted resources.NN
GetMaintenanceWindowRetrieves a maintenance window.YN
GetMaintenanceWindowExecutionRetrieves details about a specific a maintenance window execution.YN
GetMaintenanceWindowExecutionTaskRetrieves the details about a specific task run as part of a maintenance window execution.YN
GetMaintenanceWindowExecutionTaskInvocationRetrieves information about a specific task running on a specific target.YN
GetMaintenanceWindowTaskRetrieves the details of a maintenance window task.YN
GetOpsItemGet information about an OpsItem by using the ID.NN
GetOpsMetadataView operational metadata related to an application in Application Manager.NN
GetOpsSummaryView a summary of operations metadata (OpsData) based on specified filters and aggregators.YN
GetParameterHistoryRetrieves the history of all changes to a parameter.YN
GetParametersByPathRetrieve information about one or more parameters under a specified level in a hierarchy.YN
GetPatchBaselineRetrieves information about a patch baseline.NN
GetPatchBaselineForPatchGroupRetrieves the patch baseline that should be used for the specified patch group.YN
GetResourcePoliciesReturns an array of the Policy object.NN
GetServiceSettingServiceSetting is an account-level setting for an Amazon Web Services service.YN
LabelParameterVersionA parameter label is a user-defined alias to help you manage different versions of a parameter.YN
ListAssociationsReturns all State Manager associations in the current Amazon Web Services account and Amazon Web Services Region.YN
ListAssociationVersionsRetrieves all versions of an association for a specific association ID.YN
ListCommandInvocationsAn invocation is copy of a command sent to a specific managed node.YN
ListComplianceItemsFor a specified resource ID, this API operation returns a list of compliance statuses for different resource types.YN
ListComplianceSummariesReturns a summary count of compliant and non-compliant resources for a compliance type.YN
ListDocumentMetadataHistoryAmazon Web Services Systems Manager Change Manager is no longer open to new customers.YN
ListDocumentsReturns all Systems Manager (SSM) documents in the current Amazon Web Services account and Amazon Web Services Region.YN
ListDocumentVersionsList all versions for a document.YN
ListNodesTakes in filters and returns a list of managed nodes matching the filter criteria.YN
ListNodesSummaryGenerates a summary of managed instance/node metadata based on the filters and aggregators you specify.YN
ListOpsItemEventsReturns a list of all OpsItem events in the current Amazon Web Services Region and Amazon Web Services account.YN
ListOpsItemRelatedItemsLists all related-item resources associated with a Systems Manager OpsCenter OpsItem.YN
ListOpsMetadataAmazon Web Services Systems Manager calls this API operation when displaying all Application Manager OpsMetadata objects or blobs.YN
ListResourceComplianceSummariesReturns a resource-level summary count.YN
ListResourceDataSyncLists your resource data sync configurations.YN
ListTagsForResourceReturns a list of the tags assigned to the specified resource.YN
ModifyDocumentPermissionShares a Amazon Web Services Systems Manager document (SSM document)publicly or privately.YY
PutComplianceItemsRegisters a compliance type and other compliance details on a designated resource.YN
PutInventoryBulk update custom inventory items on one or more managed nodes.YN
PutParameterCreate or update a parameter in Parameter Store.YN
PutResourcePolicyCreates or updates a Systems Manager resource policy.NN
RegisterDefaultPatchBaselineDefines the default patch baseline for the relevant operating system.NN
RegisterPatchBaselineForPatchGroupRegisters a patch baseline for a patch group.NN
RegisterTargetWithMaintenanceWindowRegisters a target with a maintenance window.YN
RegisterTaskWithMaintenanceWindowAdds a new task to a maintenance window.YN
RemoveTagsFromResourceRemoves tag keys from the specified resource.YN
ResetServiceSettingServiceSetting is an account-level setting for an Amazon Web Services service.YN
ResumeSessionReconnects a session to a managed node after it has been disconnected.YN
SendAutomationSignalSends a signal to an Automation execution to change the current behavior or status of the execution.NN
StartAccessRequestStarts the workflow for just-in-time node access sessions.NN
StartAssociationsOnceRuns an association immediately and only one time.NN
StartAutomationExecutionInitiates execution of an Automation runbook.YN
StartChangeRequestExecutionAmazon Web Services Systems Manager Change Manager is no longer open to new customers.NN
StartExecutionPreviewInitiates the process of creating a preview showing the effects that running a specified Automation runbook would have on the targeted resources.NN
StopAutomationExecutionStop an Automation that is currently running.YN
TerminateSessionPermanently ends a session and closes the data connection between the Session Manager client and SSM Agent on the managed node.YN
UnlabelParameterVersionRemove a label or labels from a parameter.YN
UpdateAssociationUpdates an association.YN
UpdateAssociationStatusUpdates the status of the Amazon Web Services Systems Manager document (SSM document) associated with the specified managed node.YN
UpdateDocumentUpdates one or more values for an SSM document.YN
UpdateDocumentDefaultVersionSet the default version of a document.YN
UpdateDocumentMetadataAmazon Web Services Systems Manager Change Manager is no longer open to new customers.YN
UpdateMaintenanceWindowUpdates an existing maintenance window.YN
UpdateMaintenanceWindowTargetModifies the target of an existing maintenance window.YN
UpdateMaintenanceWindowTaskModifies a task assigned to a maintenance window.YN
UpdateManagedInstanceRoleChanges the Identity and Access Management (IAM) role that is assigned to the on-premises server, edge device, or virtual machines (VM).NN
UpdateOpsItemEdit or change an OpsItem.YN
UpdateOpsMetadataAmazon Web Services Systems Manager calls this API operation when you edit OpsMetadata in Application Manager.NN
UpdatePatchBaselineModifies an existing patch baseline.NN
UpdateResourceDataSyncUpdate a resource data sync.YN
UpdateServiceSettingServiceSetting is an account-level setting for an Amazon Web Services service.YN
CreateDataChannelCreateDataChannel recorded by CloudTrail for AWS Systems Manager. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
GetManifestGetManifest recorded by CloudTrail for AWS Systems Manager. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
ListInstanceAssociationsListInstanceAssociations recorded by CloudTrail for AWS Systems Manager. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
ManagedInstanceConnectionLostManagedInstanceConnectionLost recorded by CloudTrail for AWS Systems Manager. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
OpenDataChannelOpenDataChannel recorded by CloudTrail for AWS Systems Manager. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
PutConfigurePackageResultPutConfigurePackageResult recorded by CloudTrail for AWS Systems Manager. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
UpdateInstanceAssociationStatusUpdateInstanceAssociationStatus recorded by CloudTrail for AWS Systems Manager. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
UpdateInstanceInformationUpdateInstanceInformation recorded by CloudTrail for AWS Systems Manager. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
CreateCloudConnectorCreates a cloud connector that establishes a connection between Systems Manager and a third-party cloud environment.NN
DeleteCloudConnectorDeletes a cloud connector.NN
GetCloudConnectorReturns detailed information about a cloud connector.NN
ListCloudConnectorsReturns a list of cloud connectors in the current Amazon Web Services account and Amazon Web Services Region.NN
UpdateCloudConnectorUpdates an existing cloud connector with new configuration details.NN
ValidateCloudConnectorValidates the configuration and connectivity of a cloud connector.NN

any: AWS Systems Manager (catch-all)

#
Service
ssm

Description

Catch-all entry for AWS Systems Manager rules that match the service but not a specific eventName.

CreateAssociation

#
Service
ssm

Description

Creates an association between a managed node and a Systems Manager document, defining the configuration state to apply.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "6202dca8-ff97-4a65-8fd9-0b03d7e407e8",
  "eventName": "CreateAssociation",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T19:25:26Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "ff346246-7355-4e77-ba3a-77a034dae792",
  "requestParameters": {
    "applyOnlyAtCronInterval": false,
    "name": "AWS-RunShellScript",
    "parameters": "HIDDEN_DUE_TO_SECURITY_REASONS",
    "targets": [
      {
        "key": "InstanceIds",
        "values": [
          "i-0123456789abcdef0"
        ]
      }
    ]
  },
  "responseElements": {
    "associationDescription": {
      "applyOnlyAtCronInterval": false,
      "associationId": "c93a05c3-e24a-4016-a7bf-51d1b9a6a740",
      "associationVersion": "1",
      "date": "2026-06-29T19:25:26Z",
      "documentVersion": "$DEFAULT",
      "lastUpdateAssociationDate": "2026-06-29T19:25:26Z",
      "name": "AWS-RunShellScript",
      "overview": {
        "detailedStatus": "Creating",
        "status": "Pending"
      },
      "parameters": "HIDDEN_DUE_TO_SECURITY_REASONS",
      "targets": [
        {
          "key": "InstanceIds",
          "values": [
            "i-0123456789abcdef0"
          ]
        }
      ]
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Kusto #

CreateDocument

#
Service
ssm

Description

Creates a Systems Manager document that defines the actions to perform on managed nodes.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "1129bf80-1af8-44cf-a6a1-c5face3f0711",
  "eventName": "CreateDocument",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T19:12:22Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "bb4ef741-4f8e-4d92-b33a-a5ce8eece0d9",
  "requestParameters": {
    "content": "HIDDEN_DUE_TO_SECURITY_REASONS",
    "documentFormat": "JSON",
    "name": "dwfix-doc"
  },
  "responseElements": {
    "documentDescription": {
      "createdDate": "2026-06-29T19:12:22Z",
      "defaultVersion": "1",
      "description": "dw",
      "documentFormat": "JSON",
      "documentId": "df6de79c-6403-4f9d-8870-08f6c8588a2b",
      "documentType": "Command",
      "documentVersion": "1",
      "hash": "e664bf5099908ccd8df0990c9e1e5e39bbdb7f9af37502ed96967145f4bf9a75",
      "hashType": "Sha256",
      "latestVersion": "1",
      "name": "dwfix-doc",
      "owner": "123456789012",
      "platformTypes": [
        "Linux",
        "MacOS"
      ],
      "schemaVersion": "2.2",
      "status": "Creating",
      "tags": []
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS SSM Command Document Created by Rare User source high: Identifies when an AWS Systems Manager (SSM) command document is created by a user or role who does not typically perform this action. Adversaries may create SSM command documents to execute commands on managed instances, potentially leading to unauthorized access, command and control, data exfiltration and more.T1651

DescribeInstancePatches

#
Service
ssm

Description

Retrieves information about the patches on a specific managed node and their states relative to the patch baseline.

Example CloudTrail Event #

{
  "eventVersion": "1.11",
  "userIdentity": {
    "type": "Root",
    "principalId": "123456789012",
    "arn": "arn:aws:iam::123456789012:root",
    "accountId": "123456789012",
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE"
  },
  "eventTime": "2026-07-28T20:58:18Z",
  "eventSource": "ssm.amazonaws.com",
  "eventName": "DescribeInstancePatches",
  "awsRegion": "us-west-1",
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/n,Z,E,C,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#ssm.describe-instance-patches",
  "requestParameters": {
    "instanceId": "i-00000000000000000"
  },
  "responseElements": null,
  "requestID": "be164893-076c-492d-9bd3-c3d7114a7dc6",
  "eventID": "c2e7494a-0bf3-4abe-a536-40959a2ba6a7",
  "readOnly": true,
  "eventType": "AwsApiCall",
  "managementEvent": true,
  "recipientAccountId": "123456789012",
  "eventCategory": "Management",
  "tlsDetails": {
    "tlsVersion": "TLSv1.2",
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

GetInventory

#
Service
ssm

Description

Queries the Systems Manager inventory, returning aggregated data about managed nodes based on specified filters.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "e01a5cda-643a-4e70-9e34-d071f85733c6",
  "eventName": "GetInventory",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:32:46Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "2c8a587e-9d1e-403e-b7e9-7bb4af16ed3b",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

GetInventorySchema

#
Service
ssm

Description

Returns a list of the metadata types currently available to populate a Systems Manager inventory.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: ssm:GetInventorySchema on resource: arn:aws:ssm:us-east-1:811596193553:*",
  "eventID": "bdf2b609-e558-4000-b603-602de4838a82",
  "eventName": "GetInventorySchema",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2019-10-19T23:49:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "66895ea7-7f09-430d-89b9-3919d7bc08d1",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "213.253.166.5",
  "userAgent": "Boto3/1.9.210 Python/2.7.10 Darwin/18.7.0 Botocore/1.12.210",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

GetParameter

#
Service
ssm

Description

Retrieves the value of a single parameter from Systems Manager Parameter Store.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "736cbe1d-d978-4599-ba4c-a4d682b908b8",
  "eventName": "GetParameter",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2023-07-10T11:58:10Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "45d5aa2b-5f29-4425-ab3d-a37df96a667e",
  "requestParameters": {
    "name": "/credentials/stratus-red-team/credentials-6",
    "withDecryption": true
  },
  "resources": [
    {
      "ARN": "arn:aws:ssm:us-east-1:123837392027:parameter/credentials/stratus-red-team/credentials-6",
      "accountId": "123837392027"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_11a6ef34-e130-4579-a1d3-79c915cee6ec HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS Systems Manager SecureString Parameter Request with Decryption Flag source medium: Detects the first occurrence of a user identity accessing AWS Systems Manager (SSM) SecureString parameters using the GetParameter or GetParameters API actions with credentials in the request parameters. This could indicate that the user is accessing sensitive information. This rule detects when a user accesses a SecureString parameter with the withDecryption parameter set to true. This is a New Terms rule that detects the first occurrence of an AWS identity accessing SecureString parameters with decryption.T1555, T1555.006↳ also matches GetParameters

Panther #

  • AWS Decrypt SSM Parameters source medium: Identify principals retrieving a high number of SSM Parameters of type 'SecretString'. This rule filters out known administrative roles that legitimately need bulk parameter access.T1555↳ also matches GetParameters

