AWS Systems Manager
| eventName | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all entry for AWS Systems Manager rules that match the service but not a specific eventName. | N | N |
| Create | Creates an association between a managed node and a Systems Manager document, defining the configuration state to apply. | Y | Y |
| Create | Creates a Systems Manager document that defines the actions to perform on managed nodes. | Y | Y |
| Describe | Retrieves information about the patches on a specific managed node and their states relative to the patch baseline. | Y | Y |
| Get | Queries the Systems Manager inventory, returning aggregated data about managed nodes based on specified filters. | Y | Y |
| Get | Returns a list of the metadata types currently available to populate a Systems Manager inventory. | Y | Y |
| Get | Retrieves the value of a single parameter from Systems Manager Parameter Store. | Y | Y |
| Get | Retrieves the values of one or more parameters from Systems Manager Parameter Store. | Y | Y |
| List | Lists the commands sent to managed nodes in the current account and region. | Y | Y |
| List | Lists the inventory entries for a specified managed node and inventory type. | Y | Y |
| Register | Registers an on-premises server or virtual machine with Systems Manager so it can be managed as a managed node. | N | Y |
| Send | Runs a Systems Manager document on one or more managed nodes, executing the specified commands or scripts. | Y | Y |
| Start | Initiates a connection to a managed node through AWS Systems Manager Session Manager. | Y | Y |
| Add | Adds or overwrites one or more tags for the specified resource. | Y | N |
| Associate | Associates a related item to a Systems Manager OpsCenter OpsItem. | N | N |
| Cancel | Attempts to cancel the command specified by the Command ID. | Y | N |
| Cancel | Stops a maintenance window execution that is already in progress and cancels any tasks in the window that haven't already starting running. | Y | N |
| Create | Generates an activation code and activation ID you can use to register your on-premises servers, edge devices, or virtual machine (VM) with Amazon Web Services Systems Manager. | Y | N |
| Create | Associates the specified Amazon Web Services Systems Manager document (SSM document) with the specified managed nodes or targets. | Y | N |
| Create | Creates a new maintenance window. | Y | N |
| Create | Creates a new OpsItem. | Y | N |
| Create | If you create a new application in Application Manager, Amazon Web Services Systems Manager calls this API operation to specify information about the new application, including the application type. | Y | N |
| Create | Creates a patch baseline. | Y | N |
| Create | A resource data sync helps you view data from multiple sources in a single location. | N | N |
| Delete | Deletes an activation. | Y | N |
| Delete | Disassociates the specified Amazon Web Services Systems Manager document (SSM document) from the specified managed node. | Y | N |
| Delete | Deletes the Amazon Web Services Systems Manager document (SSM document) and all managed node associations to the document. | Y | N |
| Delete | Delete a custom inventory type or the data associated with a custom Inventory type. | Y | N |
| Delete | Deletes a maintenance window. | Y | N |
| Delete | Delete an OpsItem. | Y | N |
| Delete | Delete OpsMetadata related to an application. | N | N |
| Delete | Delete a parameter from the system. | Y | N |
| Delete | Delete a list of parameters. | Y | N |
| Delete | Deletes a patch baseline. | N | N |
| Delete | Deletes a resource data sync configuration. | Y | N |
| Delete | Deletes a Systems Manager resource policy. | N | N |
| Deregister | Removes the server or virtual machine from the list of registered servers. | Y | N |
| Deregister | Removes a patch group from a patch baseline. | N | N |
| Deregister | Removes a target from a maintenance window. | Y | N |
| Deregister | Removes a task from a maintenance window. | Y | N |
| Describe | Describes details about the activation, such as the date and time the activation was created, its expiration date, the Identity and Access Management (IAM) role assigned to the managed nodes in the activation, and the number of nodes regist. | Y | N |
| Describe | Describes the association for the specified target or managed node. | Y | N |
| Describe | Views all executions for a specific association ID. | Y | N |
| Describe | Views information about a specific execution of a specific association. | Y | N |
| Describe | Provides details about all active and terminated Automation executions. | Y | N |
| Describe | Information about all active and terminated step executions in an Automation workflow. | Y | N |
| Describe | Lists all patches eligible to be included in a patch baseline. | Y | N |
| Describe | Describes the specified Amazon Web Services Systems Manager document (SSM document). | Y | N |
| Describe | Describes the permissions for a Amazon Web Services Systems Manager document (SSM document). | Y | N |
| Describe | All associations for the managed nodes. | Y | N |
| Describe | Retrieves the current effective patches (the patch and the approval state) for the specified patch baseline. | N | N |
| Describe | The status of the associations for the managed nodes. | Y | N |
| Describe | Provides information about one or more of your managed nodes, including the operating system platform, SSM Agent version, association status, and IP address. | Y | Y |
| Describe | Retrieves the high-level patch state of one or more managed nodes. | N | N |
| Describe | Retrieves the high-level patch state for the managed nodes in the specified patch group. | Y | N |
| Describe | An API operation used by the Systems Manager console to display information about Systems Manager managed nodes. | Y | N |
| Describe | Describes a specific delete inventory operation. | Y | N |
| Describe | Lists the executions of a maintenance window. | Y | N |
| Describe | Retrieves the individual task executions (one per target) for a particular task run as part of a maintenance window execution. | Y | N |
| Describe | For a given maintenance window execution, lists the tasks that were run. | Y | N |
| Describe | Retrieves the maintenance windows in an Amazon Web Services account. | Y | N |
| Describe | Retrieves information about upcoming executions of a maintenance window. | Y | N |
| Describe | Retrieves information about the maintenance window targets or tasks that a managed node is associated with. | Y | N |
| Describe | Lists the targets registered with the maintenance window. | Y | N |
| Describe | Lists the tasks in a maintenance window. | Y | N |
| Describe | Query a set of OpsItems. | Y | N |
| Describe | Lists the parameters in your Amazon Web Services account or the parameters shared with you when you enable the Shared option. | Y | N |
| Describe | Lists the patch baselines in your Amazon Web Services account. | Y | N |
| Describe | Lists all patch groups that have been registered with patch baselines. | Y | N |
| Describe | Returns high-level aggregated patch compliance state information for a patch group. | Y | N |
| Describe | Lists the properties of available patches organized by product, product family, classification, severity, and other properties of available patches. | Y | N |
| Describe | Retrieves a list of all active sessions (both connected and disconnected) or terminated sessions from the past 30 days. | Y | N |
| Disassociate | Deletes the association between an OpsItem and a related item. | N | N |
| Get | Returns a credentials set to be used with just-in-time node access. | N | N |
| Get | Get detailed information about a particular Automation execution. | Y | N |
| Get | Gets the state of a Amazon Web Services Systems Manager change calendar at the current time or a specified time. | Y | N |
| Get | Returns detailed information about command execution for an invocation or plugin. | Y | N |
| Get | Retrieves the Session Manager connection status for a managed node to determine whether it is running and ready to receive Session Manager connections. | N | N |
| Get | Retrieves the default patch baseline. | Y | N |
| Get | Retrieves the current snapshot for the patch baseline the managed node uses. | N | N |
| Get | Gets the contents of the specified Amazon Web Services Systems Manager document (SSM document). | Y | N |
| Get | Initiates the process of retrieving an existing preview that shows the effects that running a specified Automation runbook would have on the targeted resources. | N | N |
| Get | Retrieves a maintenance window. | Y | N |
| Get | Retrieves details about a specific a maintenance window execution. | Y | N |
| Get | Retrieves the details about a specific task run as part of a maintenance window execution. | Y | N |
| Get | Retrieves information about a specific task running on a specific target. | Y | N |
| Get | Retrieves the details of a maintenance window task. | Y | N |
| Get | Get information about an OpsItem by using the ID. | N | N |
| Get | View operational metadata related to an application in Application Manager. | N | N |
| Get | View a summary of operations metadata (OpsData) based on specified filters and aggregators. | Y | N |
| Get | Retrieves the history of all changes to a parameter. | Y | N |
| Get | Retrieve information about one or more parameters under a specified level in a hierarchy. | Y | N |
| Get | Retrieves information about a patch baseline. | N | N |
| Get | Retrieves the patch baseline that should be used for the specified patch group. | Y | N |
| Get | Returns an array of the Policy object. | N | N |
| Get | ServiceSetting is an account-level setting for an Amazon Web Services service. | Y | N |
| Label | A parameter label is a user-defined alias to help you manage different versions of a parameter. | Y | N |
| List | Returns all State Manager associations in the current Amazon Web Services account and Amazon Web Services Region. | Y | N |
| List | Retrieves all versions of an association for a specific association ID. | Y | N |
| List | An invocation is copy of a command sent to a specific managed node. | Y | N |
| List | For a specified resource ID, this API operation returns a list of compliance statuses for different resource types. | Y | N |
| List | Returns a summary count of compliant and non-compliant resources for a compliance type. | Y | N |
| List | Amazon Web Services Systems Manager Change Manager is no longer open to new customers. | Y | N |
| List | Returns all Systems Manager (SSM) documents in the current Amazon Web Services account and Amazon Web Services Region. | Y | N |
| List | List all versions for a document. | Y | N |
| List | Takes in filters and returns a list of managed nodes matching the filter criteria. | Y | N |
| List | Generates a summary of managed instance/node metadata based on the filters and aggregators you specify. | Y | N |
| List | Returns a list of all OpsItem events in the current Amazon Web Services Region and Amazon Web Services account. | Y | N |
| List | Lists all related-item resources associated with a Systems Manager OpsCenter OpsItem. | Y | N |
| List | Amazon Web Services Systems Manager calls this API operation when displaying all Application Manager OpsMetadata objects or blobs. | Y | N |
| List | Returns a resource-level summary count. | Y | N |
| List | Lists your resource data sync configurations. | Y | N |
| List | Returns a list of the tags assigned to the specified resource. | Y | N |
| Modify | Shares a Amazon Web Services Systems Manager document (SSM document)publicly or privately. | Y | Y |
| Put | Registers a compliance type and other compliance details on a designated resource. | Y | N |
| Put | Bulk update custom inventory items on one or more managed nodes. | Y | N |
| Put | Create or update a parameter in Parameter Store. | Y | N |
| Put | Creates or updates a Systems Manager resource policy. | N | N |
| Register | Defines the default patch baseline for the relevant operating system. | N | N |
| Register | Registers a patch baseline for a patch group. | N | N |
| Register | Registers a target with a maintenance window. | Y | N |
| Register | Adds a new task to a maintenance window. | Y | N |
| Remove | Removes tag keys from the specified resource. | Y | N |
| Reset | ServiceSetting is an account-level setting for an Amazon Web Services service. | Y | N |
| Resume | Reconnects a session to a managed node after it has been disconnected. | Y | N |
| Send | Sends a signal to an Automation execution to change the current behavior or status of the execution. | N | N |
| Start | Starts the workflow for just-in-time node access sessions. | N | N |
| Start | Runs an association immediately and only one time. | N | N |
| Start | Initiates execution of an Automation runbook. | Y | N |
| Start | Amazon Web Services Systems Manager Change Manager is no longer open to new customers. | N | N |
| Start | Initiates the process of creating a preview showing the effects that running a specified Automation runbook would have on the targeted resources. | N | N |
| Stop | Stop an Automation that is currently running. | Y | N |
| Terminate | Permanently ends a session and closes the data connection between the Session Manager client and SSM Agent on the managed node. | Y | N |
| Unlabel | Remove a label or labels from a parameter. | Y | N |
| Update | Updates an association. | Y | N |
| Update | Updates the status of the Amazon Web Services Systems Manager document (SSM document) associated with the specified managed node. | Y | N |
| Update | Updates one or more values for an SSM document. | Y | N |
| Update | Set the default version of a document. | Y | N |
| Update | Amazon Web Services Systems Manager Change Manager is no longer open to new customers. | Y | N |
| Update | Updates an existing maintenance window. | Y | N |
| Update | Modifies the target of an existing maintenance window. | Y | N |
| Update | Modifies a task assigned to a maintenance window. | Y | N |
| Update | Changes the Identity and Access Management (IAM) role that is assigned to the on-premises server, edge device, or virtual machines (VM). | N | N |
| Update | Edit or change an OpsItem. | Y | N |
| Update | Amazon Web Services Systems Manager calls this API operation when you edit OpsMetadata in Application Manager. | N | N |
| Update | Modifies an existing patch baseline. | N | N |
| Update | Update a resource data sync. | Y | N |
| Update | ServiceSetting is an account-level setting for an Amazon Web Services service. | Y | N |
| Create | CreateDataChannel recorded by CloudTrail for AWS Systems Manager. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Get | GetManifest recorded by CloudTrail for AWS Systems Manager. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| List | ListInstanceAssociations recorded by CloudTrail for AWS Systems Manager. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Managed | ManagedInstanceConnectionLost recorded by CloudTrail for AWS Systems Manager. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Open | OpenDataChannel recorded by CloudTrail for AWS Systems Manager. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Put | PutConfigurePackageResult recorded by CloudTrail for AWS Systems Manager. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Update | UpdateInstanceAssociationStatus recorded by CloudTrail for AWS Systems Manager. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Update | UpdateInstanceInformation recorded by CloudTrail for AWS Systems Manager. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Create | Creates a cloud connector that establishes a connection between Systems Manager and a third-party cloud environment. | N | N |
| Delete | Deletes a cloud connector. | N | N |
| Get | Returns detailed information about a cloud connector. | N | N |
| List | Returns a list of cloud connectors in the current Amazon Web Services account and Amazon Web Services Region. | N | N |
| Update | Updates an existing cloud connector with new configuration details. | N | N |
| Validate | Validates the configuration and connectivity of a cloud connector. | N | N |
any: AWS Systems Manager (catch-all)
#Description
Catch-all entry for AWS Systems Manager rules that match the service but not a specific eventName.