References #

GetParameters

#
Service
ssm

Description

Retrieves the values of one or more parameters from Systems Manager Parameter Store.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "928546c4-79d3-4f9e-aec5-319ef6685cde",
  "eventName": "GetParameters",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2023-07-10T11:58:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "fc91dc6f-0e31-41af-9c02-b99e500ab596",
  "requestParameters": {
    "names": [
      "/credentials/stratus-red-team/credentials-0",
      "/credentials/stratus-red-team/credentials-12",
      "/credentials/stratus-red-team/credentials-15",
      "/credentials/stratus-red-team/credentials-16",
      "/credentials/stratus-red-team/credentials-21",
      "/credentials/stratus-red-team/credentials-25",
      "/credentials/stratus-red-team/credentials-30",
      "/credentials/stratus-red-team/credentials-34",
      "/credentials/stratus-red-team/credentials-35",
      "/credentials/stratus-red-team/credentials-9"
    ],
    "withDecryption": true
  },
  "resources": [
    {
      "ARN": "arn:aws:ssm:us-east-1:123837392027:parameter/credentials/stratus-red-team/credentials-0",
      "accountId": "123837392027"
    },
    {
      "ARN": "arn:aws:ssm:us-east-1:123837392027:parameter/credentials/stratus-red-team/credentials-12",
      "accountId": "123837392027"
    },
    {
      "ARN": "arn:aws:ssm:us-east-1:123837392027:parameter/credentials/stratus-red-team/credentials-15",
      "accountId": "123837392027"
    },
    {
      "ARN": "arn:aws:ssm:us-east-1:123837392027:parameter/credentials/stratus-red-team/credentials-16",
      "accountId": "123837392027"
    },
    {
      "ARN": "arn:aws:ssm:us-east-1:123837392027:parameter/credentials/stratus-red-team/credentials-21",
      "accountId": "123837392027"
    },
    {
      "ARN": "arn:aws:ssm:us-east-1:123837392027:parameter/credentials/stratus-red-team/credentials-25",
      "accountId": "123837392027"
    },
    {
      "ARN": "arn:aws:ssm:us-east-1:123837392027:parameter/credentials/stratus-red-team/credentials-30",
      "accountId": "123837392027"
    },
    {
      "ARN": "arn:aws:ssm:us-east-1:123837392027:parameter/credentials/stratus-red-team/credentials-34",
      "accountId": "123837392027"
    },
    {
      "ARN": "arn:aws:ssm:us-east-1:123837392027:parameter/credentials/stratus-red-team/credentials-35",
      "accountId": "123837392027"
    },
    {
      "ARN": "arn:aws:ssm:us-east-1:123837392027:parameter/credentials/stratus-red-team/credentials-9",
      "accountId": "123837392027"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "stratus-red-team_11a6ef34-e130-4579-a1d3-79c915cee6ec",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS Systems Manager SecureString Parameter Request with Decryption Flag source medium: Detects the first occurrence of a user identity accessing AWS Systems Manager (SSM) SecureString parameters using the GetParameter or GetParameters API actions with credentials in the request parameters. This could indicate that the user is accessing sensitive information. This rule detects when a user accesses a SecureString parameter with the withDecryption parameter set to true. This is a New Terms rule that detects the first occurrence of an AWS identity accessing SecureString parameters with decryption.T1555, T1555.006↳ also matches GetParameter

Panther #

  • AWS Decrypt SSM Parameters source medium: Identify principals retrieving a high number of SSM Parameters of type 'SecretString'. This rule filters out known administrative roles that legitimately need bulk parameter access.T1555↳ also matches GetParameter

References #

ListCommands

#
Service
ssm

Description

Lists the commands sent to managed nodes in the current account and region.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: ssm:ListCommands on resource: arn:aws:ssm:us-east-1:811596193553:*",
  "eventID": "bcbb788c-0783-4edd-8d64-d712518e",
  "eventName": "ListCommands",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2019-10-19T23:49:23Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "readOnly": true,
  "recipientAccountId": "811596193553",
  "requestID": "29acd72f-074a-42b6-9022-95fa6e93418f",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "213.253.166.5",
  "userAgent": "Boto3/1.9.210 Python/2.7.10 Darwin/18.7.0 Botocore/1.12.210",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

ListInventoryEntries

#
Service
ssm

Description

Lists the inventory entries for a specified managed node and inventory type.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "3 validation errors detected: Value 'dw-probe' at 'instanceId' failed to satisfy constraint: Member must have length greater than or equal to 10; Value 'dw-probe' at 'instanceId' failed to satisfy constraint: Member must satisfy regular expression pattern: (^i-(\\w{8}|\\w{17})$)|(^mi-\\w{17}$); Value 'ddddd' at 'typeName' failed to satisfy constraint: Member must satisfy regular expression pattern: ^(AWS|Custom):.*$",
  "eventCategory": "Management",
  "eventID": "5afab473-5138-443c-9b5c-a968d3c26e47",
  "eventName": "ListInventoryEntries",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:46:11Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "bb873ee6-8635-41ec-856e-a82d832a8895",
  "requestParameters": {
    "instanceId": "dw-probe",
    "typeName": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

RegisterManagedInstance

#
Service
ssm

Description

Registers an on-premises server or virtual machine with Systems Manager so it can be managed as a managed node.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "a0ce9b28-5a5f-4c52-8474-c4914360c681",
  "eventSource": "ssm.amazonaws.com",
  "eventName": "RegisterManagedInstance",
  "awsRegion": "us-east-2",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "8593d18d-f772-45ee-8658-87a382e11d33",
  "userAgent": "aws-sdk-go/1.55.5 (go1.25.11; linux; arm64) amazon-ssm-agent/3.3.4793.0",
  "tlsDetails": {
    "tlsVersion": "TLSv1.2",
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-east-2.amazonaws.com"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

SendCommand

#
Service
ssm

Description

Runs a Systems Manager document on one or more managed nodes, executing the specified commands or scripts.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "99b46479-d5c7-4384-b342-006ece8c36a0",
  "eventName": "SendCommand",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2023-07-10T11:57:16Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "f2b7ffbd-9959-45f8-bc13-6f93c699b06d",
  "requestParameters": {
    "documentName": "AWS-RunShellScript",
    "instanceIds": [
      "i-0dbc91f429e48eeed"
    ],
    "interactive": false,
    "parameters": "HIDDEN_DUE_TO_SECURITY_REASONS"
  },
  "responseElements": {
    "command": {
      "alarmConfiguration": {
        "alarms": [],
        "ignorePollAlarmFailure": false
      },
      "clientName": "",
      "clientSourceId": "",
      "cloudWatchOutputConfig": {
        "cloudWatchLogGroupName": "",
        "cloudWatchOutputEnabled": false
      },
      "commandId": "bbf52fc0-1a25-4020-b1b4-1872ff8edd12",
      "comment": "",
      "completedCount": 0,
      "deliveryTimedOutCount": 0,
      "documentName": "AWS-RunShellScript",
      "documentVersion": "$DEFAULT",
      "errorCount": 0,
      "expiresAfter": "Jul 10, 2023 1:57:16 PM",
      "instanceIds": [
        "i-0dbc91f429e48eeed"
      ],
      "interactive": false,
      "maxConcurrency": "50",
      "maxErrors": "0",
      "notificationConfig": {
        "notificationArn": "",
        "notificationEvents": [],
        "notificationType": ""
      },
      "outputS3BucketName": "",
      "outputS3KeyPrefix": "",
      "outputS3Region": "us-east-1",
      "parameters": "HIDDEN_DUE_TO_SECURITY_REASONS",
      "requestedDateTime": "Jul 10, 2023 11:57:16 AM",
      "serviceRole": "",
      "status": "Pending",
      "statusDetails": "Pending",
      "targetCount": 1,
      "targets": [],
      "timeoutSeconds": 3600,
      "triggeredAlarms": []
    }
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aws::errorCode (sigma rule field)eqsuccess1 rulesigma
process_name (elastic rule field)inbase641 ruleelastic
process_name (elastic rule field)incurl1 ruleelastic
process_name (elastic rule field)innc1 ruleelastic
process_name (elastic rule field)inncat1 ruleelastic
process_name (elastic rule field)innetcat1 ruleelastic
process_name (elastic rule field)inopenssl1 ruleelastic
process_name (elastic rule field)inperl1 ruleelastic
process_name (elastic rule field)inphp1 ruleelastic
process_name (elastic rule field)inpython1 ruleelastic
process_name (elastic rule field)inpython31 ruleelastic
process_name (elastic rule field)inrsync1 ruleelastic
process_name (elastic rule field)inruby1 ruleelastic
process_name (elastic rule field)inscp1 ruleelastic
process_name (elastic rule field)insftp1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • AWS EC2 LOLBin Execution via SSM SendCommand source medium: Identifies the execution of Living Off the Land Binaries (LOLBins) or GTFOBins on EC2 instances via AWS Systems Manager (SSM) SendCommand API. This detection correlates AWS CloudTrail SendCommand events with endpoint process execution by matching SSM command IDs. While AWS redacts command parameters in CloudTrail logs, this correlation technique reveals the actual commands executed on EC2 instances. Adversaries may abuse SSM to execute malicious commands remotely without requiring SSH or RDP access, using legitimate system utilities for data exfiltration, establishing reverse shells, or lateral movement.T1059, T1059.004, T1105, T1651
  • AWS SSM `SendCommand` Execution by Rare User source low: Detects the execution of commands or scripts on EC2 instances using AWS Systems Manager (SSM), such as RunShellScript, RunPowerShellScript or custom documents. While legitimate users may employ these commands for management tasks, they can also be exploited by attackers with credentials to establish persistence, install malware, or execute reverse shells for further access to compromised instances. This is a New Terms rule that looks for the first instance of this behavior by a user or role.T1651

Kusto #

Panther #

References #

StartSession

#
Service
ssm

Description

Initiates a connection to a managed node through AWS Systems Manager Session Manager.

Example CloudTrail Event #

{
  "awsRegion": "ap-southeast-2",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/Level6 is not authorized to perform: ssm:StartSession on resource: arn:aws:ec2:ap-southeast-2:811596193553:instance/i-b4fbbdb99485b1594",
  "eventID": "a5d6b789-9143-4724-8a63-1bcc17876f",
  "eventName": "StartSession",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2019-09-19T23:29:38Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "08c96390-6974-4d29-a314-e74b18d5d17d",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "227.254.253.118",
  "userAgent": "aws-cli/1.16.190 Python/3.7.4 Darwin/17.5.0 botocore/1.12.180",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS SSM Session Started to EC2 Instance source high: Identifies the first occurrence of an AWS user or role establishing a session via SSM to an EC2 instance. Adversaries may use AWS Session Manager to establish a session to an EC2 instance to execute commands on the instance. This can be used to gain access to the instance and perform actions such as privilege escalation.T1021, T1021.007

References #

AddTagsToResource

#
Service
ssm

Description

Adds or overwrites one or more tags for the specified resource.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "d5ddc9bd-9457-49e0-a31b-ffb9fba1fd73",
  "eventName": "AddTagsToResource",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T19:12:21Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "ae6fbc9f-66d6-4609-8556-c420a25602a0",
  "requestParameters": {
    "resourceId": "/dwfix/p",
    "resourceType": "Parameter",
    "tags": [
      {
        "key": "dw",
        "value": "f"
      }
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

AssociateOpsItemRelatedItem

#
Service
ssm

Description

Associates a related item to a Systems Manager OpsCenter OpsItem.

CancelCommand

#
Service
ssm

Description

Attempts to cancel the command specified by the Command ID.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "1 validation error detected: Value 'dddddddddddddddddddddddddddddddddddd' at 'commandId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[A-Fa-f0-9]{8}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{12}$",
  "eventCategory": "Management",
  "eventID": "ab8566d9-2328-4a73-8251-fc504272e57d",
  "eventName": "CancelCommand",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T19:26:49Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "ff3c88d4-b84f-41e8-a853-3321d7b0748a",
  "requestParameters": {
    "commandId": "dddddddddddddddddddddddddddddddddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CancelMaintenanceWindowExecution

#
Service
ssm

Description

Stops a maintenance window execution that is already in progress and cancels any tasks in the window that haven't already starting running.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "1 validation error detected: Value at 'windowExecutionId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[0-9a-fA-F]{8}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{12}$",
  "eventCategory": "Management",
  "eventID": "5c36d983-4482-4205-b278-dc2b2170cd21",
  "eventName": "CancelMaintenanceWindowExecution",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T19:26:49Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "b9bca564-7e10-4433-a69e-2eab4428f4a1",
  "requestParameters": {
    "windowExecutionId": "dddddddddddddddddddddddddddddddddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateActivation

#
Service
ssm

Description

Generates an activation code and activation ID you can use to register your on-premises servers, edge devices, or virtual machine (VM) with Amazon Web Services Systems Manager.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Nonexistent role or missing ssm service principal in trust policy: arn:aws:iam::123456789012:role/AmazonSSMManagedInstanceCore",
  "eventCategory": "Management",
  "eventID": "e3c7ca52-07f9-4355-85b1-d67d9f2e7dc0",
  "eventName": "CreateActivation",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T20:58:59Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "8926e2f8-8f36-46ae-b1c5-4f99d53199b3",
  "requestParameters": {
    "defaultInstanceName": "dwfix-instance-ea8e728b",
    "description": "dwfix test hybrid activation",
    "iamRole": "AmazonSSMManagedInstanceCore",
    "registrationLimit": 1,
    "tags": [
      {
        "key": "dwfix",
        "value": "true"
      }
    ]
  },
  "resources": [
    {
      "ARN": "arn:aws:iam::123456789012:role/AmazonSSMManagedInstanceCore",
      "accountId": "123456789012"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b,n cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateAssociationBatch

#
Service
ssm

Description

Associates the specified Amazon Web Services Systems Manager document (SSM document) with the specified managed nodes or targets.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidTarget",
  "errorMessage": "Instance ID or targets must be specified",
  "eventCategory": "Management",
  "eventID": "a88adeee-4d6a-4cae-859e-7236c204e4a8",
  "eventName": "CreateAssociationBatch",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T20:58:56Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "03411194-16f7-44dd-824a-c511087bf4d0",
  "requestParameters": {
    "entries": [
      {
        "applyOnlyAtCronInterval": false,
        "associationName": "dwfix-assoc-ea8e728b",
        "name": "dwfix-doc-ea8e728b"
      }
    ]
  },
  "resources": [
    {
      "ARN": "arn:aws:ssm:us-west-1:123456789012:document/dwfix-doc-ea8e728b",
      "accountId": "123456789012"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b,n cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateMaintenanceWindow

#
Service
ssm

Description

Creates a new maintenance window.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "24179075-a83b-44ec-9d4a-4a6dfb77b9b7",
  "eventName": "CreateMaintenanceWindow",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T20:58:55Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "f8f01781-cd08-4a86-93e3-4e168f29c2d3",
  "requestParameters": {
    "allowUnassociatedTargets": true,
    "clientToken": "15eb483c-f0b7-4fc8-8484-0e02c8289d10",
    "cutoff": 0,
    "description": "HIDDEN_DUE_TO_SECURITY_REASONS",
    "duration": 1,
    "name": "dwfix-mw-ea8e728b",
    "schedule": "cron(0 2 ? * SUN *)",
    "tags": [
      {
        "key": "dwfix",
        "value": "true"
      }
    ]
  },
  "resources": [
    {
      "ARN": "arn:aws:ssm:us-west-1:123456789012:maintenancewindow/mw-06e8430a431fc17a1",
      "accountId": "123456789012"
    }
  ],
  "responseElements": {
    "windowId": "mw-06e8430a431fc17a1"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b,n cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateOpsItem

#
Service
ssm

Description

Creates a new OpsItem.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "f294a404-7fd0-4710-a7f9-d0b57a9ed1e8",
  "eventName": "CreateOpsItem",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T20:58:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "43ddd473-1f32-4c3a-bbc2-73dcc2c97e85",
  "requestParameters": {
    "category": "Availability",
    "description": "dwfix test ops item for CloudTrail sample collection",
    "priority": 3,
    "severity": "3",
    "source": "dwfix-collector",
    "tags": [
      {
        "key": "dwfix",
        "value": "true"
      }
    ],
    "title": "dwfix-item-ea8e728b"
  },
  "responseElements": {
    "opsItemArn": "arn:aws:ssm:us-west-1:123456789012:opsitem/oi-e32d6871b32d",
    "opsItemId": "oi-e32d6871b32d"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b,n cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateOpsMetadata

#
Service
ssm

Description

If you create a new application in Application Manager, Amazon Web Services Systems Manager calls this API operation to specify information about the new application, including the application type.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "e525a495-1bab-4007-97a3-3fb55801bfc1",
  "eventName": "CreateOpsMetadata",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T20:58:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "69191487-dd8f-4532-83fc-42a1a7135e7f",
  "requestParameters": {
    "resourceId": "dwfix-resource-ea8e728b",
    "tags": [
      {
        "key": "dwfix",
        "value": "true"
      }
    ]
  },
  "resources": [
    {
      "ARN": "arn:aws:ssm:us-west-1:123456789012:opsmetadata/*",
      "accountId": "123456789012"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b,n cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreatePatchBaseline

#
Service
ssm

Description

Creates a patch baseline.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Patch Baseline attribute: Approved Patches and Approval Rule, at least one must be non empty.",
  "eventCategory": "Management",
  "eventID": "2b271645-8c2c-41b8-90d8-a47248bc841c",
  "eventName": "CreatePatchBaseline",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T20:58:55Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "0c5b8cf6-a624-4f89-8535-62ae8c265afb",
  "requestParameters": {
    "approvedPatchesComplianceLevel": "MEDIUM",
    "clientToken": "7daf494f-828e-40e3-986e-eba882556e07",
    "description": "HIDDEN_DUE_TO_SECURITY_REASONS",
    "name": "dwfix-baseline-ea8e728b",
    "operatingSystem": "WINDOWS",
    "tags": [
      {
        "key": "dwfix",
        "value": "true"
      }
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b,n cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateResourceDataSync

#
Service
ssm

Description

A resource data sync helps you view data from multiple sources in a single location.

DeleteActivation

#
Service
ssm

Description

Deletes an activation.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "2 validation errors detected: Value 'dw-probe' at 'activationId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$; Value 'dw-probe' at 'activationId' failed to satisfy constraint: Member must have length greater than or equal to 36",
  "eventCategory": "Management",
  "eventID": "2570d62b-f579-4c60-96a8-690c5ed1f2cf",
  "eventName": "DeleteActivation",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T19:26:49Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "380d7308-1c32-4bab-80bd-f2d2c2df23d9",
  "requestParameters": {
    "activationId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteAssociation

#
Service
ssm

Description

Disassociates the specified Amazon Web Services Systems Manager document (SSM document) from the specified managed node.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "13d309c5-c885-4e62-863d-f209bd4baa51",
  "eventName": "DeleteAssociation",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T19:25:26Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "da2e044d-1620-4856-8555-fb304be6ad32",
  "requestParameters": {
    "associationId": "c93a05c3-e24a-4016-a7bf-51d1b9a6a740"
  },
  "resources": [
    {
      "ARN": "arn:aws:ssm:us-west-1:123456789012:association/c93a05c3-e24a-4016-a7bf-51d1b9a6a740",
      "accountId": "123456789012"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteDocument

#
Service
ssm

Description

Deletes the Amazon Web Services Systems Manager document (SSM document) and all managed node associations to the document.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "2ff0ec7f-016a-443a-aa3d-7fc5bc181ab8",
  "eventName": "DeleteDocument",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T19:12:22Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "f7cf8a7f-3028-48e7-9f84-085fba300f72",
  "requestParameters": {
    "force": false,
    "name": "dwfix-doc"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteInventory

#
Service
ssm

Description

Delete a custom inventory type or the data associated with a custom Inventory type.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "1 validation error detected: Value 'ddddd' at 'typeName' failed to satisfy constraint: Member must satisfy regular expression pattern: ^(AWS|Custom):.*$",
  "eventCategory": "Management",
  "eventID": "d6bd122e-386b-4455-86c9-fb57ccde15e6",
  "eventName": "DeleteInventory",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T19:26:49Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "0e798de9-7ca1-48dd-ab2b-192888cf5c69",
  "requestParameters": {
    "clientToken": "249bba08-90a8-4fec-bcbb-679500e159b6",
    "dryRun": false,
    "typeName": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteMaintenanceWindow

#
Service
ssm

Description

Deletes a maintenance window.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "1 validation error detected: Value at 'windowId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^mw-[0-9a-f]{17}$",
  "eventCategory": "Management",
  "eventID": "3f64eee5-09a7-431b-9103-2138208ede22",
  "eventName": "DeleteMaintenanceWindow",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T19:26:49Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "e10fddb4-077c-4197-bce1-3198245d1d27",
  "requestParameters": {
    "windowId": "dddddddddddddddddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteOpsItem

#
Service
ssm

Description

Delete an OpsItem.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "7f90b983-c3f6-4eb6-9573-8072b41cb989",
  "eventName": "DeleteOpsItem",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T20:58:55Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "3432e0f4-09f5-4798-a9b9-3c02427485d8",
  "requestParameters": {
    "opsItemId": "oi-e32d6871b32d"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b,n cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteOpsMetadata

#
Service
ssm

Description

Delete OpsMetadata related to an application.

DeleteParameter

#
Service
ssm

Description

Delete a parameter from the system.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "2b2f4de3-8b4e-48b7-9326-ec2118c61742",
  "eventName": "DeleteParameter",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2023-07-10T12:08:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "979718f4-079c-4c62-a7cd-729519b0f7fe",
  "requestParameters": {
    "name": "/credentials/stratus-red-team/credentials-22"
  },
  "resources": [
    {
      "ARN": "arn:aws:ssm:us-east-1:123837392027:parameter/credentials/stratus-red-team/credentials-22",
      "accountId": "123837392027"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DeleteParameters

#
Service
ssm

Description

Delete a list of parameters.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "173572ef-812d-40d9-b8c0-8c023810031c",
  "eventName": "DeleteParameters",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T19:26:49Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "42a29dec-3c2a-4800-a33b-a70477477617",
  "requestParameters": {
    "names": [
      "ddddd"
    ]
  },
  "resources": [
    {
      "ARN": "arn:aws:ssm:us-west-1:123456789012:parameter/ddddd",
      "accountId": "123456789012"
    }
  ],
  "responseElements": {
    "deletedParameters": [],
    "invalidParameters": [
      "ddddd"
    ]
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeletePatchBaseline

#
Service
ssm

Description

Deletes a patch baseline.

DeleteResourceDataSync

#
Service
ssm

Description

Deletes a resource data sync configuration.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ResourceDataSyncNotFoundException",
  "errorMessage": "ResourceDataSync with name ddddd synctype SyncToDestination does not exists",
  "eventCategory": "Management",
  "eventID": "6c2f7552-416d-4d0e-a638-acee559aa24f",
  "eventName": "DeleteResourceDataSync",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T19:26:49Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "5752f466-1525-4705-ac07-1af7debd966c",
  "requestParameters": {
    "syncName": "ddddd"
  },
  "resources": [
    {
      "ARN": "arn:aws:ssm:us-west-1:123456789012:resource-data-sync/ddddd",
      "accountId": "123456789012"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteResourcePolicy

#
Service
ssm

Description

Deletes a Systems Manager resource policy.

DeregisterManagedInstance

#
Service
ssm

Description

Removes the server or virtual machine from the list of registered servers.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "1 validation error detected: Value 'dddddddddddddddddddd' at 'instanceId' failed to satisfy constraint: Member must satisfy regular expression pattern: (^mi-[0-9a-f]{17}$)|(^eks_c:[0-9A-Za-z][A-Za-z0-9\\-_]{0,99}_\\w{17}$)",
  "eventCategory": "Management",
  "eventID": "a69d6fd5-49b7-47c8-bd9b-29fd82efd737",
  "eventName": "DeregisterManagedInstance",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T19:26:49Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "2d92ebe2-2b11-45e3-8c8e-6f237779ec35",
  "requestParameters": {
    "instanceId": "dddddddddddddddddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeregisterPatchBaselineForPatchGroup

#
Service
ssm

Description

Removes a patch group from a patch baseline.

DeregisterTargetFromMaintenanceWindow

#
Service
ssm

Description

Removes a target from a maintenance window.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "2 validation errors detected: Value at 'windowTargetId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[0-9a-fA-F]{8}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{12}$; Value at 'windowId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^mw-[0-9a-f]{17}$",
  "eventCategory": "Management",
  "eventID": "900e85d8-b5c4-45f1-beb1-c5bee6c59a17",
  "eventName": "DeregisterTargetFromMaintenanceWindow",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T19:26:49Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "138d2733-1976-4f8f-8e0d-f50c7f803b17",
  "requestParameters": {
    "windowId": "dddddddddddddddddddd",
    "windowTargetId": "dddddddddddddddddddddddddddddddddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeregisterTaskFromMaintenanceWindow

#
Service
ssm

Description

Removes a task from a maintenance window.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "2 validation errors detected: Value at 'windowTaskId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[0-9a-fA-F]{8}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{12}$; Value at 'windowId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^mw-[0-9a-f]{17}$",
  "eventCategory": "Management",
  "eventID": "b192a288-0ac0-485f-bd84-2db7f2fef4b0",
  "eventName": "DeregisterTaskFromMaintenanceWindow",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T19:26:49Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "69ed0fbb-e627-4f63-97b8-67be8becd724",
  "requestParameters": {
    "windowId": "dddddddddddddddddddd",
    "windowTaskId": "dddddddddddddddddddddddddddddddddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeActivations

#
Service
ssm

Description

Describes details about the activation, such as the date and time the activation was created, its expiration date, the Identity and Access Management (IAM) role assigned to the managed nodes in the activation, and the number of nodes regist.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "d5a810ed-d1ef-4d64-bb20-af990d950beb",
  "eventName": "DescribeActivations",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2018-10-17T20:32:14Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "readOnly": true,
  "recipientAccountId": "811596193553",
  "requestID": "3a2112d4-6295-4c17-8b6f-3c060ab9a42d",
  "requestParameters": null,
  "resources": [],
  "responseElements": null,
  "sourceIPAddress": "9.245.1.85",
  "userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeAssociation

#
Service
ssm

Description

Describes the association for the specified target or managed node.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "ValidationException",
  "errorMessage": "Must either provide instance id + document name, or provide association id ",
  "eventID": "a910d90c-33cf-4cf8-9b2e-e38599fb232b",
  "eventName": "DescribeAssociation",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2018-10-17T20:32:15Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "readOnly": true,
  "recipientAccountId": "811596193553",
  "requestID": "3ce4ad23-22c4-4e98-bfc0-4f59853b4b",
  "requestParameters": null,
  "resources": [
    {
      "ARN": "arn:aws:ssm:us-east-1:811596193553:managed-instance/null",
      "accountId": "811596193553"
    },
    {
      "ARN": "arn:aws:ssm:us-east-1:811596193553:document/null",
      "accountId": "811596193553"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "9.245.1.85",
  "userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeAssociationExecutions

#
Service
ssm

Description

Views all executions for a specific association ID.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "1 validation error detected: Value 'dw-probe' at 'associationId' failed to satisfy constraint: Member must satisfy regular expression pattern: [0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}",
  "eventCategory": "Management",
  "eventID": "1bb558d6-db9a-4ba3-b121-eb7858a0ece6",
  "eventName": "DescribeAssociationExecutions",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:46:11Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "f4c8d7e9-946c-4d40-bfc6-08af548155fe",
  "requestParameters": {
    "associationId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeAssociationExecutionTargets

#
Service
ssm

Description

Views information about a specific execution of a specific association.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "2 validation errors detected: Value 'dw-probe' at 'executionId' failed to satisfy constraint: Member must satisfy regular expression pattern: [0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}; Value 'dw-probe' at 'associationId' failed to satisfy constraint: Member must satisfy regular expression pattern: [0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}",
  "eventCategory": "Management",
  "eventID": "30cda0b3-a326-4e54-9608-3fec4af0d964",
  "eventName": "DescribeAssociationExecutionTargets",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:46:11Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "840fcba9-8440-44e2-a4d3-2ed0ba09bafb",
  "requestParameters": {
    "associationId": "dw-probe",
    "executionId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeAutomationExecutions

#
Service
ssm

Description

Provides details about all active and terminated Automation executions.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "d5c139456-f338-47f6-a0fc-59438256b203",
  "eventName": "DescribeAutomationExecutions",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2018-10-17T20:32:14Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "readOnly": true,
  "recipientAccountId": "811596193553",
  "requestID": "b62a7bf7-cc2b-48ab-8bc5-d88ce8aea65e",
  "requestParameters": null,
  "resources": [],
  "responseElements": null,
  "sourceIPAddress": "9.245.1.85",
  "userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeAutomationStepExecutions

#
Service
ssm

Description

Information about all active and terminated step executions in an Automation workflow.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "1 validation error detected: Value at 'automationExecutionId' failed to satisfy constraint: Member must satisfy regular expression pattern: [a-fA-F0-9]{8}-[a-fA-F0-9]{4}-[a-fA-F0-9]{4}-[a-fA-F0-9]{4}-[a-fA-F0-9]{12}",
  "eventCategory": "Management",
  "eventID": "1bc33c81-dd6e-4152-92db-b0b2eab37935",
  "eventName": "DescribeAutomationStepExecutions",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:46:11Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "14b587f7-fac2-419b-9450-16f6fdb6617f",
  "requestParameters": {
    "automationExecutionId": "dddddddddddddddddddddddddddddddddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeAvailablePatches

#
Service
ssm

Description

Lists all patches eligible to be included in a patch baseline.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "36c8d420-3b9f-4099-bfd6-99fd28afadf0",
  "eventName": "DescribeAvailablePatches",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2018-10-17T20:32:14Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "readOnly": true,
  "recipientAccountId": "811596193553",
  "requestID": "447ed1f6-becc-4822-afd2-358fe4ae20c1",
  "requestParameters": null,
  "resources": [],
  "responseElements": null,
  "sourceIPAddress": "9.245.1.85",
  "userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeDocument

#
Service
ssm

Description

Describes the specified Amazon Web Services Systems Manager document (SSM document).