CreateAssociation
#Description
Creates an association between a managed node and a Systems Manager document, defining the configuration state to apply.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "6202dca8-ff97-4a65-8fd9-0b03d7e407e8",
"eventName": "CreateAssociation",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T19:25:26Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "ff346246-7355-4e77-ba3a-77a034dae792",
"requestParameters": {
"applyOnlyAtCronInterval": false,
"name": "AWS-RunShellScript",
"parameters": "HIDDEN_DUE_TO_SECURITY_REASONS",
"targets": [
{
"key": "InstanceIds",
"values": [
"i-0123456789abcdef0"
]
}
]
},
"responseElements": {
"associationDescription": {
"applyOnlyAtCronInterval": false,
"associationId": "c93a05c3-e24a-4016-a7bf-51d1b9a6a740",
"associationVersion": "1",
"date": "2026-06-29T19:25:26Z",
"documentVersion": "$DEFAULT",
"lastUpdateAssociationDate": "2026-06-29T19:25:26Z",
"name": "AWS-RunShellScript",
"overview": {
"detailedStatus": "Creating",
"status": "Pending"
},
"parameters": "HIDDEN_DUE_TO_SECURITY_REASONS",
"targets": [
{
"key": "InstanceIds",
"values": [
"i-0123456789abcdef0"
]
}
]
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1518, T1538, T1580↳ also matches DescribeInstancePatches, GetInventory, GetInventorySchema, ListCommands, ListInventoryEntries Kusto #
T1651↳ also matches SendCommand
CreateDocument
#Description
Creates a Systems Manager document that defines the actions to perform on managed nodes.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "1129bf80-1af8-44cf-a6a1-c5face3f0711",
"eventName": "CreateDocument",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T19:12:22Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "bb4ef741-4f8e-4d92-b33a-a5ce8eece0d9",
"requestParameters": {
"content": "HIDDEN_DUE_TO_SECURITY_REASONS",
"documentFormat": "JSON",
"name": "dwfix-doc"
},
"responseElements": {
"documentDescription": {
"createdDate": "2026-06-29T19:12:22Z",
"defaultVersion": "1",
"description": "dw",
"documentFormat": "JSON",
"documentId": "df6de79c-6403-4f9d-8870-08f6c8588a2b",
"documentType": "Command",
"documentVersion": "1",
"hash": "e664bf5099908ccd8df0990c9e1e5e39bbdb7f9af37502ed96967145f4bf9a75",
"hashType": "Sha256",
"latestVersion": "1",
"name": "dwfix-doc",
"owner": "123456789012",
"platformTypes": [
"Linux",
"MacOS"
],
"schemaVersion": "2.2",
"status": "Creating",
"tags": []
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1651
DescribeInstancePatches
#Description
Retrieves information about the patches on a specific managed node and their states relative to the patch baseline.
Example CloudTrail Event #
{
"eventVersion": "1.11",
"userIdentity": {
"type": "Root",
"principalId": "123456789012",
"arn": "arn:aws:iam::123456789012:root",
"accountId": "123456789012",
"accessKeyId": "AKIAIOSFODNN7EXAMPLE"
},
"eventTime": "2026-07-28T20:58:18Z",
"eventSource": "ssm.amazonaws.com",
"eventName": "DescribeInstancePatches",
"awsRegion": "us-west-1",
"sourceIPAddress": "203.0.113.5",
"userAgent": "aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/n,Z,E,C,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#ssm.describe-instance-patches",
"requestParameters": {
"instanceId": "i-00000000000000000"
},
"responseElements": null,
"requestID": "be164893-076c-492d-9bd3-c3d7114a7dc6",
"eventID": "c2e7494a-0bf3-4abe-a536-40959a2ba6a7",
"readOnly": true,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "123456789012",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1518, T1538, T1580↳ also matches CreateAssociation, GetInventory, GetInventorySchema, ListCommands, ListInventoryEntries
GetInventory
#Description
Queries the Systems Manager inventory, returning aggregated data about managed nodes based on specified filters.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "e01a5cda-643a-4e70-9e34-d071f85733c6",
"eventName": "GetInventory",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:32:46Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "2c8a587e-9d1e-403e-b7e9-7bb4af16ed3b",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1518, T1538, T1580↳ also matches CreateAssociation, DescribeInstancePatches, GetInventorySchema, ListCommands, ListInventoryEntries
GetInventorySchema
#Description
Returns a list of the metadata types currently available to populate a Systems Manager inventory.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: ssm:GetInventorySchema on resource: arn:aws:ssm:us-east-1:811596193553:*",
"eventID": "bdf2b609-e558-4000-b603-602de4838a82",
"eventName": "GetInventorySchema",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2019-10-19T23:49:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "66895ea7-7f09-430d-89b9-3919d7bc08d1",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "213.253.166.5",
"userAgent": "Boto3/1.9.210 Python/2.7.10 Darwin/18.7.0 Botocore/1.12.210",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1518, T1538, T1580↳ also matches CreateAssociation, DescribeInstancePatches, GetInventory, ListCommands, ListInventoryEntries
References #
GetParameter
#Description
Retrieves the value of a single parameter from Systems Manager Parameter Store.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "736cbe1d-d978-4599-ba4c-a4d682b908b8",
"eventName": "GetParameter",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2023-07-10T11:58:10Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "45d5aa2b-5f29-4425-ab3d-a37df96a667e",
"requestParameters": {
"name": "/credentials/stratus-red-team/credentials-6",
"withDecryption": true
},
"resources": [
{
"ARN": "arn:aws:ssm:us-east-1:123837392027:parameter/credentials/stratus-red-team/credentials-6",
"accountId": "123837392027"
}
],
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_11a6ef34-e130-4579-a1d3-79c915cee6ec HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1555, T1555.006↳ also matches GetParameters Panther #
T1555↳ also matches GetParameters
References #
GetParameters
#Description
Retrieves the values of one or more parameters from Systems Manager Parameter Store.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "928546c4-79d3-4f9e-aec5-319ef6685cde",
"eventName": "GetParameters",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2023-07-10T11:58:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "fc91dc6f-0e31-41af-9c02-b99e500ab596",
"requestParameters": {
"names": [
"/credentials/stratus-red-team/credentials-0",
"/credentials/stratus-red-team/credentials-12",
"/credentials/stratus-red-team/credentials-15",
"/credentials/stratus-red-team/credentials-16",
"/credentials/stratus-red-team/credentials-21",
"/credentials/stratus-red-team/credentials-25",
"/credentials/stratus-red-team/credentials-30",
"/credentials/stratus-red-team/credentials-34",
"/credentials/stratus-red-team/credentials-35",
"/credentials/stratus-red-team/credentials-9"
],
"withDecryption": true
},
"resources": [
{
"ARN": "arn:aws:ssm:us-east-1:123837392027:parameter/credentials/stratus-red-team/credentials-0",
"accountId": "123837392027"
},
{
"ARN": "arn:aws:ssm:us-east-1:123837392027:parameter/credentials/stratus-red-team/credentials-12",
"accountId": "123837392027"
},
{
"ARN": "arn:aws:ssm:us-east-1:123837392027:parameter/credentials/stratus-red-team/credentials-15",
"accountId": "123837392027"
},
{
"ARN": "arn:aws:ssm:us-east-1:123837392027:parameter/credentials/stratus-red-team/credentials-16",
"accountId": "123837392027"
},
{
"ARN": "arn:aws:ssm:us-east-1:123837392027:parameter/credentials/stratus-red-team/credentials-21",
"accountId": "123837392027"
},
{
"ARN": "arn:aws:ssm:us-east-1:123837392027:parameter/credentials/stratus-red-team/credentials-25",
"accountId": "123837392027"
},
{
"ARN": "arn:aws:ssm:us-east-1:123837392027:parameter/credentials/stratus-red-team/credentials-30",
"accountId": "123837392027"
},
{
"ARN": "arn:aws:ssm:us-east-1:123837392027:parameter/credentials/stratus-red-team/credentials-34",
"accountId": "123837392027"
},
{
"ARN": "arn:aws:ssm:us-east-1:123837392027:parameter/credentials/stratus-red-team/credentials-35",
"accountId": "123837392027"
},
{
"ARN": "arn:aws:ssm:us-east-1:123837392027:parameter/credentials/stratus-red-team/credentials-9",
"accountId": "123837392027"
}
],
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "stratus-red-team_11a6ef34-e130-4579-a1d3-79c915cee6ec",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1555, T1555.006↳ also matches GetParameter Panther #
T1555↳ also matches GetParameter
References #
ListCommands
#Description
Lists the commands sent to managed nodes in the current account and region.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: ssm:ListCommands on resource: arn:aws:ssm:us-east-1:811596193553:*",
"eventID": "bcbb788c-0783-4edd-8d64-d712518e",
"eventName": "ListCommands",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2019-10-19T23:49:23Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "29acd72f-074a-42b6-9022-95fa6e93418f",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "213.253.166.5",
"userAgent": "Boto3/1.9.210 Python/2.7.10 Darwin/18.7.0 Botocore/1.12.210",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1518, T1538, T1580↳ also matches CreateAssociation, DescribeInstancePatches, GetInventory, GetInventorySchema, ListInventoryEntries
References #
ListInventoryEntries
#Description
Lists the inventory entries for a specified managed node and inventory type.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "3 validation errors detected: Value 'dw-probe' at 'instanceId' failed to satisfy constraint: Member must have length greater than or equal to 10; Value 'dw-probe' at 'instanceId' failed to satisfy constraint: Member must satisfy regular expression pattern: (^i-(\\w{8}|\\w{17})$)|(^mi-\\w{17}$); Value 'ddddd' at 'typeName' failed to satisfy constraint: Member must satisfy regular expression pattern: ^(AWS|Custom):.*$",
"eventCategory": "Management",
"eventID": "5afab473-5138-443c-9b5c-a968d3c26e47",
"eventName": "ListInventoryEntries",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:46:11Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "bb873ee6-8635-41ec-856e-a82d832a8895",
"requestParameters": {
"instanceId": "dw-probe",
"typeName": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1518, T1538, T1580↳ also matches CreateAssociation, DescribeInstancePatches, GetInventory, GetInventorySchema, ListCommands
RegisterManagedInstance
#Description
Registers an on-premises server or virtual machine with Systems Manager so it can be managed as a managed node.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "a0ce9b28-5a5f-4c52-8474-c4914360c681",
"eventSource": "ssm.amazonaws.com",
"eventName": "RegisterManagedInstance",
"awsRegion": "us-east-2",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "8593d18d-f772-45ee-8658-87a382e11d33",
"userAgent": "aws-sdk-go/1.55.5 (go1.25.11; linux; arm64) amazon-ssm-agent/3.3.4793.0",
"tlsDetails": {
"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-east-2.amazonaws.com"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1078, T1078.002
SendCommand
#Description
Runs a Systems Manager document on one or more managed nodes, executing the specified commands or scripts.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "99b46479-d5c7-4384-b342-006ece8c36a0",
"eventName": "SendCommand",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2023-07-10T11:57:16Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "f2b7ffbd-9959-45f8-bc13-6f93c699b06d",
"requestParameters": {
"documentName": "AWS-RunShellScript",
"instanceIds": [
"i-0dbc91f429e48eeed"
],
"interactive": false,
"parameters": "HIDDEN_DUE_TO_SECURITY_REASONS"
},
"responseElements": {
"command": {
"alarmConfiguration": {
"alarms": [],
"ignorePollAlarmFailure": false
},
"clientName": "",
"clientSourceId": "",
"cloudWatchOutputConfig": {
"cloudWatchLogGroupName": "",
"cloudWatchOutputEnabled": false
},
"commandId": "bbf52fc0-1a25-4020-b1b4-1872ff8edd12",
"comment": "",
"completedCount": 0,
"deliveryTimedOutCount": 0,
"documentName": "AWS-RunShellScript",
"documentVersion": "$DEFAULT",
"errorCount": 0,
"expiresAfter": "Jul 10, 2023 1:57:16 PM",
"instanceIds": [
"i-0dbc91f429e48eeed"
],
"interactive": false,
"maxConcurrency": "50",
"maxErrors": "0",
"notificationConfig": {
"notificationArn": "",
"notificationEvents": [],
"notificationType": ""
},
"outputS3BucketName": "",
"outputS3KeyPrefix": "",
"outputS3Region": "us-east-1",
"parameters": "HIDDEN_DUE_TO_SECURITY_REASONS",
"requestedDateTime": "Jul 10, 2023 11:57:16 AM",
"serviceRole": "",
"status": "Pending",
"statusDetails": "Pending",
"targetCount": 1,
"targets": [],
"timeoutSeconds": 3600,
"triggeredAlarms": []
}
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
aws::errorCode (sigma rule field) | eq | success | 1 rule | sigma |
process_name (elastic rule field) | in | base64 | 1 rule | elastic |
process_name (elastic rule field) | in | curl | 1 rule | elastic |
process_name (elastic rule field) | in | nc | 1 rule | elastic |
process_name (elastic rule field) | in | ncat | 1 rule | elastic |
process_name (elastic rule field) | in | netcat | 1 rule | elastic |
process_name (elastic rule field) | in | openssl | 1 rule | elastic |
process_name (elastic rule field) | in | perl | 1 rule | elastic |
process_name (elastic rule field) | in | php | 1 rule | elastic |
process_name (elastic rule field) | in | python | 1 rule | elastic |
process_name (elastic rule field) | in | python3 | 1 rule | elastic |
process_name (elastic rule field) | in | rsync | 1 rule | elastic |
process_name (elastic rule field) | in | ruby | 1 rule | elastic |
process_name (elastic rule field) | in | scp | 1 rule | elastic |
process_name (elastic rule field) | in | sftp | 1 rule | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1566, T1566.002Elastic #
SendCommand API. This detection correlates AWS CloudTrail SendCommand events with endpoint process execution by matching SSM command IDs. While AWS redacts command parameters in CloudTrail logs, this correlation technique reveals the actual commands executed on EC2 instances. Adversaries may abuse SSM to execute malicious commands remotely without requiring SSH or RDP access, using legitimate system utilities for data exfiltration, establishing reverse shells, or lateral movement.T1059, T1059.004, T1105, T1651T1651Kusto #
T1651↳ also matches CreateAssociation Panther #
T1203
References #
StartSession
#Description
Initiates a connection to a managed node through AWS Systems Manager Session Manager.