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:sts::811596193553:assumed-role/flaws/i-aa2d3b42e5c6e801a is not authorized to perform: ssm:DescribeDocument on resource: arn:aws:ssm:us-west-2::document/AWS-RunShellScript",
  "eventID": "e400b73f-4a1b-4cc2-ba39-9d78eb00311d",
  "eventName": "DescribeDocument",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2020-02-20T03:42:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "readOnly": true,
  "recipientAccountId": "811596193553",
  "requestID": "27f8aef1-9d56-4632-bfd7-d64db91e2e6a",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "1.9.142.0",
  "userAgent": "aws-cli/1.18.0 Python/2.7.17 Linux/5.4.0-kali3-amd64 botocore/1.15.0",
  "userIdentity": {
    "accessKeyId": "ASIAJL2MNK6Q8GDKNZLM",
    "accountId": "811596193553",
    "arn": "arn:aws:sts::811596193553:assumed-role/flaws/i-aa2d3b42e5c6e801a",
    "principalId": "AROACW5CSA8C8WHOB3O7Q:i-aa2d3b42e5c6e801a",
    "sessionContext": {
      "attributes": {
        "creationDate": "2020-02-20T02:47:20Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {
        "accountId": "811596193553",
        "arn": "arn:aws:iam::811596193553:role/flaws",
        "principalId": "AROACW5CSA8C8WHOB3O7Q",
        "type": "Role",
        "userName": "flaws"
      },
      "webIdFederationData": {}
    },
    "type": "AssumedRole"
  }
}

References #

DescribeDocumentPermission

#
Service
ssm

Description

Describes the permissions for a Amazon Web Services Systems Manager document (SSM document).

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidDocument",
  "errorMessage": "Document with name dw-probe does not exist.",
  "eventCategory": "Management",
  "eventID": "ce0800e0-1cb6-473e-b40b-8f149e155ad5",
  "eventName": "DescribeDocumentPermission",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:46:11Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "6d485a9a-3738-4485-9428-d9e65574c84e",
  "requestParameters": {
    "name": "dw-probe",
    "permissionType": "Share"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeEffectiveInstanceAssociations

#
Service
ssm

Description

All associations for the managed nodes.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "2 validation errors detected: Value 'dw-probe' at 'instanceId' failed to satisfy constraint: Member must have length greater than or equal to 10; Value 'dw-probe' at 'instanceId' failed to satisfy constraint: Member must satisfy regular expression pattern: (^i-(\\w{8}|\\w{17})$)|(^mi-\\w{17}$)",
  "eventCategory": "Management",
  "eventID": "cb4af5b4-0680-43fd-a55f-dfdfee0408ab",
  "eventName": "DescribeEffectiveInstanceAssociations",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:46:11Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "acc62908-e007-40d8-894e-0a26f6c57894",
  "requestParameters": {
    "instanceId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeEffectivePatchesForPatchBaseline

#
Service
ssm

Description

Retrieves the current effective patches (the patch and the approval state) for the specified patch baseline.

DescribeInstanceAssociationsStatus

#
Service
ssm

Description

The status of the associations for the managed nodes.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "2 validation errors detected: Value 'dw-probe' at 'instanceId' failed to satisfy constraint: Member must have length greater than or equal to 10; Value 'dw-probe' at 'instanceId' failed to satisfy constraint: Member must satisfy regular expression pattern: (^i-(\\w{8}|\\w{17})$)|(^mi-\\w{17}$)",
  "eventCategory": "Management",
  "eventID": "130ba2fb-33b1-424a-bb92-d6d75f9f6c65",
  "eventName": "DescribeInstanceAssociationsStatus",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:46:11Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "2c9a1ada-d267-436d-802a-a35fdb5b53fc",
  "requestParameters": {
    "instanceId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeInstanceInformation

#
Service
ssm

Description

Provides information about one or more of your managed nodes, including the operating system platform, SSM Agent version, association status, and IP address.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "31084771-651b-4632-87f4-7511fbdfb1bd",
  "eventName": "DescribeInstanceInformation",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2023-07-10T11:56:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "f146ac8b-04a0-47ac-b33a-0b1274622e6a",
  "requestParameters": {
    "filters": [
      {
        "key": "InstanceIds",
        "values": [
          "i-0dbc91f429e48eeed"
        ]
      }
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

DescribeInstancePatchStates

#
Service
ssm

Description

Retrieves the high-level patch state of one or more managed nodes.

DescribeInstancePatchStatesForPatchGroup

#
Service
ssm

Description

Retrieves the high-level patch state for the managed nodes in the specified patch group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "27cb5812-61c8-4aab-aded-e26068deafd3",
  "eventName": "DescribeInstancePatchStatesForPatchGroup",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:46:11Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "cb2a8271-52f9-48df-b1d1-6e5d318deacf",
  "requestParameters": {
    "patchGroup": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeInstanceProperties

#
Service
ssm

Description

An API operation used by the Systems Manager console to display information about Systems Manager managed nodes.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "cf674e6f-1d90-4e2b-8d1f-9314510554ca",
  "eventName": "DescribeInstanceProperties",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:32:46Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "94bd2f16-870e-4a44-bca2-bb2127fd4e53",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeInventoryDeletions

#
Service
ssm

Description

Describes a specific delete inventory operation.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "916d7af2-c4d3-4e7c-a693-cb8fde3e1205",
  "eventName": "DescribeInventoryDeletions",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2018-10-17T20:32:14Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "d1b31e2f-b6c2-46ff-85d2-f3889e6d1b71",
  "requestParameters": null,
  "resources": [],
  "responseElements": null,
  "sourceIPAddress": "9.245.1.85",
  "userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeMaintenanceWindowExecutions

#
Service
ssm

Description

Lists the executions of a maintenance window.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "1 validation error detected: Value at 'windowId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^mw-[0-9a-f]{17}$",
  "eventCategory": "Management",
  "eventID": "c0d45215-cead-4cc1-a7b8-d17ac023d116",
  "eventName": "DescribeMaintenanceWindowExecutions",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:46:11Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "3050394e-3d75-482a-9e19-5e74e651d297",
  "requestParameters": {
    "windowId": "dddddddddddddddddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeMaintenanceWindowExecutionTaskInvocations

#
Service
ssm

Description

Retrieves the individual task executions (one per target) for a particular task run as part of a maintenance window execution.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "2 validation errors detected: Value at 'windowExecutionId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[0-9a-fA-F]{8}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{12}$; Value at 'taskId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[0-9a-fA-F]{8}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{12}$",
  "eventCategory": "Management",
  "eventID": "d6c20136-a34e-4720-97ce-50d9c4774cd2",
  "eventName": "DescribeMaintenanceWindowExecutionTaskInvocations",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:46:11Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "b581a7ea-daac-4f1f-8f82-ee3bff87724d",
  "requestParameters": {
    "taskId": "dddddddddddddddddddddddddddddddddddd",
    "windowExecutionId": "dddddddddddddddddddddddddddddddddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeMaintenanceWindowExecutionTasks

#
Service
ssm

Description

For a given maintenance window execution, lists the tasks that were run.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "1 validation error detected: Value at 'windowExecutionId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[0-9a-fA-F]{8}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{12}$",
  "eventCategory": "Management",
  "eventID": "e3768e59-ff25-4f07-89d1-90eaae0bb67a",
  "eventName": "DescribeMaintenanceWindowExecutionTasks",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:46:11Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "6e48fd38-3777-40d8-a1e7-0d24b2284140",
  "requestParameters": {
    "windowExecutionId": "dddddddddddddddddddddddddddddddddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeMaintenanceWindows

#
Service
ssm

Description

Retrieves the maintenance windows in an Amazon Web Services account.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "9e93b985-067b-4ab2-b4e0-b90818da30",
  "eventName": "DescribeMaintenanceWindows",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2018-10-17T20:32:15Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "readOnly": true,
  "recipientAccountId": "811596193553",
  "requestID": "a57009-6166-44e6-b387-f7be9b2a5aa8",
  "requestParameters": null,
  "resources": [],
  "responseElements": null,
  "sourceIPAddress": "9.245.1.85",
  "userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeMaintenanceWindowSchedule

#
Service
ssm

Description

Retrieves information about upcoming executions of a maintenance window.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "ValidationException",
  "errorMessage": "Must provide either a valid WindowId or target, but not both.",
  "eventID": "d58b2b9f-fb73-4f2b-b387-6d47b950e328",
  "eventName": "DescribeMaintenanceWindowSchedule",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2018-10-17T20:32:15Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "readOnly": true,
  "recipientAccountId": "811596193553",
  "requestID": "010898fac-58b0-4e3b-b767-1c17ece4a81d",
  "requestParameters": null,
  "resources": [],
  "responseElements": null,
  "sourceIPAddress": "9.245.1.85",
  "userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeMaintenanceWindowsForTarget

#
Service
ssm

Description

Retrieves information about the maintenance window targets or tasks that a managed node is associated with.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "2 validation errors detected: Value at 'targets.1.member.values' failed to satisfy constraint: Member must not be null; Value at 'targets.1.member.key' failed to satisfy constraint: Member must not be null",
  "eventCategory": "Management",
  "eventID": "e0cffdb6-9405-4f67-a7b2-f693cee9c1b4",
  "eventName": "DescribeMaintenanceWindowsForTarget",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:46:11Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "333a1261-5364-46ee-859b-e1060d6a60d7",
  "requestParameters": {
    "resourceType": "INSTANCE",
    "targets": [
      {}
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeMaintenanceWindowTargets

#
Service
ssm

Description

Lists the targets registered with the maintenance window.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "1 validation error detected: Value at 'windowId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^mw-[0-9a-f]{17}$",
  "eventCategory": "Management",
  "eventID": "c70389ef-afbb-4002-9c7d-5155120ec9b4",
  "eventName": "DescribeMaintenanceWindowTargets",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:46:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "42a2dd8e-ee38-45f1-81c6-57e2d2f71844",
  "requestParameters": {
    "windowId": "dddddddddddddddddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeMaintenanceWindowTasks

#
Service
ssm

Description

Lists the tasks in a maintenance window.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "1 validation error detected: Value at 'windowId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^mw-[0-9a-f]{17}$",
  "eventCategory": "Management",
  "eventID": "17f0f5f7-fb86-48db-84da-70da3cd516aa",
  "eventName": "DescribeMaintenanceWindowTasks",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:46:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "2f4e570b-41cf-4813-853d-bde1e65ef807",
  "requestParameters": {
    "windowId": "dddddddddddddddddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeOpsItems

#
Service
ssm

Description

Query a set of OpsItems.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: ssm:DescribeOpsItems on resource: arn:aws:ssm:us-east-1:811596193553:*",
  "eventID": "efba09c0-786a-47af-be63-1147d732c1df",
  "eventName": "DescribeOpsItems",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2020-06-10T05:35:37Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "readOnly": true,
  "recipientAccountId": "811596193553",
  "requestID": "e299fdfa-2b7b-47d1-bc2d-5db84418422d",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "251.105.254.1",
  "userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeParameters

#
Service
ssm

Description

Lists the parameters in your Amazon Web Services account or the parameters shared with you when you enable the Shared option.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "ee1aebd5-7f00-4af5-b150-6c13598ce418",
  "eventName": "DescribeParameters",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2023-07-10T11:58:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "5b0be49c-7d15-4cae-99ba-15f7ef95cad3",
  "requestParameters": {
    "maxResults": 10,
    "nextToken": "AAEAASOszR5OBQ4RDciQegOaCl6Zq8rrJIxfnEcfNL/Ewge/AAAAAGSr8mPsv80kHuiSIHxVshJUMtXQoPHxkvZFBz1WzlVHSM37sNKja344OydoFrxGTyHjKxKa+4zBdCjog5HJhnnP5kXewwsCb206xirvHT2aLFq/I0dTKd+YcwC+xN8yJCmR15W5o8+q+xOzYnJ3r2yOnS45AMu0kz6reaneUvnAoOBwj6PgyogUkmkiZgOJzpTxOnQgesT/d2Fs8OSsW/cdhphIB6N/8yptjrgrjrAdXdqZibQB3MAuhZRh3mZPMXgi/VpbeG6qLS5WppEj1OfikloZ0Zp5EhnPydTOOmI37ZlhZFc/b5X6sSYTi+df2/RXTeah096HvrK3z0mIIS0GVu4TwH0ugt3fNlW1WXNP/x3eVffyAQPDeocjDlL8XECE8GRpFD1V3VJvjQ2AJfDbMXvmhItKnhfPBlMZXOA6yr4oAvr88/acdOD7RRc4+4ji9bkY9TXXc6tPJJuydQvKl/XkzpNcTDUMk3YPTKUI79rN8q6e+YAXTTWCXMT2MGEf4jXlt/h9fAV2t3YjQ03Howy/rgbgjBYEd5jb2MiU4OoN/OUuTmw/51KmqZCBTpM3mAxZRsF/AJC52S3EU9fkAowUPzfX8mSTFosMS/dfUvcSITRfnd7KX5WubIDgaELeraALTABGaCvpsyVLYTr5KmpmHsVgE83exL23f+dZBl6OJA==",
    "shared": false
  },
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "stratus-red-team_11a6ef34-e130-4579-a1d3-79c915cee6ec",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribePatchBaselines

#
Service
ssm

Description

Lists the patch baselines in your Amazon Web Services account.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "85414c80-4bcf-4e01-8f50-380461dafb3d",
  "eventName": "DescribePatchBaselines",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2018-10-17T20:32:15Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "readOnly": true,
  "recipientAccountId": "811596193553",
  "requestID": "daec38c9-5b61-4a75-90fe-41497da9ed89",
  "requestParameters": null,
  "resources": [],
  "responseElements": null,
  "sourceIPAddress": "9.245.1.85",
  "userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribePatchGroups

#
Service
ssm

Description

Lists all patch groups that have been registered with patch baselines.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "8f97d241-b703-4f2d-acca-7c09c669b346",
  "eventName": "DescribePatchGroups",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2018-10-17T20:32:15Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "readOnly": true,
  "recipientAccountId": "811596193553",
  "requestID": "4be88d4b-9ff7-470a-be75-e479620a9",
  "requestParameters": null,
  "resources": [],
  "responseElements": null,
  "sourceIPAddress": "9.245.1.85",
  "userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribePatchGroupState

#
Service
ssm

Description

Returns high-level aggregated patch compliance state information for a patch group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "8ffabaca-a4d1-4cd8-a070-26b78af902f3",
  "eventName": "DescribePatchGroupState",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:46:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "6dbceef0-5137-49e1-99b3-274719603363",
  "requestParameters": {
    "patchGroup": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribePatchProperties

#
Service
ssm

Description

Lists the properties of available patches organized by product, product family, classification, severity, and other properties of available patches.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "PatchSet is required when OperatingSystem is Windows and Property is either PRODUCT or PRODUCT_FAMILY",
  "eventCategory": "Management",
  "eventID": "44d39407-edf9-485e-9e2e-86ad7e45951c",
  "eventName": "DescribePatchProperties",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:46:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "4f86c8d9-112b-449b-a980-ea4608c59844",
  "requestParameters": {
    "operatingSystem": "WINDOWS",
    "property": "PRODUCT"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeSessions

#
Service
ssm

Description

Retrieves a list of all active sessions (both connected and disconnected) or terminated sessions from the past 30 days.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "5905a68d-29c4-47b5-9f6c-fdd7d6276500",
  "eventName": "DescribeSessions",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2019-09-12T18:28:17Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "f09a2b35-41ab-42ec-b0e9-7c32ad7e07a4",
  "requestParameters": {
    "state": "History"
  },
  "responseElements": {
    "sessions": []
  },
  "sourceIPAddress": "163.23.3.0",
  "userAgent": "Boto3/1.9.165 Python/3.5.2 Linux/4.15.0-55-generic Botocore/1.12.165",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DisassociateOpsItemRelatedItem

#
Service
ssm

Description

Deletes the association between an OpsItem and a related item.

GetAccessToken

#
Service
ssm

Description

Returns a credentials set to be used with just-in-time node access.

GetAutomationExecution

#
Service
ssm

Description

Get detailed information about a particular Automation execution.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "1 validation error detected: Value at 'automationExecutionId' failed to satisfy constraint: Member must satisfy regular expression pattern: [a-fA-F0-9]{8}-[a-fA-F0-9]{4}-[a-fA-F0-9]{4}-[a-fA-F0-9]{4}-[a-fA-F0-9]{12}",
  "eventCategory": "Management",
  "eventID": "3b52e6d3-87cd-4903-bd61-ee326263423e",
  "eventName": "GetAutomationExecution",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:46:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "0903ba55-7b3e-4c42-8d53-8078d8ae6860",
  "requestParameters": {
    "automationExecutionId": "dddddddddddddddddddddddddddddddddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetCalendarState

#
Service
ssm

Description

Gets the state of a Amazon Web Services Systems Manager change calendar at the current time or a specified time.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidDocument",
  "errorMessage": "The specified Change Calendar Document 'arn:aws:iam::123456789012:role/dw-probe' does not exist.",
  "eventCategory": "Management",
  "eventID": "4fd978f9-67e2-45d6-9a79-81834245cd84",
  "eventName": "GetCalendarState",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:46:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "ec57fd47-b1c8-44e4-acee-e44451631247",
  "requestParameters": {
    "calendarNames": [
      "arn:aws:iam::123456789012:role/dw-probe"
    ]
  },
  "resources": [
    {
      "ARN": "arn:aws:iam::123456789012:role/dw-probe",
      "accountId": "123456789012"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetCommandInvocation

#
Service
ssm

Description

Returns detailed information about command execution for an invocation or plugin.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "1924d89a-7dde-4a0b-8d3d-5de7cce7dd81",
  "eventName": "GetCommandInvocation",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2023-07-10T11:57:21Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "40ac240e-7387-4add-a976-348c3c9854e5",
  "requestParameters": {
    "commandId": "bbf52fc0-1a25-4020-b1b4-1872ff8edd12",
    "instanceId": "i-0dbc91f429e48eeed"
  },
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

GetConnectionStatus

#
Service
ssm

Description

Retrieves the Session Manager connection status for a managed node to determine whether it is running and ready to receive Session Manager connections.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "459c6e28-df93-4e4c-9269-10458a3c971e",
  "eventSource": "ssm.amazonaws.com",
  "eventName": "GetConnectionStatus",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "1f1e3ab6-a28d-46a4-ad66-9fd70df0ceb1",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
  "tlsDetails": {
    "tlsVersion": "TLSv1.2",
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com"
  }
}

GetDefaultPatchBaseline

#
Service
ssm

Description

Retrieves the default patch baseline.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: ssm:GetDefaultPatchBaseline on resource: arn:aws:ssm:us-east-1:811596193553:*",
  "eventID": "dc8bb942-720b-4fbd-82eb-eca30d8f99b5",
  "eventName": "GetDefaultPatchBaseline",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2019-10-19T23:49:26Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "015c66b9-77f3-4b81-b779-624eac37bd01",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "213.253.166.5",
  "userAgent": "Boto3/1.9.210 Python/2.7.10 Darwin/18.7.0 Botocore/1.12.210",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

GetDeployablePatchSnapshotForInstance

#
Service
ssm

Description

Retrieves the current snapshot for the patch baseline the managed node uses.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "5b7e3859-ab93-46ca-9060-16634aadfc75",
  "eventSource": "ssm.amazonaws.com",
  "eventName": "GetDeployablePatchSnapshotForInstance",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "a3aed819-090f-40d0-b5a6-aa419c925a02",
  "userAgent": "Boto3/1.10.50 Python/3.10.12 Linux/5.15.0-1022-aws Botocore/1.13.50",
  "tlsDetails": {
    "tlsVersion": "TLSv1.2",
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com"
  }
}

GetDocument

#
Service
ssm

Description

Gets the contents of the specified Amazon Web Services Systems Manager document (SSM document).

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "ea812b7e-ebeb-4950-8dc8-a4a9af56a8c6",
  "eventName": "GetDocument",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2023-07-10T11:57:45Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "9c938fe7-19f8-4c55-bbf0-34380b80558e",
  "requestParameters": {
    "documentVersion": "1",
    "name": "AWS-GatherSoftwareInventory"
  },
  "responseElements": null,
  "sourceIPAddress": "3.225.16.109",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "aws-sdk-go/1.41.4 (go1.18.3; linux; amd64) amazon-ssm-agent/",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCSHSEVYP5",
    "accountId": "123837392027",
    "arn": "arn:aws:sts::123837392027:assumed-role/stratus-red-team-ec2-steal-credentials-role/i-0dbc91f429e48eeed",
    "principalId": "AROATFQR7NSC6Q6YRQ2Q7:i-0dbc91f429e48eeed",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T11:55:22Z",
        "mfaAuthenticated": "false"
      },
      "ec2RoleDelivery": "2.0",
      "sessionIssuer": {
        "accountId": "123837392027",
        "arn": "arn:aws:iam::123837392027:role/stratus-red-team-ec2-steal-credentials-role",
        "principalId": "AROATFQR7NSC6Q6YRQ2Q7",
        "type": "Role",
        "userName": "stratus-red-team-ec2-steal-credentials-role"
      },
      "webIdFederationData": {}
    },
    "type": "AssumedRole"
  }
}

References #

GetExecutionPreview

#
Service
ssm

Description

Initiates the process of retrieving an existing preview that shows the effects that running a specified Automation runbook would have on the targeted resources.

GetMaintenanceWindow

#
Service
ssm

Description

Retrieves a maintenance window.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "1 validation error detected: Value at 'windowId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^mw-[0-9a-f]{17}$",
  "eventCategory": "Management",
  "eventID": "45077c58-9f2e-4b9d-b33d-4ff6b52ff487",
  "eventName": "GetMaintenanceWindow",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:46:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "e9020eb6-c427-4cb1-9388-b78fbe2a08a9",
  "requestParameters": {
    "windowId": "dddddddddddddddddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetMaintenanceWindowExecution

#
Service
ssm

Description

Retrieves details about a specific a maintenance window execution.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "1 validation error detected: Value at 'windowExecutionId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[0-9a-fA-F]{8}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{12}$",
  "eventCategory": "Management",
  "eventID": "0d0f3dae-54bf-4bcb-b662-2f283928f41a",
  "eventName": "GetMaintenanceWindowExecution",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:46:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "e5bc1bdf-1029-4485-b591-14ca5c81dcab",
  "requestParameters": {
    "windowExecutionId": "dddddddddddddddddddddddddddddddddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetMaintenanceWindowExecutionTask

#
Service
ssm

Description

Retrieves the details about a specific task run as part of a maintenance window execution.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "2 validation errors detected: Value at 'windowExecutionId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[0-9a-fA-F]{8}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{12}$; Value at 'taskId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[0-9a-fA-F]{8}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{12}$",
  "eventCategory": "Management",
  "eventID": "ea842d48-1217-4d16-b75f-39ddd545e015",
  "eventName": "GetMaintenanceWindowExecutionTask",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:46:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "eb72bb43-0e10-4c42-9d92-31a317cb0ef4",
  "requestParameters": {
    "taskId": "dddddddddddddddddddddddddddddddddddd",
    "windowExecutionId": "dddddddddddddddddddddddddddddddddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetMaintenanceWindowExecutionTaskInvocation

#
Service
ssm

Description

Retrieves information about a specific task running on a specific target.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "3 validation errors detected: Value at 'windowExecutionId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[0-9a-fA-F]{8}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{12}$; Value at 'invocationId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[0-9a-fA-F]{8}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{12}$; Value at 'taskId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[0-9a-fA-F]{8}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{12}$",
  "eventCategory": "Management",
  "eventID": "c72ba639-4e8d-4203-9129-23b8ec045ffc",
  "eventName": "GetMaintenanceWindowExecutionTaskInvocation",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:46:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "57406dfd-2369-4d62-9046-1a0219845cc4",
  "requestParameters": {
    "invocationId": "dddddddddddddddddddddddddddddddddddd",
    "taskId": "dddddddddddddddddddddddddddddddddddd",
    "windowExecutionId": "dddddddddddddddddddddddddddddddddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetMaintenanceWindowTask

#
Service
ssm

Description

Retrieves the details of a maintenance window task.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "2 validation errors detected: Value at 'windowTaskId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[0-9a-fA-F]{8}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{12}$; Value at 'windowId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^mw-[0-9a-f]{17}$",
  "eventCategory": "Management",
  "eventID": "06988c06-f6e0-4b35-93cf-21068a4e77bf",
  "eventName": "GetMaintenanceWindowTask",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:46:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "6012130e-4b13-45cf-b03d-b841a3fe4323",
  "requestParameters": {
    "windowId": "dddddddddddddddddddd",
    "windowTaskId": "dddddddddddddddddddddddddddddddddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetOpsItem

#
Service
ssm

Description

Get information about an OpsItem by using the ID.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "6387aaa4-a35f-4c35-a434-82bc3eef1785",
  "eventSource": "ssm.amazonaws.com",
  "eventName": "GetOpsItem",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "bcea32ff-2ab7-4a20-be19-7fe004be0514",
  "userAgent": "opsinsights.ssm.amazonaws.com"
}

GetOpsMetadata

#
Service
ssm

Description

View operational metadata related to an application in Application Manager.

GetOpsSummary

#
Service
ssm

Description

View a summary of operations metadata (OpsData) based on specified filters and aggregators.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "0bf3916b-6cff-406d-8235-16afaa42499e",
  "eventName": "GetOpsSummary",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:32:46Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "0614a0e3-52f1-4aa4-8c9c-824dbaddf82d",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetParameterHistory

#
Service
ssm

Description

Retrieves the history of all changes to a parameter.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "f2f3f6af-a0ef-4f21-9594-580a3b123b46",
  "eventName": "GetParameterHistory",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:46:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "1e6144d3-977a-4138-a07d-3b10086ad981",
  "requestParameters": {
    "name": "ddddd"
  },
  "resources": [
    {
      "ARN": "arn:aws:ssm:us-west-1:123456789012:parameter/ddddd",
      "accountId": "123456789012"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetParametersByPath

#
Service
ssm

Description

Retrieve information about one or more parameters under a specified level in a hierarchy.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "2b902d6c-9f41-40bd-8ffb-6c2715455b75",
  "eventName": "GetParametersByPath",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:46:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "18ffda17-3388-43b9-a561-e53d4d781953",
  "requestParameters": {
    "path": "ddddd"
  },
  "resources": [
    {
      "ARN": "arn:aws:ssm:us-west-1:123456789012:parameter/ddddd",
      "accountId": "123456789012"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetPatchBaseline

#
Service
ssm

Description

Retrieves information about a patch baseline.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "8fffe675-27cc-4918-be98-04d32618ff46",
  "eventSource": "ssm.amazonaws.com",
  "eventName": "GetPatchBaseline",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "dc2a74a5-3473-402c-b9f8-5f172ca91ae8",
  "userAgent": "Boto3/1.42.97 md/Botocore#1.42.97 ua/2.1 os/linux#5.10.255-259-299.1043.amzn2.x86_64 md/arch#x86_64 lang/python#3.11.15 md/pyimpl#CPython exec-env/AWS_Lambda_python3.11 m/D,b,Z cfg/retry-mode#legacy Botocore/1.42.97",
  "tlsDetails": {
    "tlsVersion": "TLSv1.2",
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com"
  }
}

GetPatchBaselineForPatchGroup

#
Service
ssm

Description

Retrieves the patch baseline that should be used for the specified patch group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "33487ccb-e581-4312-ab78-943dd17eff39",
  "eventName": "GetPatchBaselineForPatchGroup",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:46:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "9318aa52-6603-4538-8d28-f2a670e4afae",
  "requestParameters": {
    "patchGroup": "ddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetResourcePolicies

#
Service
ssm

Description

Returns an array of the Policy object.