Example CloudTrail Event #
{
"awsRegion": "ap-southeast-2",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::811596193553:user/Level6 is not authorized to perform: ssm:StartSession on resource: arn:aws:ec2:ap-southeast-2:811596193553:instance/i-b4fbbdb99485b1594",
"eventID": "a5d6b789-9143-4724-8a63-1bcc17876f",
"eventName": "StartSession",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2019-09-19T23:29:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "08c96390-6974-4d29-a314-e74b18d5d17d",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "227.254.253.118",
"userAgent": "aws-cli/1.16.190 Python/3.7.4 Darwin/17.5.0 botocore/1.12.180",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1021, T1021.007
References #
CancelCommand
#Description
Attempts to cancel the command specified by the Command ID.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "1 validation error detected: Value 'dddddddddddddddddddddddddddddddddddd' at 'commandId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[A-Fa-f0-9]{8}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{12}$",
"eventCategory": "Management",
"eventID": "ab8566d9-2328-4a73-8251-fc504272e57d",
"eventName": "CancelCommand",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T19:26:49Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "ff3c88d4-b84f-41e8-a853-3321d7b0748a",
"requestParameters": {
"commandId": "dddddddddddddddddddddddddddddddddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CancelMaintenanceWindowExecution
#Description
Stops a maintenance window execution that is already in progress and cancels any tasks in the window that haven't already starting running.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "1 validation error detected: Value at 'windowExecutionId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[0-9a-fA-F]{8}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{12}$",
"eventCategory": "Management",
"eventID": "5c36d983-4482-4205-b278-dc2b2170cd21",
"eventName": "CancelMaintenanceWindowExecution",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T19:26:49Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "b9bca564-7e10-4433-a69e-2eab4428f4a1",
"requestParameters": {
"windowExecutionId": "dddddddddddddddddddddddddddddddddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateActivation
#Description
Generates an activation code and activation ID you can use to register your on-premises servers, edge devices, or virtual machine (VM) with Amazon Web Services Systems Manager.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Nonexistent role or missing ssm service principal in trust policy: arn:aws:iam::123456789012:role/AmazonSSMManagedInstanceCore",
"eventCategory": "Management",
"eventID": "e3c7ca52-07f9-4355-85b1-d67d9f2e7dc0",
"eventName": "CreateActivation",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T20:58:59Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "8926e2f8-8f36-46ae-b1c5-4f99d53199b3",
"requestParameters": {
"defaultInstanceName": "dwfix-instance-ea8e728b",
"description": "dwfix test hybrid activation",
"iamRole": "AmazonSSMManagedInstanceCore",
"registrationLimit": 1,
"tags": [
{
"key": "dwfix",
"value": "true"
}
]
},
"resources": [
{
"ARN": "arn:aws:iam::123456789012:role/AmazonSSMManagedInstanceCore",
"accountId": "123456789012"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b,n cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateAssociationBatch
#Description
Associates the specified Amazon Web Services Systems Manager document (SSM document) with the specified managed nodes or targets.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidTarget",
"errorMessage": "Instance ID or targets must be specified",
"eventCategory": "Management",
"eventID": "a88adeee-4d6a-4cae-859e-7236c204e4a8",
"eventName": "CreateAssociationBatch",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T20:58:56Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "03411194-16f7-44dd-824a-c511087bf4d0",
"requestParameters": {
"entries": [
{
"applyOnlyAtCronInterval": false,
"associationName": "dwfix-assoc-ea8e728b",
"name": "dwfix-doc-ea8e728b"
}
]
},
"resources": [
{
"ARN": "arn:aws:ssm:us-west-1:123456789012:document/dwfix-doc-ea8e728b",
"accountId": "123456789012"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b,n cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateMaintenanceWindow
#Description
Creates a new maintenance window.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "24179075-a83b-44ec-9d4a-4a6dfb77b9b7",
"eventName": "CreateMaintenanceWindow",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T20:58:55Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "f8f01781-cd08-4a86-93e3-4e168f29c2d3",
"requestParameters": {
"allowUnassociatedTargets": true,
"clientToken": "15eb483c-f0b7-4fc8-8484-0e02c8289d10",
"cutoff": 0,
"description": "HIDDEN_DUE_TO_SECURITY_REASONS",
"duration": 1,
"name": "dwfix-mw-ea8e728b",
"schedule": "cron(0 2 ? * SUN *)",
"tags": [
{
"key": "dwfix",
"value": "true"
}
]
},
"resources": [
{
"ARN": "arn:aws:ssm:us-west-1:123456789012:maintenancewindow/mw-06e8430a431fc17a1",
"accountId": "123456789012"
}
],
"responseElements": {
"windowId": "mw-06e8430a431fc17a1"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b,n cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateOpsItem
#Description
Creates a new OpsItem.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "f294a404-7fd0-4710-a7f9-d0b57a9ed1e8",
"eventName": "CreateOpsItem",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T20:58:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "43ddd473-1f32-4c3a-bbc2-73dcc2c97e85",
"requestParameters": {
"category": "Availability",
"description": "dwfix test ops item for CloudTrail sample collection",
"priority": 3,
"severity": "3",
"source": "dwfix-collector",
"tags": [
{
"key": "dwfix",
"value": "true"
}
],
"title": "dwfix-item-ea8e728b"
},
"responseElements": {
"opsItemArn": "arn:aws:ssm:us-west-1:123456789012:opsitem/oi-e32d6871b32d",
"opsItemId": "oi-e32d6871b32d"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b,n cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateOpsMetadata
#Description
If you create a new application in Application Manager, Amazon Web Services Systems Manager calls this API operation to specify information about the new application, including the application type.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "e525a495-1bab-4007-97a3-3fb55801bfc1",
"eventName": "CreateOpsMetadata",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T20:58:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "69191487-dd8f-4532-83fc-42a1a7135e7f",
"requestParameters": {
"resourceId": "dwfix-resource-ea8e728b",
"tags": [
{
"key": "dwfix",
"value": "true"
}
]
},
"resources": [
{
"ARN": "arn:aws:ssm:us-west-1:123456789012:opsmetadata/*",
"accountId": "123456789012"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b,n cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreatePatchBaseline
#Description
Creates a patch baseline.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Patch Baseline attribute: Approved Patches and Approval Rule, at least one must be non empty.",
"eventCategory": "Management",
"eventID": "2b271645-8c2c-41b8-90d8-a47248bc841c",
"eventName": "CreatePatchBaseline",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T20:58:55Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "0c5b8cf6-a624-4f89-8535-62ae8c265afb",
"requestParameters": {
"approvedPatchesComplianceLevel": "MEDIUM",
"clientToken": "7daf494f-828e-40e3-986e-eba882556e07",
"description": "HIDDEN_DUE_TO_SECURITY_REASONS",
"name": "dwfix-baseline-ea8e728b",
"operatingSystem": "WINDOWS",
"tags": [
{
"key": "dwfix",
"value": "true"
}
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b,n cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateResourceDataSync
#Description
A resource data sync helps you view data from multiple sources in a single location.
DeleteActivation
#Description
Deletes an activation.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "2 validation errors detected: Value 'dw-probe' at 'activationId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$; Value 'dw-probe' at 'activationId' failed to satisfy constraint: Member must have length greater than or equal to 36",
"eventCategory": "Management",
"eventID": "2570d62b-f579-4c60-96a8-690c5ed1f2cf",
"eventName": "DeleteActivation",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T19:26:49Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "380d7308-1c32-4bab-80bd-f2d2c2df23d9",
"requestParameters": {
"activationId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteAssociation
#Description
Disassociates the specified Amazon Web Services Systems Manager document (SSM document) from the specified managed node.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "13d309c5-c885-4e62-863d-f209bd4baa51",
"eventName": "DeleteAssociation",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T19:25:26Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "da2e044d-1620-4856-8555-fb304be6ad32",
"requestParameters": {
"associationId": "c93a05c3-e24a-4016-a7bf-51d1b9a6a740"
},
"resources": [
{
"ARN": "arn:aws:ssm:us-west-1:123456789012:association/c93a05c3-e24a-4016-a7bf-51d1b9a6a740",
"accountId": "123456789012"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteDocument
#Description
Deletes the Amazon Web Services Systems Manager document (SSM document) and all managed node associations to the document.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "2ff0ec7f-016a-443a-aa3d-7fc5bc181ab8",
"eventName": "DeleteDocument",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T19:12:22Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "f7cf8a7f-3028-48e7-9f84-085fba300f72",
"requestParameters": {
"force": false,
"name": "dwfix-doc"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteInventory
#Description
Delete a custom inventory type or the data associated with a custom Inventory type.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "1 validation error detected: Value 'ddddd' at 'typeName' failed to satisfy constraint: Member must satisfy regular expression pattern: ^(AWS|Custom):.*$",
"eventCategory": "Management",
"eventID": "d6bd122e-386b-4455-86c9-fb57ccde15e6",
"eventName": "DeleteInventory",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T19:26:49Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "0e798de9-7ca1-48dd-ab2b-192888cf5c69",
"requestParameters": {
"clientToken": "249bba08-90a8-4fec-bcbb-679500e159b6",
"dryRun": false,
"typeName": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteMaintenanceWindow
#Description
Deletes a maintenance window.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "1 validation error detected: Value at 'windowId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^mw-[0-9a-f]{17}$",
"eventCategory": "Management",
"eventID": "3f64eee5-09a7-431b-9103-2138208ede22",
"eventName": "DeleteMaintenanceWindow",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T19:26:49Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "e10fddb4-077c-4197-bce1-3198245d1d27",
"requestParameters": {
"windowId": "dddddddddddddddddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteOpsItem
#Description
Delete an OpsItem.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "7f90b983-c3f6-4eb6-9573-8072b41cb989",
"eventName": "DeleteOpsItem",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T20:58:55Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "3432e0f4-09f5-4798-a9b9-3c02427485d8",
"requestParameters": {
"opsItemId": "oi-e32d6871b32d"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b,n cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteOpsMetadata
#Description
Delete OpsMetadata related to an application.