GetServiceSetting

#
Service
ssm

Description

ServiceSetting is an account-level setting for an Amazon Web Services service.

Example CloudTrail Event #

{
  "awsRegion": "us-east-2",
  "eventCategory": "Management",
  "eventID": "a7fa27fa-0712-487d-940c-c78e25b97068",
  "eventName": "GetServiceSetting",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2021-07-07T19:58:36Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "797507667711",
  "requestID": "5fe799a7-891e-4d03-9515-621d78935473",
  "requestParameters": {
    "settingId": "/ssm/opsdata/Association"
  },
  "resources": [
    {
      "ARN": "arn:aws:ssm:us-east-2:797507667711:servicesetting/ssm/opsdata/Association",
      "accountId": "797507667711"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "ssm.amazonaws.com",
  "userAgent": "ssm.amazonaws.com",
  "userIdentity": {
    "accessKeyId": "ASIA3TLZJI37ZGYXYJR6",
    "accountId": "797507667711",
    "arn": "arn:aws:sts::797507667711:assumed-role/AWSServiceRoleForAmazonSSM/SSMExplorerOnboarding",
    "invokedBy": "ssm.amazonaws.com",
    "principalId": "AROA3TLZJI375YZ4W5JE6:SSMExplorerOnboarding",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-07-07T19:58:36Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {
        "accountId": "797507667711",
        "arn": "arn:aws:iam::797507667711:role/aws-service-role/ssm.amazonaws.com/AWSServiceRoleForAmazonSSM",
        "principalId": "AROA3TLZJI375YZ4W5JE6",
        "type": "Role",
        "userName": "AWSServiceRoleForAmazonSSM"
      },
      "webIdFederationData": {}
    },
    "type": "AssumedRole"
  }
}

References #

LabelParameterVersion

#
Service
ssm

Description

A parameter label is a user-defined alias to help you manage different versions of a parameter.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "918605c3-889a-4242-9478-480168544f7f",
  "eventName": "LabelParameterVersion",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T19:12:21Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "c8bb2d96-1300-4b63-b25e-ce7fc5e9bb9f",
  "requestParameters": {
    "labels": [
      "dw"
    ],
    "name": "/dwfix/p"
  },
  "resources": [
    {
      "ARN": "arn:aws:ssm:us-west-1:123456789012:parameter/dwfix/p",
      "accountId": "123456789012"
    }
  ],
  "responseElements": {
    "invalidLabels": [],
    "parameterVersion": 1
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListAssociations

#
Service
ssm

Description

Returns all State Manager associations in the current Amazon Web Services account and Amazon Web Services Region.

Example CloudTrail Event #

{
  "awsRegion": "sa-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::731544447609:user/cloudsploit is not authorized to perform: ssm:ListAssociations on resource: arn:aws:ssm:sa-east-1:731544447609:*",
  "eventCategory": "Management",
  "eventID": "ef889ee9-73ab-4dad-8072-ac683b51ea3a",
  "eventName": "ListAssociations",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2021-04-13T11:35:43Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "731544447609",
  "requestID": "47d6788d-473e-40f6-8944-18a79cc15602",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "34.12.134.20",
  "userAgent": "aws-sdk-nodejs/2.885.0 linux/v14.16.1 callback",
  "userIdentity": {
    "accessKeyId": "AKIAYTOGP2RLGBSBSMH2",
    "accountId": "731544447609",
    "arn": "arn:aws:iam::731544447609:user/cloudsploit",
    "principalId": "AIDAYTOGP2RLMDEPWZWMJ",
    "type": "IAMUser",
    "userName": "cloudsploit"
  }
}

References #

ListAssociationVersions

#
Service
ssm

Description

Retrieves all versions of an association for a specific association ID.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "1 validation error detected: Value 'dw-probe' at 'associationId' failed to satisfy constraint: Member must satisfy regular expression pattern: [0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}",
  "eventCategory": "Management",
  "eventID": "2fb30cf4-a03f-411e-abb1-0f05bf100bed",
  "eventName": "ListAssociationVersions",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:46:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "edea72e1-36d3-4577-a816-d14e661f23db",
  "requestParameters": {
    "associationId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListCommandInvocations

#
Service
ssm

Description

An invocation is copy of a command sent to a specific managed node.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: ssm:ListCommandInvocations on resource: arn:aws:ssm:us-east-1:811596193553:*",
  "eventID": "7d79776b-f8e7-44be-8237-7eece17704bf",
  "eventName": "ListCommandInvocations",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2019-10-19T23:49:23Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "readOnly": true,
  "recipientAccountId": "811596193553",
  "requestID": "ec4ef62c-d4ff-4883-bde8-b615e67bfc35",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "213.253.166.5",
  "userAgent": "Boto3/1.9.210 Python/2.7.10 Darwin/18.7.0 Botocore/1.12.210",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

ListComplianceItems

#
Service
ssm

Description

For a specified resource ID, this API operation returns a list of compliance statuses for different resource types.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: ssm:ListComplianceItems on resource: arn:aws:ssm:us-east-1:811596193553:*",
  "eventID": "0f7e1e45-cdb1-41b4-b2df-7d0db13e5527",
  "eventName": "ListComplianceItems",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2019-10-19T23:49:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "a40634d-fc1d-44ec-9210-e5a630bc9583",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "213.253.166.5",
  "userAgent": "Boto3/1.9.210 Python/2.7.10 Darwin/18.7.0 Botocore/1.12.210",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

ListComplianceSummaries

#
Service
ssm

Description

Returns a summary count of compliant and non-compliant resources for a compliance type.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: ssm:ListComplianceSummaries on resource: arn:aws:ssm:us-east-1:811596193553:*",
  "eventID": "2147ef0b-dd43-435a-be6a-4b4da446275a",
  "eventName": "ListComplianceSummaries",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2019-10-19T23:49:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "readOnly": true,
  "recipientAccountId": "811596193553",
  "requestID": "95d5664b-07c1-47ac-a0d4-d0bfeff68a88",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "213.253.166.5",
  "userAgent": "Boto3/1.9.210 Python/2.7.10 Darwin/18.7.0 Botocore/1.12.210",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

ListDocumentMetadataHistory

#
Service
ssm

Description

Amazon Web Services Systems Manager Change Manager is no longer open to new customers.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidDocument",
  "errorMessage": "Document with name dw-probe does not exist.",
  "eventCategory": "Management",
  "eventID": "bc19ba25-7d44-43c2-9892-a022f07b389a",
  "eventName": "ListDocumentMetadataHistory",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:46:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "a7a2a78f-13b2-4f3c-943d-c43e0b899dd4",
  "requestParameters": {
    "metadata": "DocumentReviews",
    "name": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListDocuments

#
Service
ssm

Description

Returns all Systems Manager (SSM) documents in the current Amazon Web Services account and Amazon Web Services Region.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "eventID": "60232-d234-43c5-ad0a-9899a814c45c",
  "eventName": "ListDocuments",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2018-02-24T14:07:04Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.04",
  "readOnly": true,
  "recipientAccountId": "811596193553",
  "requestID": "fde8fe19-196b-11e8-bd17-6353eb759645a",
  "requestParameters": {
    "nextToken": "AAMAAe3kWXUBkOucQH5dRt07QpFarDfzafvljnZRFBkhaIYtAAAAAFqRcYhiGccbGS4Cy4b/kW1KfoXNoY8eBMZzHfplgc+WHv2jNXbl8YFgM9vt5+VC4QkTVrB+1F1Rxg6rVBsdRawI6yL6kyTBHZkzoR6l0hV+xs7VqA8SrRlz4U3SndVhK0Mp6fGbgf/ZRGXgn03rXeYJGlqEOWGNIB7qdVRhxzGtVfRVz6hgH72U4QZGBzH3Qv5UBfvkBShvnWfeuFqddE0p9Iocu2LDIU/6WTN486HQOG+/dpDDZ3v0HwPbjo4T7ouvEEIWv8wD3yK3R8FI9iwDQE2Ir9v/PH+t1RsBA1JcAxEclxE+YgdREOpgLeSOoivNVsbD91qam4nQgeBwo5azJyUoj3afDK+/Ngjqu/nRfmit8AqFypbqxzp/LLAABdWLf80vZ04D5fWsUgpUVeWseT5mzLEuDR3Cc54w+cqrz+RAW3Ea0rWha5198UzceqtKRtbssNTVfDMjyZyLQeRb2yjgE74KLb8fCVtQoOVeNpPGXAAFPme3uWoJVzY2jnbbQXoRABA2Ly/R2/0xSimeWth4BTSo8pAqUm4cjsy24E8nJHC5QAbI3LoPqqDoa+7Bb+QvLbLhcUr+4NGgW3G0JBiw6u1lonNMtAI0fhkFWd6z1zPYoBrEpgIpjjWwNOM/bA3cyrfSvzY+nM/HLJcktUhKKoCr88Ua7L6CzMbEGFkRKXesS/4OtBDEdhoXCWRcyAKbICXx0Zg7yjhtyO0ZCQo5pYaYj5g1b3iL1kl6C9BQ2zKbUYjBbsi/3KKFCh8OXjG7T1+9HK3F3BTfWeIehbkP"
  },
  "resources": [],
  "responseElements": null,
  "sourceIPAddress": "245.181.7.4",
  "userAgent": "aws-cli/1.14.44 Python/3.6.4 Linux/4.15.5-1-ARCH botocore/1.8.48",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

ListDocumentVersions

#
Service
ssm

Description

List all versions for a document.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidDocument",
  "errorMessage": "Invalid document name arn:aws:iam::123456789012:role/dw-probe",
  "eventCategory": "Management",
  "eventID": "6bb5f39a-8886-4277-9618-6e296bfb3118",
  "eventName": "ListDocumentVersions",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:46:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "40ae5b39-56d1-4f83-ae72-ab1c7d6ed24e",
  "requestParameters": {
    "name": "arn:aws:iam::123456789012:role/dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListNodes

#
Service
ssm

Description

Takes in filters and returns a list of managed nodes matching the filter criteria.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "UnsupportedOperationException",
  "errorMessage": "This is an unsupported operation for this account. You must first enable the Systems Manager integrated experience in your account.",
  "eventCategory": "Management",
  "eventID": "210d0fbe-4a61-424d-bec1-18fcfce6c626",
  "eventName": "ListNodes",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:32:46Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "c189b705-d5a3-4dda-b12e-c20a1f48e5a8",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListNodesSummary

#
Service
ssm

Description

Generates a summary of managed instance/node metadata based on the filters and aggregators you specify.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "UnsupportedOperationException",
  "errorMessage": "This is an unsupported operation for this account. You must first enable the Systems Manager integrated experience in your account.",
  "eventCategory": "Management",
  "eventID": "2057032f-6bbc-4484-af8c-1fcd25607cff",
  "eventName": "ListNodesSummary",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:46:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "4ea4c824-4517-435a-8f32-f90f6ac9558a",
  "requestParameters": {
    "aggregators": [
      {
        "aggregatorType": "Count",
        "attributeName": "AgentVersion",
        "typeName": "Instance"
      }
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListOpsItemEvents

#
Service
ssm

Description

Returns a list of all OpsItem events in the current Amazon Web Services Region and Amazon Web Services account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "862dffed-f98b-4d37-b228-f54b9c22fd7b",
  "eventName": "ListOpsItemEvents",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:32:46Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "d578a3de-91f3-4012-aa89-44229583c9f8",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListOpsItemRelatedItems

#
Service
ssm

Description

Lists all related-item resources associated with a Systems Manager OpsCenter OpsItem.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "OpsItemInvalidParameterException",
  "errorMessage": "OpsItemId is required. (Service: AmazonSSM; Status Code: 400; Error Code: OpsItemInvalidParameterException; Request ID: a187a736-8acb-4cef-8f23-8c26aa66bc4c; Proxy: null)",
  "eventCategory": "Management",
  "eventID": "1e3a16fd-47fb-48a4-9311-651bf35267fb",
  "eventName": "ListOpsItemRelatedItems",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:32:46Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "a187a736-8acb-4cef-8f23-8c26aa66bc4c",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListOpsMetadata

#
Service
ssm

Description

Amazon Web Services Systems Manager calls this API operation when displaying all Application Manager OpsMetadata objects or blobs.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "a32c61f6-1143-40d0-a972-d97f99a26138",
  "eventName": "ListOpsMetadata",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T18:32:46Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "986428f4-dd74-4f10-a636-3eba8108cbec",
  "requestParameters": null,
  "resources": [
    {
      "ARN": "arn:aws:ssm:us-west-1:123456789012:*",
      "accountId": "123456789012"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListResourceComplianceSummaries

#
Service
ssm

Description

Returns a resource-level summary count.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: ssm:ListResourceComplianceSummaries on resource: arn:aws:ssm:us-east-1:811596193553:*",
  "eventID": "47a49d91-a9e3-4884-a6f7-23b5bf412ee2",
  "eventName": "ListResourceComplianceSummaries",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2019-10-19T23:49:23Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "readOnly": true,
  "recipientAccountId": "811596193553",
  "requestID": "39a495819-162a-4676-90e8-f2f8af5f9277",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "213.253.166.5",
  "userAgent": "Boto3/1.9.210 Python/2.7.10 Darwin/18.7.0 Botocore/1.12.210",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

ListResourceDataSync

#
Service
ssm

Description

Lists your resource data sync configurations.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: ssm:ListResourceDataSync on resource: arn:aws:ssm:us-east-1:811596193553:*",
  "eventID": "d9ead80c-d6ed-4cae-8597-488012ffc08",
  "eventName": "ListResourceDataSync",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2019-10-19T23:49:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "bd465ced-0b26-47d5-b95b-5f2d50c66aa4",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "213.253.166.5",
  "userAgent": "Boto3/1.9.210 Python/2.7.10 Darwin/18.7.0 Botocore/1.12.210",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

ListTagsForResource

#
Service
ssm

Description

Returns a list of the tags assigned to the specified resource.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "46499e1d-8ecf-4bab-9042-c6c23ce59271",
  "eventName": "ListTagsForResource",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2023-07-10T11:58:11Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "3b42bf16-d5eb-4b7e-87e5-6736d2bcf06a",
  "requestParameters": {
    "resourceId": "/credentials/stratus-red-team/credentials-30",
    "resourceType": "Parameter"
  },
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_11a6ef34-e130-4579-a1d3-79c915cee6ec HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

ModifyDocumentPermission

#
Service
ssm

Description

Shares a Amazon Web Services Systems Manager document (SSM document)publicly or privately.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidParameterException",
  "errorMessage": "Either AccountIdsToAdd or AccountIdsToRemove must be specified for API operation",
  "eventCategory": "Management",
  "eventID": "4f71bac2-52b3-47dd-b886-6b74aac101c6",
  "eventName": "ModifyDocumentPermission",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T19:26:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "c89c69a5-6fe0-4319-a1f8-086b3fdcb9c2",
  "requestParameters": {
    "name": "dw-probe",
    "permissionType": "Share"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

PutComplianceItems

#
Service
ssm

Description

Registers a compliance type and other compliance details on a designated resource.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "46041132-1dd7-49f5-88af-4b3f3521f861",
  "eventName": "PutComplianceItems",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2023-07-10T11:58:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "7fd23164-de26-4f96-bd5f-0ddf9d425657",
  "requestParameters": {
    "complianceType": "Association",
    "executionSummary": {
      "executionId": "",
      "executionTime": "Jul 10, 2023, 11:58:13 AM",
      "executionType": ""
    },
    "itemContentHash": "69y67YXkh+2LwNYisaGL/A==",
    "items": [
      {
        "details": {
          "DocumentName": "AWS-GatherSoftwareInventory",
          "DocumentVersion": "1"
        },
        "id": "56fcb26d-8140-4f3f-8f77-7ff7344b4057",
        "severity": "UNSPECIFIED",
        "status": "COMPLIANT",
        "title": ""
      }
    ],
    "resourceId": "i-0dbc91f429e48eeed",
    "resourceType": "ManagedInstance"
  },
  "responseElements": null,
  "sourceIPAddress": "3.225.16.109",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "aws-sdk-go/1.41.4 (go1.18.3; linux; amd64) amazon-ssm-agent/",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCSHSEVYP5",
    "accountId": "123837392027",
    "arn": "arn:aws:sts::123837392027:assumed-role/stratus-red-team-ec2-steal-credentials-role/i-0dbc91f429e48eeed",
    "principalId": "AROATFQR7NSC6Q6YRQ2Q7:i-0dbc91f429e48eeed",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T11:55:22Z",
        "mfaAuthenticated": "false"
      },
      "ec2RoleDelivery": "2.0",
      "sessionIssuer": {
        "accountId": "123837392027",
        "arn": "arn:aws:iam::123837392027:role/stratus-red-team-ec2-steal-credentials-role",
        "principalId": "AROATFQR7NSC6Q6YRQ2Q7",
        "type": "Role",
        "userName": "stratus-red-team-ec2-steal-credentials-role"
      },
      "webIdFederationData": {}
    },
    "type": "AssumedRole"
  }
}

References #

PutInventory

#
Service
ssm

Description

Bulk update custom inventory items on one or more managed nodes.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "7e486988-6d22-4c5d-9b55-eba68b0f23d9",
  "eventName": "PutInventory",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2023-07-10T11:58:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "dbb09c3f-9e39-478c-a0ec-515fd3aa4a2a",
  "requestParameters": {
    "instanceId": "i-0dbc91f429e48eeed",
    "items": [
      {
        "captureTime": "2023-07-10T11:57:45Z",
        "contentHash": "lDHZTHFNUyHYPLo8R7wPSA==",
        "schemaVersion": "1.0",
        "typeName": "AWS:Network"
      },
      {
        "captureTime": "2023-07-10T11:57:45Z",
        "contentHash": "N6YlnMDB2uKZp4Zkid/wvQ==",
        "schemaVersion": "1.0",
        "typeName": "AWS:BillingInfo"
      },
      {
        "captureTime": "2023-07-10T11:57:45Z",
        "contentHash": "omMpn3JVX/I6oe7BzY9EFA==",
        "schemaVersion": "1.0",
        "typeName": "AWS:InstanceDetailedInformation"
      },
      {
        "captureTime": "2023-07-10T11:57:45Z",
        "contentHash": "M1LVyOGk7deedu/aVytRVg==",
        "schemaVersion": "1.1",
        "typeName": "AWS:Application"
      },
      {
        "captureTime": "2023-07-10T11:57:46Z",
        "contentHash": "DLq350DMx3pp69NF6sJlfg==",
        "schemaVersion": "1.0",
        "typeName": "AWS:AWSComponent"
      }
    ]
  },
  "resources": [
    {
      "ARN": "arn:aws:ec2:us-east-1:123837392027:instance/i-0dbc91f429e48eeed",
      "accountId": "123837392027"
    },
    {
      "ARN": "arn:aws:ssm:us-east-1:123837392027:managed-instance-inventory/i-0dbc91f429e48eeed",
      "accountId": "123837392027"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "3.225.16.109",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "aws-sdk-go/1.41.4 (go1.18.3; linux; amd64) amazon-ssm-agent/",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCSHSEVYP5",
    "accountId": "123837392027",
    "arn": "arn:aws:sts::123837392027:assumed-role/stratus-red-team-ec2-steal-credentials-role/i-0dbc91f429e48eeed",
    "principalId": "AROATFQR7NSC6Q6YRQ2Q7:i-0dbc91f429e48eeed",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T11:55:22Z",
        "mfaAuthenticated": "false"
      },
      "ec2RoleDelivery": "2.0",
      "sessionIssuer": {
        "accountId": "123837392027",
        "arn": "arn:aws:iam::123837392027:role/stratus-red-team-ec2-steal-credentials-role",
        "principalId": "AROATFQR7NSC6Q6YRQ2Q7",
        "type": "Role",
        "userName": "stratus-red-team-ec2-steal-credentials-role"
      },
      "webIdFederationData": {}
    },
    "type": "AssumedRole"
  }
}

References #

PutParameter

#
Service
ssm

Description

Create or update a parameter in Parameter Store.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "93e58a50-11f0-4859-8f1c-472dd35a1aeb",
  "eventName": "PutParameter",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2023-07-10T11:58:10Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "4e963a0b-fe4a-4928-a618-f37cc2f04f61",
  "requestParameters": {
    "allowedPattern": "",
    "name": "/credentials/stratus-red-team/credentials-34",
    "overwrite": false,
    "tags": [
      {
        "key": "StratusRedTeam",
        "value": "true"
      }
    ],
    "tier": "Standard",
    "type": "SecureString",
    "value": "HIDDEN_DUE_TO_SECURITY_REASONS"
  },
  "resources": [
    {
      "ARN": "arn:aws:ssm:us-east-1:123837392027:parameter/credentials/stratus-red-team/credentials-34",
      "accountId": "123837392027"
    }
  ],
  "responseElements": {
    "tier": "Standard",
    "version": 1
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_11a6ef34-e130-4579-a1d3-79c915cee6ec HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

PutResourcePolicy

#
Service
ssm

Description

Creates or updates a Systems Manager resource policy.

RegisterDefaultPatchBaseline

#
Service
ssm

Description

Defines the default patch baseline for the relevant operating system.

RegisterPatchBaselineForPatchGroup

#
Service
ssm

Description

Registers a patch baseline for a patch group.

RegisterTargetWithMaintenanceWindow

#
Service
ssm

Description

Registers a target with a maintenance window.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "30f8c38e-0d52-4939-89a4-b0cae787dfad",
  "eventName": "RegisterTargetWithMaintenanceWindow",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T20:58:55Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "12b65194-3b50-42d9-883b-4ad33ca05cd5",
  "requestParameters": {
    "clientToken": "c40ee37d-33ed-48a5-80f9-a58c651cdef1",
    "description": "HIDDEN_DUE_TO_SECURITY_REASONS",
    "name": "dwfix-target-ea8e728b",
    "ownerInformation": "HIDDEN_DUE_TO_SECURITY_REASONS",
    "resourceType": "INSTANCE",
    "targets": [
      {
        "key": "tag:Env",
        "values": [
          "dwfix"
        ]
      }
    ],
    "windowId": "mw-06e8430a431fc17a1"
  },
  "resources": [
    {
      "ARN": "arn:aws:ssm:us-west-1:123456789012:maintenancewindow/mw-06e8430a431fc17a1",
      "accountId": "123456789012"
    }
  ],
  "responseElements": {
    "windowTargetId": "3ab5475a-c068-4c44-b46a-749da462f21b"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b,n cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

RegisterTaskWithMaintenanceWindow

#
Service
ssm

Description

Adds a new task to a maintenance window.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "Maintenance window tasks without targets do not support MaxErrors values. For Run Command tasks, you must specify at least one resource as the target of the task. You can specify between 1 and 50 instance IDs, or between 1 and 10 maintenance window target IDs. Maintenance window tasks without targets do not support MaxConcurrency values.",
  "eventCategory": "Management",
  "eventID": "1410be51-7e30-4deb-aede-af8d9791c5a4",
  "eventName": "RegisterTaskWithMaintenanceWindow",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T20:58:55Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "526d7ab8-2294-4c57-87e0-71908ca07b45",
  "requestParameters": {
    "clientToken": "88c38243-5421-4438-8a09-97b09c1792db",
    "description": "HIDDEN_DUE_TO_SECURITY_REASONS",
    "maxConcurrency": "1",
    "maxErrors": "1",
    "name": "dwfix-task-ea8e728b",
    "priority": 1,
    "serviceRoleArn": "arn:aws:iam::123456789012:role/aws-service-role/ssm.amazonaws.com/AWSServiceRoleForAmazonSSM",
    "taskArn": "AWS-RunShellScript",
    "taskType": "RUN_COMMAND",
    "windowId": "mw-06e8430a431fc17a1"
  },
  "resources": [
    {
      "ARN": "arn:aws:ssm:us-west-1:123456789012:maintenancewindow/mw-06e8430a431fc17a1",
      "accountId": "123456789012"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b,n cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

RemoveTagsFromResource

#
Service
ssm

Description

Removes tag keys from the specified resource.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "dfd91567-fd3c-400e-bfb5-96728468f2ef",
  "eventName": "RemoveTagsFromResource",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T19:12:21Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "25c60b07-6361-46fe-98e3-a9207965dd74",
  "requestParameters": {
    "resourceId": "/dwfix/p",
    "resourceType": "Parameter",
    "tagKeys": [
      "dw"
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ResetServiceSetting

#
Service
ssm

Description

ServiceSetting is an account-level setting for an Amazon Web Services service.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "98cd697c-4a80-4825-904b-2dca1915e50f",
  "eventName": "ResetServiceSetting",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T19:26:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "2a9e2d04-a426-47a7-98a3-e74944be8e94",
  "requestParameters": {
    "settingId": "ddddd"
  },
  "resources": [
    {
      "ARN": "arn:aws:ssm:us-west-1:123456789012:servicesetting/ddddd",
      "accountId": "123456789012"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ResumeSession

#
Service
ssm

Description

Reconnects a session to a managed node after it has been disconnected.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::123456789012:user/TrailDiscover is not authorized to perform: ssm:ResumeSession on resource: arn:aws:ssm:us-east-1:192374575148:session/TrailDiscoverTarget because no identity-based policy allows the ssm:ResumeSession action",
  "eventCategory": "Management",
  "eventID": "414dacad-43e6-4327-aec8-dcb0caacc5dc",
  "eventName": "ResumeSession",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2024-08-18T16:13:21Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "219e0244-a4ea-40b8-b870-059954972199",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "0.0.0.0",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "aws-cli/2.17.32 md/awscrt#0.21.2 ua/2.0 os/linux#0.0.0.0-microsoft-standard-WSL2 md/arch#x86_64 lang/python#3.11.9 md/pyimpl#CPython exec-env/grimoire_f303ce4d-3e7b-43b5-84c0-0b58b10696c7 cfg/retry-mode#standard md/installer#exe md/distrib#ubuntu.24 md/prompt#off md/command#ssm.resume-session",
  "userIdentity": {
    "accessKeyId": "AKIA****************",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/TrailDiscover",
    "principalId": "AROA****************:User",
    "type": "IAMUser",
    "userName": "TrailDiscover"
  }
}

References #

SendAutomationSignal

#
Service
ssm

Description

Sends a signal to an Automation execution to change the current behavior or status of the execution.

StartAccessRequest

#
Service
ssm

Description

Starts the workflow for just-in-time node access sessions.

StartAssociationsOnce

#
Service
ssm

Description

Runs an association immediately and only one time.

StartAutomationExecution

#
Service
ssm

Description

Initiates execution of an Automation runbook.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "be7076b9-e1ef-4df6-bc02-554ad9d66772",
  "eventName": "StartAutomationExecution",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T20:58:57Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "42a9e32d-7e21-4c8d-a9a6-fb112dbca24b",
  "requestParameters": {
    "documentName": "dwfix-auto-ea8e728b"
  },
  "responseElements": {
    "automationExecutionId": "42a9e32d-7e21-4c8d-a9a6-fb112dbca24b"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b,n cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

StartChangeRequestExecution

#
Service
ssm

Description

Amazon Web Services Systems Manager Change Manager is no longer open to new customers.

StartExecutionPreview

#
Service
ssm

Description

Initiates the process of creating a preview showing the effects that running a specified Automation runbook would have on the targeted resources.