DeleteParameter
#Description
Delete a parameter from the system.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "2b2f4de3-8b4e-48b7-9326-ec2118c61742",
"eventName": "DeleteParameter",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2023-07-10T12:08:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "979718f4-079c-4c62-a7cd-729519b0f7fe",
"requestParameters": {
"name": "/credentials/stratus-red-team/credentials-22"
},
"resources": [
{
"ARN": "arn:aws:ssm:us-east-1:123837392027:parameter/credentials/stratus-red-team/credentials-22",
"accountId": "123837392027"
}
],
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DeleteParameters
#Description
Delete a list of parameters.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "173572ef-812d-40d9-b8c0-8c023810031c",
"eventName": "DeleteParameters",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T19:26:49Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "42a29dec-3c2a-4800-a33b-a70477477617",
"requestParameters": {
"names": [
"ddddd"
]
},
"resources": [
{
"ARN": "arn:aws:ssm:us-west-1:123456789012:parameter/ddddd",
"accountId": "123456789012"
}
],
"responseElements": {
"deletedParameters": [],
"invalidParameters": [
"ddddd"
]
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeletePatchBaseline
#Description
Deletes a patch baseline.
DeleteResourceDataSync
#Description
Deletes a resource data sync configuration.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ResourceDataSyncNotFoundException",
"errorMessage": "ResourceDataSync with name ddddd synctype SyncToDestination does not exists",
"eventCategory": "Management",
"eventID": "6c2f7552-416d-4d0e-a638-acee559aa24f",
"eventName": "DeleteResourceDataSync",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T19:26:49Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "5752f466-1525-4705-ac07-1af7debd966c",
"requestParameters": {
"syncName": "ddddd"
},
"resources": [
{
"ARN": "arn:aws:ssm:us-west-1:123456789012:resource-data-sync/ddddd",
"accountId": "123456789012"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteResourcePolicy
#Description
Deletes a Systems Manager resource policy.
DeregisterManagedInstance
#Description
Removes the server or virtual machine from the list of registered servers.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "1 validation error detected: Value 'dddddddddddddddddddd' at 'instanceId' failed to satisfy constraint: Member must satisfy regular expression pattern: (^mi-[0-9a-f]{17}$)|(^eks_c:[0-9A-Za-z][A-Za-z0-9\\-_]{0,99}_\\w{17}$)",
"eventCategory": "Management",
"eventID": "a69d6fd5-49b7-47c8-bd9b-29fd82efd737",
"eventName": "DeregisterManagedInstance",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T19:26:49Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "2d92ebe2-2b11-45e3-8c8e-6f237779ec35",
"requestParameters": {
"instanceId": "dddddddddddddddddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeregisterPatchBaselineForPatchGroup
#Description
Removes a patch group from a patch baseline.
DeregisterTargetFromMaintenanceWindow
#Description
Removes a target from a maintenance window.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "2 validation errors detected: Value at 'windowTargetId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[0-9a-fA-F]{8}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{12}$; Value at 'windowId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^mw-[0-9a-f]{17}$",
"eventCategory": "Management",
"eventID": "900e85d8-b5c4-45f1-beb1-c5bee6c59a17",
"eventName": "DeregisterTargetFromMaintenanceWindow",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T19:26:49Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "138d2733-1976-4f8f-8e0d-f50c7f803b17",
"requestParameters": {
"windowId": "dddddddddddddddddddd",
"windowTargetId": "dddddddddddddddddddddddddddddddddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeregisterTaskFromMaintenanceWindow
#Description
Removes a task from a maintenance window.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "2 validation errors detected: Value at 'windowTaskId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[0-9a-fA-F]{8}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{12}$; Value at 'windowId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^mw-[0-9a-f]{17}$",
"eventCategory": "Management",
"eventID": "b192a288-0ac0-485f-bd84-2db7f2fef4b0",
"eventName": "DeregisterTaskFromMaintenanceWindow",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T19:26:49Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "69ed0fbb-e627-4f63-97b8-67be8becd724",
"requestParameters": {
"windowId": "dddddddddddddddddddd",
"windowTaskId": "dddddddddddddddddddddddddddddddddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeActivations
#Description
Describes details about the activation, such as the date and time the activation was created, its expiration date, the Identity and Access Management (IAM) role assigned to the managed nodes in the activation, and the number of nodes regist.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "d5a810ed-d1ef-4d64-bb20-af990d950beb",
"eventName": "DescribeActivations",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2018-10-17T20:32:14Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "3a2112d4-6295-4c17-8b6f-3c060ab9a42d",
"requestParameters": null,
"resources": [],
"responseElements": null,
"sourceIPAddress": "9.245.1.85",
"userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeAssociation
#Description
Describes the association for the specified target or managed node.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "ValidationException",
"errorMessage": "Must either provide instance id + document name, or provide association id ",
"eventID": "a910d90c-33cf-4cf8-9b2e-e38599fb232b",
"eventName": "DescribeAssociation",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2018-10-17T20:32:15Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "3ce4ad23-22c4-4e98-bfc0-4f59853b4b",
"requestParameters": null,
"resources": [
{
"ARN": "arn:aws:ssm:us-east-1:811596193553:managed-instance/null",
"accountId": "811596193553"
},
{
"ARN": "arn:aws:ssm:us-east-1:811596193553:document/null",
"accountId": "811596193553"
}
],
"responseElements": null,
"sourceIPAddress": "9.245.1.85",
"userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeAssociationExecutions
#Description
Views all executions for a specific association ID.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "1 validation error detected: Value 'dw-probe' at 'associationId' failed to satisfy constraint: Member must satisfy regular expression pattern: [0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}",
"eventCategory": "Management",
"eventID": "1bb558d6-db9a-4ba3-b121-eb7858a0ece6",
"eventName": "DescribeAssociationExecutions",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:46:11Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "f4c8d7e9-946c-4d40-bfc6-08af548155fe",
"requestParameters": {
"associationId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeAssociationExecutionTargets
#Description
Views information about a specific execution of a specific association.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "2 validation errors detected: Value 'dw-probe' at 'executionId' failed to satisfy constraint: Member must satisfy regular expression pattern: [0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}; Value 'dw-probe' at 'associationId' failed to satisfy constraint: Member must satisfy regular expression pattern: [0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}",
"eventCategory": "Management",
"eventID": "30cda0b3-a326-4e54-9608-3fec4af0d964",
"eventName": "DescribeAssociationExecutionTargets",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:46:11Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "840fcba9-8440-44e2-a4d3-2ed0ba09bafb",
"requestParameters": {
"associationId": "dw-probe",
"executionId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeAutomationExecutions
#Description
Provides details about all active and terminated Automation executions.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "d5c139456-f338-47f6-a0fc-59438256b203",
"eventName": "DescribeAutomationExecutions",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2018-10-17T20:32:14Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "b62a7bf7-cc2b-48ab-8bc5-d88ce8aea65e",
"requestParameters": null,
"resources": [],
"responseElements": null,
"sourceIPAddress": "9.245.1.85",
"userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeAutomationStepExecutions
#Description
Information about all active and terminated step executions in an Automation workflow.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "1 validation error detected: Value at 'automationExecutionId' failed to satisfy constraint: Member must satisfy regular expression pattern: [a-fA-F0-9]{8}-[a-fA-F0-9]{4}-[a-fA-F0-9]{4}-[a-fA-F0-9]{4}-[a-fA-F0-9]{12}",
"eventCategory": "Management",
"eventID": "1bc33c81-dd6e-4152-92db-b0b2eab37935",
"eventName": "DescribeAutomationStepExecutions",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:46:11Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "14b587f7-fac2-419b-9450-16f6fdb6617f",
"requestParameters": {
"automationExecutionId": "dddddddddddddddddddddddddddddddddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeAvailablePatches
#Description
Lists all patches eligible to be included in a patch baseline.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "36c8d420-3b9f-4099-bfd6-99fd28afadf0",
"eventName": "DescribeAvailablePatches",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2018-10-17T20:32:14Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "447ed1f6-becc-4822-afd2-358fe4ae20c1",
"requestParameters": null,
"resources": [],
"responseElements": null,
"sourceIPAddress": "9.245.1.85",
"userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeDocument
#Description
Describes the specified Amazon Web Services Systems Manager document (SSM document).
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:sts::811596193553:assumed-role/flaws/i-aa2d3b42e5c6e801a is not authorized to perform: ssm:DescribeDocument on resource: arn:aws:ssm:us-west-2::document/AWS-RunShellScript",
"eventID": "e400b73f-4a1b-4cc2-ba39-9d78eb00311d",
"eventName": "DescribeDocument",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2020-02-20T03:42:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "27f8aef1-9d56-4632-bfd7-d64db91e2e6a",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "1.9.142.0",
"userAgent": "aws-cli/1.18.0 Python/2.7.17 Linux/5.4.0-kali3-amd64 botocore/1.15.0",
"userIdentity": {
"accessKeyId": "ASIAJL2MNK6Q8GDKNZLM",
"accountId": "811596193553",
"arn": "arn:aws:sts::811596193553:assumed-role/flaws/i-aa2d3b42e5c6e801a",
"principalId": "AROACW5CSA8C8WHOB3O7Q:i-aa2d3b42e5c6e801a",
"sessionContext": {
"attributes": {
"creationDate": "2020-02-20T02:47:20Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:role/flaws",
"principalId": "AROACW5CSA8C8WHOB3O7Q",
"type": "Role",
"userName": "flaws"
},
"webIdFederationData": {}
},
"type": "AssumedRole"
}
}
References #
DescribeDocumentPermission
#Description
Describes the permissions for a Amazon Web Services Systems Manager document (SSM document).
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidDocument",
"errorMessage": "Document with name dw-probe does not exist.",
"eventCategory": "Management",
"eventID": "ce0800e0-1cb6-473e-b40b-8f149e155ad5",
"eventName": "DescribeDocumentPermission",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:46:11Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "6d485a9a-3738-4485-9428-d9e65574c84e",
"requestParameters": {
"name": "dw-probe",
"permissionType": "Share"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeEffectiveInstanceAssociations
#Description
All associations for the managed nodes.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "2 validation errors detected: Value 'dw-probe' at 'instanceId' failed to satisfy constraint: Member must have length greater than or equal to 10; Value 'dw-probe' at 'instanceId' failed to satisfy constraint: Member must satisfy regular expression pattern: (^i-(\\w{8}|\\w{17})$)|(^mi-\\w{17}$)",
"eventCategory": "Management",
"eventID": "cb4af5b4-0680-43fd-a55f-dfdfee0408ab",
"eventName": "DescribeEffectiveInstanceAssociations",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:46:11Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "acc62908-e007-40d8-894e-0a26f6c57894",
"requestParameters": {
"instanceId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeEffectivePatchesForPatchBaseline
#Description
Retrieves the current effective patches (the patch and the approval state) for the specified patch baseline.
DescribeInstanceAssociationsStatus
#Description
The status of the associations for the managed nodes.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "2 validation errors detected: Value 'dw-probe' at 'instanceId' failed to satisfy constraint: Member must have length greater than or equal to 10; Value 'dw-probe' at 'instanceId' failed to satisfy constraint: Member must satisfy regular expression pattern: (^i-(\\w{8}|\\w{17})$)|(^mi-\\w{17}$)",
"eventCategory": "Management",
"eventID": "130ba2fb-33b1-424a-bb92-d6d75f9f6c65",
"eventName": "DescribeInstanceAssociationsStatus",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:46:11Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "2c9a1ada-d267-436d-802a-a35fdb5b53fc",
"requestParameters": {
"instanceId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeInstanceInformation
#Description
Provides information about one or more of your managed nodes, including the operating system platform, SSM Agent version, association status, and IP address.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "31084771-651b-4632-87f4-7511fbdfb1bd",
"eventName": "DescribeInstanceInformation",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2023-07-10T11:56:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "f146ac8b-04a0-47ac-b33a-0b1274622e6a",
"requestParameters": {
"filters": [
{
"key": "InstanceIds",
"values": [
"i-0dbc91f429e48eeed"
]
}
]
},
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1518
References #
DescribeInstancePatchStates
#Description
Retrieves the high-level patch state of one or more managed nodes.
DescribeInstancePatchStatesForPatchGroup
#Description
Retrieves the high-level patch state for the managed nodes in the specified patch group.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "27cb5812-61c8-4aab-aded-e26068deafd3",
"eventName": "DescribeInstancePatchStatesForPatchGroup",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:46:11Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "cb2a8271-52f9-48df-b1d1-6e5d318deacf",
"requestParameters": {
"patchGroup": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeInstanceProperties
#Description
An API operation used by the Systems Manager console to display information about Systems Manager managed nodes.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "cf674e6f-1d90-4e2b-8d1f-9314510554ca",
"eventName": "DescribeInstanceProperties",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:32:46Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "94bd2f16-870e-4a44-bca2-bb2127fd4e53",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeInventoryDeletions
#Description
Describes a specific delete inventory operation.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "916d7af2-c4d3-4e7c-a693-cb8fde3e1205",
"eventName": "DescribeInventoryDeletions",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2018-10-17T20:32:14Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "d1b31e2f-b6c2-46ff-85d2-f3889e6d1b71",
"requestParameters": null,
"resources": [],
"responseElements": null,
"sourceIPAddress": "9.245.1.85",
"userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeMaintenanceWindowExecutions
#Description
Lists the executions of a maintenance window.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "1 validation error detected: Value at 'windowId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^mw-[0-9a-f]{17}$",
"eventCategory": "Management",
"eventID": "c0d45215-cead-4cc1-a7b8-d17ac023d116",
"eventName": "DescribeMaintenanceWindowExecutions",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:46:11Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "3050394e-3d75-482a-9e19-5e74e651d297",
"requestParameters": {
"windowId": "dddddddddddddddddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeMaintenanceWindowExecutionTaskInvocations
#Description
Retrieves the individual task executions (one per target) for a particular task run as part of a maintenance window execution.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "2 validation errors detected: Value at 'windowExecutionId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[0-9a-fA-F]{8}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{12}$; Value at 'taskId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[0-9a-fA-F]{8}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{12}$",
"eventCategory": "Management",
"eventID": "d6c20136-a34e-4720-97ce-50d9c4774cd2",
"eventName": "DescribeMaintenanceWindowExecutionTaskInvocations",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:46:11Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "b581a7ea-daac-4f1f-8f82-ee3bff87724d",
"requestParameters": {
"taskId": "dddddddddddddddddddddddddddddddddddd",
"windowExecutionId": "dddddddddddddddddddddddddddddddddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeMaintenanceWindowExecutionTasks
#Description
For a given maintenance window execution, lists the tasks that were run.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "1 validation error detected: Value at 'windowExecutionId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[0-9a-fA-F]{8}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{12}$",
"eventCategory": "Management",
"eventID": "e3768e59-ff25-4f07-89d1-90eaae0bb67a",
"eventName": "DescribeMaintenanceWindowExecutionTasks",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:46:11Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "6e48fd38-3777-40d8-a1e7-0d24b2284140",
"requestParameters": {
"windowExecutionId": "dddddddddddddddddddddddddddddddddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeMaintenanceWindows
#Description
Retrieves the maintenance windows in an Amazon Web Services account.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "9e93b985-067b-4ab2-b4e0-b90818da30",
"eventName": "DescribeMaintenanceWindows",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2018-10-17T20:32:15Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "a57009-6166-44e6-b387-f7be9b2a5aa8",
"requestParameters": null,
"resources": [],
"responseElements": null,
"sourceIPAddress": "9.245.1.85",
"userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeMaintenanceWindowSchedule
#Description
Retrieves information about upcoming executions of a maintenance window.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "ValidationException",
"errorMessage": "Must provide either a valid WindowId or target, but not both.",
"eventID": "d58b2b9f-fb73-4f2b-b387-6d47b950e328",
"eventName": "DescribeMaintenanceWindowSchedule",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2018-10-17T20:32:15Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "010898fac-58b0-4e3b-b767-1c17ece4a81d",
"requestParameters": null,
"resources": [],
"responseElements": null,
"sourceIPAddress": "9.245.1.85",
"userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeMaintenanceWindowsForTarget
#Description
Retrieves information about the maintenance window targets or tasks that a managed node is associated with.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "2 validation errors detected: Value at 'targets.1.member.values' failed to satisfy constraint: Member must not be null; Value at 'targets.1.member.key' failed to satisfy constraint: Member must not be null",
"eventCategory": "Management",
"eventID": "e0cffdb6-9405-4f67-a7b2-f693cee9c1b4",
"eventName": "DescribeMaintenanceWindowsForTarget",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:46:11Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "333a1261-5364-46ee-859b-e1060d6a60d7",
"requestParameters": {
"resourceType": "INSTANCE",
"targets": [
{}
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeMaintenanceWindowTargets
#Description
Lists the targets registered with the maintenance window.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "1 validation error detected: Value at 'windowId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^mw-[0-9a-f]{17}$",
"eventCategory": "Management",
"eventID": "c70389ef-afbb-4002-9c7d-5155120ec9b4",
"eventName": "DescribeMaintenanceWindowTargets",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:46:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "42a2dd8e-ee38-45f1-81c6-57e2d2f71844",
"requestParameters": {
"windowId": "dddddddddddddddddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeMaintenanceWindowTasks
#Description
Lists the tasks in a maintenance window.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "1 validation error detected: Value at 'windowId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^mw-[0-9a-f]{17}$",
"eventCategory": "Management",
"eventID": "17f0f5f7-fb86-48db-84da-70da3cd516aa",
"eventName": "DescribeMaintenanceWindowTasks",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:46:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "2f4e570b-41cf-4813-853d-bde1e65ef807",
"requestParameters": {
"windowId": "dddddddddddddddddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeOpsItems
#Description
Query a set of OpsItems.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: ssm:DescribeOpsItems on resource: arn:aws:ssm:us-east-1:811596193553:*",
"eventID": "efba09c0-786a-47af-be63-1147d732c1df",
"eventName": "DescribeOpsItems",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2020-06-10T05:35:37Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "e299fdfa-2b7b-47d1-bc2d-5db84418422d",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "251.105.254.1",
"userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeParameters
#Description
Lists the parameters in your Amazon Web Services account or the parameters shared with you when you enable the Shared option.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "ee1aebd5-7f00-4af5-b150-6c13598ce418",
"eventName": "DescribeParameters",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2023-07-10T11:58:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "5b0be49c-7d15-4cae-99ba-15f7ef95cad3",
"requestParameters": {
"maxResults": 10,
"nextToken": "AAEAASOszR5OBQ4RDciQegOaCl6Zq8rrJIxfnEcfNL/Ewge/AAAAAGSr8mPsv80kHuiSIHxVshJUMtXQoPHxkvZFBz1WzlVHSM37sNKja344OydoFrxGTyHjKxKa+4zBdCjog5HJhnnP5kXewwsCb206xirvHT2aLFq/I0dTKd+YcwC+xN8yJCmR15W5o8+q+xOzYnJ3r2yOnS45AMu0kz6reaneUvnAoOBwj6PgyogUkmkiZgOJzpTxOnQgesT/d2Fs8OSsW/cdhphIB6N/8yptjrgrjrAdXdqZibQB3MAuhZRh3mZPMXgi/VpbeG6qLS5WppEj1OfikloZ0Zp5EhnPydTOOmI37ZlhZFc/b5X6sSYTi+df2/RXTeah096HvrK3z0mIIS0GVu4TwH0ugt3fNlW1WXNP/x3eVffyAQPDeocjDlL8XECE8GRpFD1V3VJvjQ2AJfDbMXvmhItKnhfPBlMZXOA6yr4oAvr88/acdOD7RRc4+4ji9bkY9TXXc6tPJJuydQvKl/XkzpNcTDUMk3YPTKUI79rN8q6e+YAXTTWCXMT2MGEf4jXlt/h9fAV2t3YjQ03Howy/rgbgjBYEd5jb2MiU4OoN/OUuTmw/51KmqZCBTpM3mAxZRsF/AJC52S3EU9fkAowUPzfX8mSTFosMS/dfUvcSITRfnd7KX5WubIDgaELeraALTABGaCvpsyVLYTr5KmpmHsVgE83exL23f+dZBl6OJA==",
"shared": false
},
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "stratus-red-team_11a6ef34-e130-4579-a1d3-79c915cee6ec",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribePatchBaselines
#Description
Lists the patch baselines in your Amazon Web Services account.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "85414c80-4bcf-4e01-8f50-380461dafb3d",
"eventName": "DescribePatchBaselines",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2018-10-17T20:32:15Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "daec38c9-5b61-4a75-90fe-41497da9ed89",
"requestParameters": null,
"resources": [],
"responseElements": null,
"sourceIPAddress": "9.245.1.85",
"userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribePatchGroups
#Description
Lists all patch groups that have been registered with patch baselines.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "8f97d241-b703-4f2d-acca-7c09c669b346",
"eventName": "DescribePatchGroups",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2018-10-17T20:32:15Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "4be88d4b-9ff7-470a-be75-e479620a9",
"requestParameters": null,
"resources": [],
"responseElements": null,
"sourceIPAddress": "9.245.1.85",
"userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribePatchGroupState
#Description
Returns high-level aggregated patch compliance state information for a patch group.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "8ffabaca-a4d1-4cd8-a070-26b78af902f3",
"eventName": "DescribePatchGroupState",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:46:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "6dbceef0-5137-49e1-99b3-274719603363",
"requestParameters": {
"patchGroup": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribePatchProperties
#Description
Lists the properties of available patches organized by product, product family, classification, severity, and other properties of available patches.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "PatchSet is required when OperatingSystem is Windows and Property is either PRODUCT or PRODUCT_FAMILY",
"eventCategory": "Management",
"eventID": "44d39407-edf9-485e-9e2e-86ad7e45951c",
"eventName": "DescribePatchProperties",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:46:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "4f86c8d9-112b-449b-a980-ea4608c59844",
"requestParameters": {
"operatingSystem": "WINDOWS",
"property": "PRODUCT"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeSessions
#Description
Retrieves a list of all active sessions (both connected and disconnected) or terminated sessions from the past 30 days.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "5905a68d-29c4-47b5-9f6c-fdd7d6276500",
"eventName": "DescribeSessions",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2019-09-12T18:28:17Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "f09a2b35-41ab-42ec-b0e9-7c32ad7e07a4",
"requestParameters": {
"state": "History"
},
"responseElements": {
"sessions": []
},
"sourceIPAddress": "163.23.3.0",
"userAgent": "Boto3/1.9.165 Python/3.5.2 Linux/4.15.0-55-generic Botocore/1.12.165",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
GetAccessToken
#Description
Returns a credentials set to be used with just-in-time node access.
GetAutomationExecution
#Description
Get detailed information about a particular Automation execution.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "1 validation error detected: Value at 'automationExecutionId' failed to satisfy constraint: Member must satisfy regular expression pattern: [a-fA-F0-9]{8}-[a-fA-F0-9]{4}-[a-fA-F0-9]{4}-[a-fA-F0-9]{4}-[a-fA-F0-9]{12}",
"eventCategory": "Management",
"eventID": "3b52e6d3-87cd-4903-bd61-ee326263423e",
"eventName": "GetAutomationExecution",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:46:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "0903ba55-7b3e-4c42-8d53-8078d8ae6860",
"requestParameters": {
"automationExecutionId": "dddddddddddddddddddddddddddddddddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetCalendarState
#Description
Gets the state of a Amazon Web Services Systems Manager change calendar at the current time or a specified time.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidDocument",
"errorMessage": "The specified Change Calendar Document 'arn:aws:iam::123456789012:role/dw-probe' does not exist.",
"eventCategory": "Management",
"eventID": "4fd978f9-67e2-45d6-9a79-81834245cd84",
"eventName": "GetCalendarState",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:46:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "ec57fd47-b1c8-44e4-acee-e44451631247",
"requestParameters": {
"calendarNames": [
"arn:aws:iam::123456789012:role/dw-probe"
]
},
"resources": [
{
"ARN": "arn:aws:iam::123456789012:role/dw-probe",
"accountId": "123456789012"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetCommandInvocation
#Description
Returns detailed information about command execution for an invocation or plugin.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "1924d89a-7dde-4a0b-8d3d-5de7cce7dd81",
"eventName": "GetCommandInvocation",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2023-07-10T11:57:21Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "40ac240e-7387-4add-a976-348c3c9854e5",
"requestParameters": {
"commandId": "bbf52fc0-1a25-4020-b1b4-1872ff8edd12",
"instanceId": "i-0dbc91f429e48eeed"
},
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
GetConnectionStatus
#Description
Retrieves the Session Manager connection status for a managed node to determine whether it is running and ready to receive Session Manager connections.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "459c6e28-df93-4e4c-9269-10458a3c971e",
"eventSource": "ssm.amazonaws.com",
"eventName": "GetConnectionStatus",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "1f1e3ab6-a28d-46a4-ad66-9fd70df0ceb1",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
"tlsDetails": {
"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com"
}
}
GetDefaultPatchBaseline
#Description
Retrieves the default patch baseline.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: ssm:GetDefaultPatchBaseline on resource: arn:aws:ssm:us-east-1:811596193553:*",
"eventID": "dc8bb942-720b-4fbd-82eb-eca30d8f99b5",
"eventName": "GetDefaultPatchBaseline",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2019-10-19T23:49:26Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "015c66b9-77f3-4b81-b779-624eac37bd01",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "213.253.166.5",
"userAgent": "Boto3/1.9.210 Python/2.7.10 Darwin/18.7.0 Botocore/1.12.210",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
GetDeployablePatchSnapshotForInstance
#Description
Retrieves the current snapshot for the patch baseline the managed node uses.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "5b7e3859-ab93-46ca-9060-16634aadfc75",
"eventSource": "ssm.amazonaws.com",
"eventName": "GetDeployablePatchSnapshotForInstance",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "a3aed819-090f-40d0-b5a6-aa419c925a02",
"userAgent": "Boto3/1.10.50 Python/3.10.12 Linux/5.15.0-1022-aws Botocore/1.13.50",
"tlsDetails": {
"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com"
}
}
GetDocument
#Description
Gets the contents of the specified Amazon Web Services Systems Manager document (SSM document).