StopAutomationExecution

#
Service
ssm

Description

Stop an Automation that is currently running.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "1 validation error detected: Value at 'automationExecutionId' failed to satisfy constraint: Member must satisfy regular expression pattern: [a-fA-F0-9]{8}-[a-fA-F0-9]{4}-[a-fA-F0-9]{4}-[a-fA-F0-9]{4}-[a-fA-F0-9]{12}",
  "eventCategory": "Management",
  "eventID": "0a191570-c4ee-4776-9f51-a93a32a674f2",
  "eventName": "StopAutomationExecution",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T19:26:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7190c664-5bec-467c-9885-f99ec7dcf184",
  "requestParameters": {
    "automationExecutionId": "dddddddddddddddddddddddddddddddddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

TerminateSession

#
Service
ssm

Description

Permanently ends a session and closes the data connection between the Session Manager client and SSM Agent on the managed node.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "c14df3be-a906-4152-a0a7-341bb558429a",
  "eventName": "TerminateSession",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T19:26:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7bb193be-b85b-4c5f-9476-36a846eac031",
  "requestParameters": {
    "sessionId": "ddddd"
  },
  "responseElements": {
    "sessionId": "ddddd"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UnlabelParameterVersion

#
Service
ssm

Description

Remove a label or labels from a parameter.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "f00c75a8-84f0-42ba-81df-2e92da955dcb",
  "eventName": "UnlabelParameterVersion",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T20:58:56Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "eef66032-4de5-4dd3-97dc-1e786eb548f5",
  "requestParameters": {
    "labels": [
      "dwfixlblea8e728b"
    ],
    "name": "/dwfix/param/ea8e728b",
    "parameterVersion": 1
  },
  "resources": [
    {
      "ARN": "arn:aws:ssm:us-west-1:123456789012:parameter/dwfix/param/ea8e728b",
      "accountId": "123456789012"
    }
  ],
  "responseElements": {
    "invalidLabels": [
      "dwfixlblea8e728b"
    ],
    "removedLabels": []
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b,n cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateAssociation

#
Service
ssm

Description

Updates an association.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "51d8f81c-255e-460e-83f0-e778789b09ce",
  "eventName": "UpdateAssociation",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T19:25:26Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "8c59f498-6037-46fe-bc9c-ed2d278c5ae8",
  "requestParameters": {
    "applyOnlyAtCronInterval": false,
    "associationId": "c93a05c3-e24a-4016-a7bf-51d1b9a6a740",
    "parameters": "HIDDEN_DUE_TO_SECURITY_REASONS"
  },
  "responseElements": {
    "associationDescription": {
      "applyOnlyAtCronInterval": false,
      "associationId": "c93a05c3-e24a-4016-a7bf-51d1b9a6a740",
      "associationVersion": "2",
      "date": "2026-06-29T19:25:26Z",
      "documentVersion": "$DEFAULT",
      "lastExecutionDate": "2026-06-29T19:25:26Z",
      "lastSuccessfulExecutionDate": "2026-06-29T19:25:26Z",
      "lastUpdateAssociationDate": "2026-06-29T19:25:26Z",
      "name": "AWS-RunShellScript",
      "overview": {
        "detailedStatus": "Creating",
        "status": "Pending"
      },
      "parameters": "HIDDEN_DUE_TO_SECURITY_REASONS",
      "targets": [
        {
          "key": "InstanceIds",
          "values": [
            "i-0123456789abcdef0"
          ]
        }
      ]
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateAssociationStatus

#
Service
ssm

Description

Updates the status of the Amazon Web Services Systems Manager document (SSM document) associated with the specified managed node.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "2 validation errors detected: Value 'dw-probe' at 'instanceId' failed to satisfy constraint: Member must have length greater than or equal to 10; Value 'dw-probe' at 'instanceId' failed to satisfy constraint: Member must satisfy regular expression pattern: (^i-(\\w{8}|\\w{17})$)|(^mi-\\w{17}$)",
  "eventCategory": "Management",
  "eventID": "e766883b-d4bc-4df9-a2e4-be0082fe975e",
  "eventName": "UpdateAssociationStatus",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T19:26:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "22be4e1b-426b-4f50-844d-38c300bf5471",
  "requestParameters": {
    "associationStatus": {
      "date": "2020-01-01T00:00:00Z",
      "message": "ddddd",
      "name": "Pending"
    },
    "instanceId": "dw-probe",
    "name": "arn:aws:iam::123456789012:role/dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateDocument

#
Service
ssm

Description

Updates one or more values for an SSM document.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidDocument",
  "eventCategory": "Management",
  "eventID": "548bb5fb-1b2a-4e48-b059-6c6b4b0b733c",
  "eventName": "UpdateDocument",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T19:26:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "9a6e5fca-e6fe-4aac-ab23-d3ade71cb835",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateDocumentDefaultVersion

#
Service
ssm

Description

Set the default version of a document.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "9527638d-4bac-4482-a55d-cebf69abd257",
  "eventName": "UpdateDocumentDefaultVersion",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T19:12:22Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "1c63fcce-60cb-468a-8f8e-dd9098419501",
  "requestParameters": {
    "documentVersion": "1",
    "name": "dwfix-doc"
  },
  "responseElements": {
    "description": {
      "defaultVersion": "1",
      "name": "dwfix-doc"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateDocumentMetadata

#
Service
ssm

Description

Amazon Web Services Systems Manager Change Manager is no longer open to new customers.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "InvalidDocument",
  "errorMessage": "Document with name dw-probe does not exist.",
  "eventCategory": "Management",
  "eventID": "5e7f9604-850d-48bf-929f-a342000b95c3",
  "eventName": "UpdateDocumentMetadata",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T19:26:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "04812531-5e69-49e1-a017-59cfeec59f9e",
  "requestParameters": {
    "documentReviews": {
      "action": "SendForReview"
    },
    "name": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateMaintenanceWindow

#
Service
ssm

Description

Updates an existing maintenance window.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "1 validation error detected: Value at 'windowId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^mw-[0-9a-f]{17}$",
  "eventCategory": "Management",
  "eventID": "70bd3309-bce0-4003-8ec4-06d9b12f97ea",
  "eventName": "UpdateMaintenanceWindow",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T19:26:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "e549ed4a-e274-4f08-a1b4-df338edd515b",
  "requestParameters": {
    "windowId": "dddddddddddddddddddd"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateMaintenanceWindowTarget

#
Service
ssm

Description

Modifies the target of an existing maintenance window.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "2 validation errors detected: Value at 'windowTargetId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[0-9a-fA-F]{8}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{12}$; Value at 'windowId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^mw-[0-9a-f]{17}$",
  "eventCategory": "Management",
  "eventID": "a4ee984c-0dd3-4468-8740-1d3efbea4415",
  "eventName": "UpdateMaintenanceWindowTarget",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T19:26:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "8c4564f1-8297-419e-8a3e-8a6ac189182e",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateMaintenanceWindowTask

#
Service
ssm

Description

Modifies a task assigned to a maintenance window.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ValidationException",
  "errorMessage": "2 validation errors detected: Value at 'windowTaskId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[0-9a-fA-F]{8}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{12}$; Value at 'windowId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^mw-[0-9a-f]{17}$",
  "eventCategory": "Management",
  "eventID": "00087560-fd52-4da0-ab11-bcaa618b8170",
  "eventName": "UpdateMaintenanceWindowTask",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T19:26:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "192ac16d-8161-48a4-b4b2-ab8dbd562588",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateManagedInstanceRole

#
Service
ssm

Description

Changes the Identity and Access Management (IAM) role that is assigned to the on-premises server, edge device, or virtual machines (VM).

UpdateOpsItem

#
Service
ssm

Description

Edit or change an OpsItem.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "d5028510-6a4d-4b78-a452-34fc6b9900d8",
  "eventName": "UpdateOpsItem",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T20:58:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "2a11e502-ab7c-42d6-8ab1-a2121844de6e",
  "requestParameters": {
    "description": "dwfix test ops item updated",
    "opsItemId": "oi-e32d6871b32d",
    "priority": 2,
    "status": "InProgress",
    "title": "dwfix-item-ea8e728b-updated"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b,n cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateOpsMetadata

#
Service
ssm

Description

Amazon Web Services Systems Manager calls this API operation when you edit OpsMetadata in Application Manager.

UpdatePatchBaseline

#
Service
ssm

Description

Modifies an existing patch baseline.

UpdateResourceDataSync

#
Service
ssm

Description

Update a resource data sync.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ResourceDataSyncInvalidConfigurationException",
  "errorMessage": "Invalid Sync type.Values could be [SyncFromSource, SyncToDestination]",
  "eventCategory": "Management",
  "eventID": "7badd339-fe3f-44bd-b276-78b42d439fb5",
  "eventName": "UpdateResourceDataSync",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T19:26:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "a7aae984-682d-47d7-af8f-06ed1bc1523c",
  "requestParameters": {
    "syncName": "ddddd",
    "syncSource": {
      "enableAllOpsDataSources": false,
      "includeFutureRegions": false,
      "sourceRegions": [
        "ddddd"
      ],
      "sourceType": "ddddd"
    },
    "syncType": "ddddd"
  },
  "resources": [
    {
      "ARN": "arn:aws:ssm:us-west-1:123456789012:resource-data-sync/ddddd",
      "accountId": "123456789012"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateServiceSetting

#
Service
ssm

Description

ServiceSetting is an account-level setting for an Amazon Web Services service.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "e9fad6de-1013-49b5-91e0-a26a8f6325c3",
  "eventName": "UpdateServiceSetting",
  "eventSource": "ssm.amazonaws.com",
  "eventTime": "2026-06-29T19:26:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "f294fde1-1451-434e-9063-88ded9635362",
  "requestParameters": {
    "settingId": "ddddd",
    "settingValue": "ddddd"
  },
  "resources": [
    {
      "ARN": "arn:aws:ssm:us-west-1:123456789012:servicesetting/ddddd",
      "accountId": "123456789012"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateDataChannel

#
Service
ssm

Description

CreateDataChannel recorded by CloudTrail for AWS Systems Manager. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "acb21d7e-ce79-4791-8351-7b39ba29ccb4",
  "eventSource": "ssm.amazonaws.com",
  "eventName": "CreateDataChannel",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "7b36a593-1d38-401d-a6e0-9c20eef28bff",
  "userAgent": "Go-http-client/1.1",
  "tlsDetails": {
    "tlsVersion": "TLSv1.2",
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

GetManifest

#
Service
ssm

Description

GetManifest recorded by CloudTrail for AWS Systems Manager. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "e5dd7b28-893f-4a06-88c6-97aa82c94757",
  "eventSource": "ssm.amazonaws.com",
  "eventName": "GetManifest",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "f67ea885-9be4-45d0-90c0-244ef40c790a",
  "userAgent": "aws-sdk-go/1.55.5 (go1.25.11; linux; amd64) amazon-ssm-agent/3.3.4793.0",
  "errorCode": "ResourceNotFoundException",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com"
  }
}

ListInstanceAssociations

#
Service
ssm

Description

ListInstanceAssociations recorded by CloudTrail for AWS Systems Manager. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "28ae8683-6dc5-4727-8618-4033f801d967",
  "eventSource": "ssm.amazonaws.com",
  "eventName": "ListInstanceAssociations",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "8d0fdc95-308a-493c-88b4-2ff4494b4325",
  "userAgent": "aws-sdk-go/1.55.5 (go1.25.11; linux; arm64) amazon-ssm-agent/3.3.4793.0",
  "tlsDetails": {
    "tlsVersion": "TLSv1.2",
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com"
  },
  "resources": [
    {
      "accountId": "123456789012",
      "ARN": "arn:aws:ec2:us-east-1:123456789012:instance/EXAMPLE"
    }
  ]
}

ManagedInstanceConnectionLost

#
Service
ssm

Description

ManagedInstanceConnectionLost recorded by CloudTrail for AWS Systems Manager. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "7807cbce-0176-47a9-81bb-8b40145bb777",
  "eventSource": "ssm.amazonaws.com",
  "eventName": "ManagedInstanceConnectionLost",
  "awsRegion": "us-east-1",
  "eventType": "AwsServiceEvent",
  "readOnly": false,
  "managementEvent": true,
  "userAgent": "ssm.amazonaws.com",
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::SSM::ManagedInstance",
      "ARN": "arn:aws:ssm:us-east-1:123456789012:managed-instance/EXAMPLE"
    }
  ]
}

OpenDataChannel

#
Service
ssm

Description

OpenDataChannel recorded by CloudTrail for AWS Systems Manager. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "a9cabdee-3bfd-4f0e-8cbd-dfd4aa328186",
  "eventSource": "ssm.amazonaws.com",
  "eventName": "OpenDataChannel",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "c00a8c89-0a85-4060-a5e8-06ef40971e3c",
  "userAgent": "ssm.amazonaws.com"
}

PutConfigurePackageResult

#
Service
ssm

Description

PutConfigurePackageResult recorded by CloudTrail for AWS Systems Manager. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "eb38ed1b-2f60-44c3-8830-476f126d067e",
  "eventSource": "ssm.amazonaws.com",
  "eventName": "PutConfigurePackageResult",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "21a662a1-1f6f-40f8-8691-b975a00b5606",
  "userAgent": "aws-sdk-go/1.55.5 (go1.25.11; linux; amd64) amazon-ssm-agent/3.3.4793.0",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com"
  }
}

UpdateInstanceAssociationStatus

#
Service
ssm

Description

UpdateInstanceAssociationStatus recorded by CloudTrail for AWS Systems Manager. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "0a6c984f-4c3e-4088-be42-fdbdf7949f78",
  "eventSource": "ssm.amazonaws.com",
  "eventName": "UpdateInstanceAssociationStatus",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "1ea2ed77-d0c8-49f9-b277-407f6bc90c1d",
  "userAgent": "aws-sdk-go/1.55.5 (go1.25.11 X:nodwarf5; linux; amd64) amazon-ssm-agent/3.3.4624.0",
  "tlsDetails": {
    "tlsVersion": "TLSv1.2",
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com"
  },
  "resources": [
    {
      "accountId": "123456789012",
      "ARN": "arn:aws:ssm:us-east-1:123456789012:association/EXAMPLE"
    },
    {
      "accountId": "123456789012",
      "ARN": "arn:aws:ec2:us-east-1:123456789012:instance/EXAMPLE"
    }
  ]
}

UpdateInstanceInformation

#
Service
ssm

Description

UpdateInstanceInformation recorded by CloudTrail for AWS Systems Manager. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "f7a02705-b749-4158-988e-c28a1ce719a7",
  "eventSource": "ssm.amazonaws.com",
  "eventName": "UpdateInstanceInformation",
  "awsRegion": "ca-central-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "ab1d152d-6e08-484e-83af-2cd8b6f7465b",
  "userAgent": "aws-sdk-go/1.55.5 (go1.25.11; windows; amd64) exec-env/EC2 amazon-ssm-agent/3.3.4793.0",
  "tlsDetails": {
    "tlsVersion": "TLSv1.2",
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ssm.ca-central-1.amazonaws.com"
  }
}

CreateCloudConnector

#
Service
ssm

Description

Creates a cloud connector that establishes a connection between Systems Manager and a third-party cloud environment.

DeleteCloudConnector

#
Service
ssm

Description

Deletes a cloud connector.

GetCloudConnector

#
Service
ssm

Description

Returns detailed information about a cloud connector.

ListCloudConnectors

#
Service
ssm

Description

Returns a list of cloud connectors in the current Amazon Web Services account and Amazon Web Services Region.

UpdateCloudConnector

#
Service
ssm

Description

Updates an existing cloud connector with new configuration details.

ValidateCloudConnector

#
Service
ssm

Description

Validates the configuration and connectivity of a cloud connector.