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "ea812b7e-ebeb-4950-8dc8-a4a9af56a8c6",
"eventName": "GetDocument",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2023-07-10T11:57:45Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "9c938fe7-19f8-4c55-bbf0-34380b80558e",
"requestParameters": {
"documentVersion": "1",
"name": "AWS-GatherSoftwareInventory"
},
"responseElements": null,
"sourceIPAddress": "3.225.16.109",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "aws-sdk-go/1.41.4 (go1.18.3; linux; amd64) amazon-ssm-agent/",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCSHSEVYP5",
"accountId": "123837392027",
"arn": "arn:aws:sts::123837392027:assumed-role/stratus-red-team-ec2-steal-credentials-role/i-0dbc91f429e48eeed",
"principalId": "AROATFQR7NSC6Q6YRQ2Q7:i-0dbc91f429e48eeed",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T11:55:22Z",
"mfaAuthenticated": "false"
},
"ec2RoleDelivery": "2.0",
"sessionIssuer": {
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:role/stratus-red-team-ec2-steal-credentials-role",
"principalId": "AROATFQR7NSC6Q6YRQ2Q7",
"type": "Role",
"userName": "stratus-red-team-ec2-steal-credentials-role"
},
"webIdFederationData": {}
},
"type": "AssumedRole"
}
}
References #
GetExecutionPreview
#Description
Initiates the process of retrieving an existing preview that shows the effects that running a specified Automation runbook would have on the targeted resources.
GetMaintenanceWindow
#Description
Retrieves a maintenance window.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "1 validation error detected: Value at 'windowId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^mw-[0-9a-f]{17}$",
"eventCategory": "Management",
"eventID": "45077c58-9f2e-4b9d-b33d-4ff6b52ff487",
"eventName": "GetMaintenanceWindow",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:46:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "e9020eb6-c427-4cb1-9388-b78fbe2a08a9",
"requestParameters": {
"windowId": "dddddddddddddddddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetMaintenanceWindowExecution
#Description
Retrieves details about a specific a maintenance window execution.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "1 validation error detected: Value at 'windowExecutionId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[0-9a-fA-F]{8}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{12}$",
"eventCategory": "Management",
"eventID": "0d0f3dae-54bf-4bcb-b662-2f283928f41a",
"eventName": "GetMaintenanceWindowExecution",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:46:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "e5bc1bdf-1029-4485-b591-14ca5c81dcab",
"requestParameters": {
"windowExecutionId": "dddddddddddddddddddddddddddddddddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetMaintenanceWindowExecutionTask
#Description
Retrieves the details about a specific task run as part of a maintenance window execution.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "2 validation errors detected: Value at 'windowExecutionId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[0-9a-fA-F]{8}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{12}$; Value at 'taskId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[0-9a-fA-F]{8}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{12}$",
"eventCategory": "Management",
"eventID": "ea842d48-1217-4d16-b75f-39ddd545e015",
"eventName": "GetMaintenanceWindowExecutionTask",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:46:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "eb72bb43-0e10-4c42-9d92-31a317cb0ef4",
"requestParameters": {
"taskId": "dddddddddddddddddddddddddddddddddddd",
"windowExecutionId": "dddddddddddddddddddddddddddddddddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetMaintenanceWindowExecutionTaskInvocation
#Description
Retrieves information about a specific task running on a specific target.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "3 validation errors detected: Value at 'windowExecutionId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[0-9a-fA-F]{8}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{12}$; Value at 'invocationId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[0-9a-fA-F]{8}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{12}$; Value at 'taskId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[0-9a-fA-F]{8}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{12}$",
"eventCategory": "Management",
"eventID": "c72ba639-4e8d-4203-9129-23b8ec045ffc",
"eventName": "GetMaintenanceWindowExecutionTaskInvocation",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:46:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "57406dfd-2369-4d62-9046-1a0219845cc4",
"requestParameters": {
"invocationId": "dddddddddddddddddddddddddddddddddddd",
"taskId": "dddddddddddddddddddddddddddddddddddd",
"windowExecutionId": "dddddddddddddddddddddddddddddddddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetMaintenanceWindowTask
#Description
Retrieves the details of a maintenance window task.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "2 validation errors detected: Value at 'windowTaskId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[0-9a-fA-F]{8}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{12}$; Value at 'windowId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^mw-[0-9a-f]{17}$",
"eventCategory": "Management",
"eventID": "06988c06-f6e0-4b35-93cf-21068a4e77bf",
"eventName": "GetMaintenanceWindowTask",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:46:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "6012130e-4b13-45cf-b03d-b841a3fe4323",
"requestParameters": {
"windowId": "dddddddddddddddddddd",
"windowTaskId": "dddddddddddddddddddddddddddddddddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetOpsItem
#Description
Get information about an OpsItem by using the ID.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "6387aaa4-a35f-4c35-a434-82bc3eef1785",
"eventSource": "ssm.amazonaws.com",
"eventName": "GetOpsItem",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "bcea32ff-2ab7-4a20-be19-7fe004be0514",
"userAgent": "opsinsights.ssm.amazonaws.com"
}
GetOpsMetadata
#Description
View operational metadata related to an application in Application Manager.
GetOpsSummary
#Description
View a summary of operations metadata (OpsData) based on specified filters and aggregators.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "0bf3916b-6cff-406d-8235-16afaa42499e",
"eventName": "GetOpsSummary",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:32:46Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "0614a0e3-52f1-4aa4-8c9c-824dbaddf82d",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetParameterHistory
#Description
Retrieves the history of all changes to a parameter.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "f2f3f6af-a0ef-4f21-9594-580a3b123b46",
"eventName": "GetParameterHistory",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:46:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "1e6144d3-977a-4138-a07d-3b10086ad981",
"requestParameters": {
"name": "ddddd"
},
"resources": [
{
"ARN": "arn:aws:ssm:us-west-1:123456789012:parameter/ddddd",
"accountId": "123456789012"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetParametersByPath
#Description
Retrieve information about one or more parameters under a specified level in a hierarchy.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "2b902d6c-9f41-40bd-8ffb-6c2715455b75",
"eventName": "GetParametersByPath",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:46:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "18ffda17-3388-43b9-a561-e53d4d781953",
"requestParameters": {
"path": "ddddd"
},
"resources": [
{
"ARN": "arn:aws:ssm:us-west-1:123456789012:parameter/ddddd",
"accountId": "123456789012"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetPatchBaseline
#Description
Retrieves information about a patch baseline.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "8fffe675-27cc-4918-be98-04d32618ff46",
"eventSource": "ssm.amazonaws.com",
"eventName": "GetPatchBaseline",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "dc2a74a5-3473-402c-b9f8-5f172ca91ae8",
"userAgent": "Boto3/1.42.97 md/Botocore#1.42.97 ua/2.1 os/linux#5.10.255-259-299.1043.amzn2.x86_64 md/arch#x86_64 lang/python#3.11.15 md/pyimpl#CPython exec-env/AWS_Lambda_python3.11 m/D,b,Z cfg/retry-mode#legacy Botocore/1.42.97",
"tlsDetails": {
"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com"
}
}
GetPatchBaselineForPatchGroup
#Description
Retrieves the patch baseline that should be used for the specified patch group.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "33487ccb-e581-4312-ab78-943dd17eff39",
"eventName": "GetPatchBaselineForPatchGroup",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:46:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "9318aa52-6603-4538-8d28-f2a670e4afae",
"requestParameters": {
"patchGroup": "ddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetResourcePolicies
#Description
Returns an array of the Policy object.
GetServiceSetting
#Description
ServiceSetting is an account-level setting for an Amazon Web Services service.
Example CloudTrail Event #
{
"awsRegion": "us-east-2",
"eventCategory": "Management",
"eventID": "a7fa27fa-0712-487d-940c-c78e25b97068",
"eventName": "GetServiceSetting",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2021-07-07T19:58:36Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "797507667711",
"requestID": "5fe799a7-891e-4d03-9515-621d78935473",
"requestParameters": {
"settingId": "/ssm/opsdata/Association"
},
"resources": [
{
"ARN": "arn:aws:ssm:us-east-2:797507667711:servicesetting/ssm/opsdata/Association",
"accountId": "797507667711"
}
],
"responseElements": null,
"sourceIPAddress": "ssm.amazonaws.com",
"userAgent": "ssm.amazonaws.com",
"userIdentity": {
"accessKeyId": "ASIA3TLZJI37ZGYXYJR6",
"accountId": "797507667711",
"arn": "arn:aws:sts::797507667711:assumed-role/AWSServiceRoleForAmazonSSM/SSMExplorerOnboarding",
"invokedBy": "ssm.amazonaws.com",
"principalId": "AROA3TLZJI375YZ4W5JE6:SSMExplorerOnboarding",
"sessionContext": {
"attributes": {
"creationDate": "2021-07-07T19:58:36Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {
"accountId": "797507667711",
"arn": "arn:aws:iam::797507667711:role/aws-service-role/ssm.amazonaws.com/AWSServiceRoleForAmazonSSM",
"principalId": "AROA3TLZJI375YZ4W5JE6",
"type": "Role",
"userName": "AWSServiceRoleForAmazonSSM"
},
"webIdFederationData": {}
},
"type": "AssumedRole"
}
}
References #
LabelParameterVersion
#Description
A parameter label is a user-defined alias to help you manage different versions of a parameter.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "918605c3-889a-4242-9478-480168544f7f",
"eventName": "LabelParameterVersion",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T19:12:21Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "c8bb2d96-1300-4b63-b25e-ce7fc5e9bb9f",
"requestParameters": {
"labels": [
"dw"
],
"name": "/dwfix/p"
},
"resources": [
{
"ARN": "arn:aws:ssm:us-west-1:123456789012:parameter/dwfix/p",
"accountId": "123456789012"
}
],
"responseElements": {
"invalidLabels": [],
"parameterVersion": 1
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListAssociations
#Description
Returns all State Manager associations in the current Amazon Web Services account and Amazon Web Services Region.
Example CloudTrail Event #
{
"awsRegion": "sa-east-1",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::731544447609:user/cloudsploit is not authorized to perform: ssm:ListAssociations on resource: arn:aws:ssm:sa-east-1:731544447609:*",
"eventCategory": "Management",
"eventID": "ef889ee9-73ab-4dad-8072-ac683b51ea3a",
"eventName": "ListAssociations",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2021-04-13T11:35:43Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "731544447609",
"requestID": "47d6788d-473e-40f6-8944-18a79cc15602",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "34.12.134.20",
"userAgent": "aws-sdk-nodejs/2.885.0 linux/v14.16.1 callback",
"userIdentity": {
"accessKeyId": "AKIAYTOGP2RLGBSBSMH2",
"accountId": "731544447609",
"arn": "arn:aws:iam::731544447609:user/cloudsploit",
"principalId": "AIDAYTOGP2RLMDEPWZWMJ",
"type": "IAMUser",
"userName": "cloudsploit"
}
}
References #
ListAssociationVersions
#Description
Retrieves all versions of an association for a specific association ID.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "1 validation error detected: Value 'dw-probe' at 'associationId' failed to satisfy constraint: Member must satisfy regular expression pattern: [0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}",
"eventCategory": "Management",
"eventID": "2fb30cf4-a03f-411e-abb1-0f05bf100bed",
"eventName": "ListAssociationVersions",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:46:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "edea72e1-36d3-4577-a816-d14e661f23db",
"requestParameters": {
"associationId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListCommandInvocations
#Description
An invocation is copy of a command sent to a specific managed node.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: ssm:ListCommandInvocations on resource: arn:aws:ssm:us-east-1:811596193553:*",
"eventID": "7d79776b-f8e7-44be-8237-7eece17704bf",
"eventName": "ListCommandInvocations",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2019-10-19T23:49:23Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "ec4ef62c-d4ff-4883-bde8-b615e67bfc35",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "213.253.166.5",
"userAgent": "Boto3/1.9.210 Python/2.7.10 Darwin/18.7.0 Botocore/1.12.210",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
ListComplianceItems
#Description
For a specified resource ID, this API operation returns a list of compliance statuses for different resource types.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: ssm:ListComplianceItems on resource: arn:aws:ssm:us-east-1:811596193553:*",
"eventID": "0f7e1e45-cdb1-41b4-b2df-7d0db13e5527",
"eventName": "ListComplianceItems",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2019-10-19T23:49:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "a40634d-fc1d-44ec-9210-e5a630bc9583",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "213.253.166.5",
"userAgent": "Boto3/1.9.210 Python/2.7.10 Darwin/18.7.0 Botocore/1.12.210",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
ListComplianceSummaries
#Description
Returns a summary count of compliant and non-compliant resources for a compliance type.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: ssm:ListComplianceSummaries on resource: arn:aws:ssm:us-east-1:811596193553:*",
"eventID": "2147ef0b-dd43-435a-be6a-4b4da446275a",
"eventName": "ListComplianceSummaries",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2019-10-19T23:49:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "95d5664b-07c1-47ac-a0d4-d0bfeff68a88",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "213.253.166.5",
"userAgent": "Boto3/1.9.210 Python/2.7.10 Darwin/18.7.0 Botocore/1.12.210",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
ListDocumentMetadataHistory
#Description
Amazon Web Services Systems Manager Change Manager is no longer open to new customers.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidDocument",
"errorMessage": "Document with name dw-probe does not exist.",
"eventCategory": "Management",
"eventID": "bc19ba25-7d44-43c2-9892-a022f07b389a",
"eventName": "ListDocumentMetadataHistory",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:46:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "a7a2a78f-13b2-4f3c-943d-c43e0b899dd4",
"requestParameters": {
"metadata": "DocumentReviews",
"name": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListDocuments
#Description
Returns all Systems Manager (SSM) documents in the current Amazon Web Services account and Amazon Web Services Region.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"eventID": "60232-d234-43c5-ad0a-9899a814c45c",
"eventName": "ListDocuments",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2018-02-24T14:07:04Z",
"eventType": "AwsApiCall",
"eventVersion": "1.04",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "fde8fe19-196b-11e8-bd17-6353eb759645a",
"requestParameters": {
"nextToken": "AAMAAe3kWXUBkOucQH5dRt07QpFarDfzafvljnZRFBkhaIYtAAAAAFqRcYhiGccbGS4Cy4b/kW1KfoXNoY8eBMZzHfplgc+WHv2jNXbl8YFgM9vt5+VC4QkTVrB+1F1Rxg6rVBsdRawI6yL6kyTBHZkzoR6l0hV+xs7VqA8SrRlz4U3SndVhK0Mp6fGbgf/ZRGXgn03rXeYJGlqEOWGNIB7qdVRhxzGtVfRVz6hgH72U4QZGBzH3Qv5UBfvkBShvnWfeuFqddE0p9Iocu2LDIU/6WTN486HQOG+/dpDDZ3v0HwPbjo4T7ouvEEIWv8wD3yK3R8FI9iwDQE2Ir9v/PH+t1RsBA1JcAxEclxE+YgdREOpgLeSOoivNVsbD91qam4nQgeBwo5azJyUoj3afDK+/Ngjqu/nRfmit8AqFypbqxzp/LLAABdWLf80vZ04D5fWsUgpUVeWseT5mzLEuDR3Cc54w+cqrz+RAW3Ea0rWha5198UzceqtKRtbssNTVfDMjyZyLQeRb2yjgE74KLb8fCVtQoOVeNpPGXAAFPme3uWoJVzY2jnbbQXoRABA2Ly/R2/0xSimeWth4BTSo8pAqUm4cjsy24E8nJHC5QAbI3LoPqqDoa+7Bb+QvLbLhcUr+4NGgW3G0JBiw6u1lonNMtAI0fhkFWd6z1zPYoBrEpgIpjjWwNOM/bA3cyrfSvzY+nM/HLJcktUhKKoCr88Ua7L6CzMbEGFkRKXesS/4OtBDEdhoXCWRcyAKbICXx0Zg7yjhtyO0ZCQo5pYaYj5g1b3iL1kl6C9BQ2zKbUYjBbsi/3KKFCh8OXjG7T1+9HK3F3BTfWeIehbkP"
},
"resources": [],
"responseElements": null,
"sourceIPAddress": "245.181.7.4",
"userAgent": "aws-cli/1.14.44 Python/3.6.4 Linux/4.15.5-1-ARCH botocore/1.8.48",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
ListDocumentVersions
#Description
List all versions for a document.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidDocument",
"errorMessage": "Invalid document name arn:aws:iam::123456789012:role/dw-probe",
"eventCategory": "Management",
"eventID": "6bb5f39a-8886-4277-9618-6e296bfb3118",
"eventName": "ListDocumentVersions",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:46:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "40ae5b39-56d1-4f83-ae72-ab1c7d6ed24e",
"requestParameters": {
"name": "arn:aws:iam::123456789012:role/dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListNodes
#Description
Takes in filters and returns a list of managed nodes matching the filter criteria.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "UnsupportedOperationException",
"errorMessage": "This is an unsupported operation for this account. You must first enable the Systems Manager integrated experience in your account.",
"eventCategory": "Management",
"eventID": "210d0fbe-4a61-424d-bec1-18fcfce6c626",
"eventName": "ListNodes",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:32:46Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "c189b705-d5a3-4dda-b12e-c20a1f48e5a8",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListNodesSummary
#Description
Generates a summary of managed instance/node metadata based on the filters and aggregators you specify.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "UnsupportedOperationException",
"errorMessage": "This is an unsupported operation for this account. You must first enable the Systems Manager integrated experience in your account.",
"eventCategory": "Management",
"eventID": "2057032f-6bbc-4484-af8c-1fcd25607cff",
"eventName": "ListNodesSummary",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:46:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "4ea4c824-4517-435a-8f32-f90f6ac9558a",
"requestParameters": {
"aggregators": [
{
"aggregatorType": "Count",
"attributeName": "AgentVersion",
"typeName": "Instance"
}
]
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListOpsItemEvents
#Description
Returns a list of all OpsItem events in the current Amazon Web Services Region and Amazon Web Services account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "862dffed-f98b-4d37-b228-f54b9c22fd7b",
"eventName": "ListOpsItemEvents",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:32:46Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "d578a3de-91f3-4012-aa89-44229583c9f8",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListOpsMetadata
#Description
Amazon Web Services Systems Manager calls this API operation when displaying all Application Manager OpsMetadata objects or blobs.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "a32c61f6-1143-40d0-a972-d97f99a26138",
"eventName": "ListOpsMetadata",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T18:32:46Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "986428f4-dd74-4f10-a636-3eba8108cbec",
"requestParameters": null,
"resources": [
{
"ARN": "arn:aws:ssm:us-west-1:123456789012:*",
"accountId": "123456789012"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListResourceComplianceSummaries
#Description
Returns a resource-level summary count.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: ssm:ListResourceComplianceSummaries on resource: arn:aws:ssm:us-east-1:811596193553:*",
"eventID": "47a49d91-a9e3-4884-a6f7-23b5bf412ee2",
"eventName": "ListResourceComplianceSummaries",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2019-10-19T23:49:23Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "39a495819-162a-4676-90e8-f2f8af5f9277",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "213.253.166.5",
"userAgent": "Boto3/1.9.210 Python/2.7.10 Darwin/18.7.0 Botocore/1.12.210",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
ListResourceDataSync
#Description
Lists your resource data sync configurations.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: ssm:ListResourceDataSync on resource: arn:aws:ssm:us-east-1:811596193553:*",
"eventID": "d9ead80c-d6ed-4cae-8597-488012ffc08",
"eventName": "ListResourceDataSync",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2019-10-19T23:49:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "bd465ced-0b26-47d5-b95b-5f2d50c66aa4",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "213.253.166.5",
"userAgent": "Boto3/1.9.210 Python/2.7.10 Darwin/18.7.0 Botocore/1.12.210",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
ModifyDocumentPermission
#Description
Shares a Amazon Web Services Systems Manager document (SSM document)publicly or privately.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidParameterException",
"errorMessage": "Either AccountIdsToAdd or AccountIdsToRemove must be specified for API operation",
"eventCategory": "Management",
"eventID": "4f71bac2-52b3-47dd-b886-6b74aac101c6",
"eventName": "ModifyDocumentPermission",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T19:26:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "c89c69a5-6fe0-4319-a1f8-086b3fdcb9c2",
"requestParameters": {
"name": "dw-probe",
"permissionType": "Share"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1526
PutComplianceItems
#Description
Registers a compliance type and other compliance details on a designated resource.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "46041132-1dd7-49f5-88af-4b3f3521f861",
"eventName": "PutComplianceItems",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2023-07-10T11:58:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "7fd23164-de26-4f96-bd5f-0ddf9d425657",
"requestParameters": {
"complianceType": "Association",
"executionSummary": {
"executionId": "",
"executionTime": "Jul 10, 2023, 11:58:13 AM",
"executionType": ""
},
"itemContentHash": "69y67YXkh+2LwNYisaGL/A==",
"items": [
{
"details": {
"DocumentName": "AWS-GatherSoftwareInventory",
"DocumentVersion": "1"
},
"id": "56fcb26d-8140-4f3f-8f77-7ff7344b4057",
"severity": "UNSPECIFIED",
"status": "COMPLIANT",
"title": ""
}
],
"resourceId": "i-0dbc91f429e48eeed",
"resourceType": "ManagedInstance"
},
"responseElements": null,
"sourceIPAddress": "3.225.16.109",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "aws-sdk-go/1.41.4 (go1.18.3; linux; amd64) amazon-ssm-agent/",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCSHSEVYP5",
"accountId": "123837392027",
"arn": "arn:aws:sts::123837392027:assumed-role/stratus-red-team-ec2-steal-credentials-role/i-0dbc91f429e48eeed",
"principalId": "AROATFQR7NSC6Q6YRQ2Q7:i-0dbc91f429e48eeed",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T11:55:22Z",
"mfaAuthenticated": "false"
},
"ec2RoleDelivery": "2.0",
"sessionIssuer": {
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:role/stratus-red-team-ec2-steal-credentials-role",
"principalId": "AROATFQR7NSC6Q6YRQ2Q7",
"type": "Role",
"userName": "stratus-red-team-ec2-steal-credentials-role"
},
"webIdFederationData": {}
},
"type": "AssumedRole"
}
}
References #
PutInventory
#Description
Bulk update custom inventory items on one or more managed nodes.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "7e486988-6d22-4c5d-9b55-eba68b0f23d9",
"eventName": "PutInventory",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2023-07-10T11:58:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "dbb09c3f-9e39-478c-a0ec-515fd3aa4a2a",
"requestParameters": {
"instanceId": "i-0dbc91f429e48eeed",
"items": [
{
"captureTime": "2023-07-10T11:57:45Z",
"contentHash": "lDHZTHFNUyHYPLo8R7wPSA==",
"schemaVersion": "1.0",
"typeName": "AWS:Network"
},
{
"captureTime": "2023-07-10T11:57:45Z",
"contentHash": "N6YlnMDB2uKZp4Zkid/wvQ==",
"schemaVersion": "1.0",
"typeName": "AWS:BillingInfo"
},
{
"captureTime": "2023-07-10T11:57:45Z",
"contentHash": "omMpn3JVX/I6oe7BzY9EFA==",
"schemaVersion": "1.0",
"typeName": "AWS:InstanceDetailedInformation"
},
{
"captureTime": "2023-07-10T11:57:45Z",
"contentHash": "M1LVyOGk7deedu/aVytRVg==",
"schemaVersion": "1.1",
"typeName": "AWS:Application"
},
{
"captureTime": "2023-07-10T11:57:46Z",
"contentHash": "DLq350DMx3pp69NF6sJlfg==",
"schemaVersion": "1.0",
"typeName": "AWS:AWSComponent"
}
]
},
"resources": [
{
"ARN": "arn:aws:ec2:us-east-1:123837392027:instance/i-0dbc91f429e48eeed",
"accountId": "123837392027"
},
{
"ARN": "arn:aws:ssm:us-east-1:123837392027:managed-instance-inventory/i-0dbc91f429e48eeed",
"accountId": "123837392027"
}
],
"responseElements": null,
"sourceIPAddress": "3.225.16.109",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "aws-sdk-go/1.41.4 (go1.18.3; linux; amd64) amazon-ssm-agent/",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCSHSEVYP5",
"accountId": "123837392027",
"arn": "arn:aws:sts::123837392027:assumed-role/stratus-red-team-ec2-steal-credentials-role/i-0dbc91f429e48eeed",
"principalId": "AROATFQR7NSC6Q6YRQ2Q7:i-0dbc91f429e48eeed",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T11:55:22Z",
"mfaAuthenticated": "false"
},
"ec2RoleDelivery": "2.0",
"sessionIssuer": {
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:role/stratus-red-team-ec2-steal-credentials-role",
"principalId": "AROATFQR7NSC6Q6YRQ2Q7",
"type": "Role",
"userName": "stratus-red-team-ec2-steal-credentials-role"
},
"webIdFederationData": {}
},
"type": "AssumedRole"
}
}
References #
PutParameter
#Description
Create or update a parameter in Parameter Store.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "93e58a50-11f0-4859-8f1c-472dd35a1aeb",
"eventName": "PutParameter",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2023-07-10T11:58:10Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "4e963a0b-fe4a-4928-a618-f37cc2f04f61",
"requestParameters": {
"allowedPattern": "",
"name": "/credentials/stratus-red-team/credentials-34",
"overwrite": false,
"tags": [
{
"key": "StratusRedTeam",
"value": "true"
}
],
"tier": "Standard",
"type": "SecureString",
"value": "HIDDEN_DUE_TO_SECURITY_REASONS"
},
"resources": [
{
"ARN": "arn:aws:ssm:us-east-1:123837392027:parameter/credentials/stratus-red-team/credentials-34",
"accountId": "123837392027"
}
],
"responseElements": {
"tier": "Standard",
"version": 1
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_11a6ef34-e130-4579-a1d3-79c915cee6ec HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
PutResourcePolicy
#Description
Creates or updates a Systems Manager resource policy.
RegisterDefaultPatchBaseline
#Description
Defines the default patch baseline for the relevant operating system.
RegisterPatchBaselineForPatchGroup
#Description
Registers a patch baseline for a patch group.
RegisterTargetWithMaintenanceWindow
#Description
Registers a target with a maintenance window.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "30f8c38e-0d52-4939-89a4-b0cae787dfad",
"eventName": "RegisterTargetWithMaintenanceWindow",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T20:58:55Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "12b65194-3b50-42d9-883b-4ad33ca05cd5",
"requestParameters": {
"clientToken": "c40ee37d-33ed-48a5-80f9-a58c651cdef1",
"description": "HIDDEN_DUE_TO_SECURITY_REASONS",
"name": "dwfix-target-ea8e728b",
"ownerInformation": "HIDDEN_DUE_TO_SECURITY_REASONS",
"resourceType": "INSTANCE",
"targets": [
{
"key": "tag:Env",
"values": [
"dwfix"
]
}
],
"windowId": "mw-06e8430a431fc17a1"
},
"resources": [
{
"ARN": "arn:aws:ssm:us-west-1:123456789012:maintenancewindow/mw-06e8430a431fc17a1",
"accountId": "123456789012"
}
],
"responseElements": {
"windowTargetId": "3ab5475a-c068-4c44-b46a-749da462f21b"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b,n cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
RegisterTaskWithMaintenanceWindow
#Description
Adds a new task to a maintenance window.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "Maintenance window tasks without targets do not support MaxErrors values. For Run Command tasks, you must specify at least one resource as the target of the task. You can specify between 1 and 50 instance IDs, or between 1 and 10 maintenance window target IDs. Maintenance window tasks without targets do not support MaxConcurrency values.",
"eventCategory": "Management",
"eventID": "1410be51-7e30-4deb-aede-af8d9791c5a4",
"eventName": "RegisterTaskWithMaintenanceWindow",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T20:58:55Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "526d7ab8-2294-4c57-87e0-71908ca07b45",
"requestParameters": {
"clientToken": "88c38243-5421-4438-8a09-97b09c1792db",
"description": "HIDDEN_DUE_TO_SECURITY_REASONS",
"maxConcurrency": "1",
"maxErrors": "1",
"name": "dwfix-task-ea8e728b",
"priority": 1,
"serviceRoleArn": "arn:aws:iam::123456789012:role/aws-service-role/ssm.amazonaws.com/AWSServiceRoleForAmazonSSM",
"taskArn": "AWS-RunShellScript",
"taskType": "RUN_COMMAND",
"windowId": "mw-06e8430a431fc17a1"
},
"resources": [
{
"ARN": "arn:aws:ssm:us-west-1:123456789012:maintenancewindow/mw-06e8430a431fc17a1",
"accountId": "123456789012"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b,n cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ResetServiceSetting
#Description
ServiceSetting is an account-level setting for an Amazon Web Services service.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "98cd697c-4a80-4825-904b-2dca1915e50f",
"eventName": "ResetServiceSetting",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T19:26:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "2a9e2d04-a426-47a7-98a3-e74944be8e94",
"requestParameters": {
"settingId": "ddddd"
},
"resources": [
{
"ARN": "arn:aws:ssm:us-west-1:123456789012:servicesetting/ddddd",
"accountId": "123456789012"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ResumeSession
#Description
Reconnects a session to a managed node after it has been disconnected.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::123456789012:user/TrailDiscover is not authorized to perform: ssm:ResumeSession on resource: arn:aws:ssm:us-east-1:192374575148:session/TrailDiscoverTarget because no identity-based policy allows the ssm:ResumeSession action",
"eventCategory": "Management",
"eventID": "414dacad-43e6-4327-aec8-dcb0caacc5dc",
"eventName": "ResumeSession",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2024-08-18T16:13:21Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "219e0244-a4ea-40b8-b870-059954972199",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "0.0.0.0",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "aws-cli/2.17.32 md/awscrt#0.21.2 ua/2.0 os/linux#0.0.0.0-microsoft-standard-WSL2 md/arch#x86_64 lang/python#3.11.9 md/pyimpl#CPython exec-env/grimoire_f303ce4d-3e7b-43b5-84c0-0b58b10696c7 cfg/retry-mode#standard md/installer#exe md/distrib#ubuntu.24 md/prompt#off md/command#ssm.resume-session",
"userIdentity": {
"accessKeyId": "AKIA****************",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/TrailDiscover",
"principalId": "AROA****************:User",
"type": "IAMUser",
"userName": "TrailDiscover"
}
}
References #
SendAutomationSignal
#Description
Sends a signal to an Automation execution to change the current behavior or status of the execution.
StartAccessRequest
#Description
Starts the workflow for just-in-time node access sessions.
StartAssociationsOnce
#Description
Runs an association immediately and only one time.
StartAutomationExecution
#Description
Initiates execution of an Automation runbook.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "be7076b9-e1ef-4df6-bc02-554ad9d66772",
"eventName": "StartAutomationExecution",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T20:58:57Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "42a9e32d-7e21-4c8d-a9a6-fb112dbca24b",
"requestParameters": {
"documentName": "dwfix-auto-ea8e728b"
},
"responseElements": {
"automationExecutionId": "42a9e32d-7e21-4c8d-a9a6-fb112dbca24b"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b,n cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
StartChangeRequestExecution
#Description
Amazon Web Services Systems Manager Change Manager is no longer open to new customers.
StartExecutionPreview
#Description
Initiates the process of creating a preview showing the effects that running a specified Automation runbook would have on the targeted resources.
StopAutomationExecution
#Description
Stop an Automation that is currently running.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "1 validation error detected: Value at 'automationExecutionId' failed to satisfy constraint: Member must satisfy regular expression pattern: [a-fA-F0-9]{8}-[a-fA-F0-9]{4}-[a-fA-F0-9]{4}-[a-fA-F0-9]{4}-[a-fA-F0-9]{12}",
"eventCategory": "Management",
"eventID": "0a191570-c4ee-4776-9f51-a93a32a674f2",
"eventName": "StopAutomationExecution",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T19:26:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7190c664-5bec-467c-9885-f99ec7dcf184",
"requestParameters": {
"automationExecutionId": "dddddddddddddddddddddddddddddddddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
TerminateSession
#Description
Permanently ends a session and closes the data connection between the Session Manager client and SSM Agent on the managed node.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "c14df3be-a906-4152-a0a7-341bb558429a",
"eventName": "TerminateSession",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T19:26:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7bb193be-b85b-4c5f-9476-36a846eac031",
"requestParameters": {
"sessionId": "ddddd"
},
"responseElements": {
"sessionId": "ddddd"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UnlabelParameterVersion
#Description
Remove a label or labels from a parameter.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "f00c75a8-84f0-42ba-81df-2e92da955dcb",
"eventName": "UnlabelParameterVersion",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T20:58:56Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "eef66032-4de5-4dd3-97dc-1e786eb548f5",
"requestParameters": {
"labels": [
"dwfixlblea8e728b"
],
"name": "/dwfix/param/ea8e728b",
"parameterVersion": 1
},
"resources": [
{
"ARN": "arn:aws:ssm:us-west-1:123456789012:parameter/dwfix/param/ea8e728b",
"accountId": "123456789012"
}
],
"responseElements": {
"invalidLabels": [
"dwfixlblea8e728b"
],
"removedLabels": []
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b,n cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateAssociation
#Description
Updates an association.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "51d8f81c-255e-460e-83f0-e778789b09ce",
"eventName": "UpdateAssociation",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T19:25:26Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "8c59f498-6037-46fe-bc9c-ed2d278c5ae8",
"requestParameters": {
"applyOnlyAtCronInterval": false,
"associationId": "c93a05c3-e24a-4016-a7bf-51d1b9a6a740",
"parameters": "HIDDEN_DUE_TO_SECURITY_REASONS"
},
"responseElements": {
"associationDescription": {
"applyOnlyAtCronInterval": false,
"associationId": "c93a05c3-e24a-4016-a7bf-51d1b9a6a740",
"associationVersion": "2",
"date": "2026-06-29T19:25:26Z",
"documentVersion": "$DEFAULT",
"lastExecutionDate": "2026-06-29T19:25:26Z",
"lastSuccessfulExecutionDate": "2026-06-29T19:25:26Z",
"lastUpdateAssociationDate": "2026-06-29T19:25:26Z",
"name": "AWS-RunShellScript",
"overview": {
"detailedStatus": "Creating",
"status": "Pending"
},
"parameters": "HIDDEN_DUE_TO_SECURITY_REASONS",
"targets": [
{
"key": "InstanceIds",
"values": [
"i-0123456789abcdef0"
]
}
]
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateAssociationStatus
#Description
Updates the status of the Amazon Web Services Systems Manager document (SSM document) associated with the specified managed node.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "2 validation errors detected: Value 'dw-probe' at 'instanceId' failed to satisfy constraint: Member must have length greater than or equal to 10; Value 'dw-probe' at 'instanceId' failed to satisfy constraint: Member must satisfy regular expression pattern: (^i-(\\w{8}|\\w{17})$)|(^mi-\\w{17}$)",
"eventCategory": "Management",
"eventID": "e766883b-d4bc-4df9-a2e4-be0082fe975e",
"eventName": "UpdateAssociationStatus",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T19:26:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "22be4e1b-426b-4f50-844d-38c300bf5471",
"requestParameters": {
"associationStatus": {
"date": "2020-01-01T00:00:00Z",
"message": "ddddd",
"name": "Pending"
},
"instanceId": "dw-probe",
"name": "arn:aws:iam::123456789012:role/dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateDocument
#Description
Updates one or more values for an SSM document.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidDocument",
"eventCategory": "Management",
"eventID": "548bb5fb-1b2a-4e48-b059-6c6b4b0b733c",
"eventName": "UpdateDocument",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T19:26:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "9a6e5fca-e6fe-4aac-ab23-d3ade71cb835",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateDocumentDefaultVersion
#Description
Set the default version of a document.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "9527638d-4bac-4482-a55d-cebf69abd257",
"eventName": "UpdateDocumentDefaultVersion",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T19:12:22Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "1c63fcce-60cb-468a-8f8e-dd9098419501",
"requestParameters": {
"documentVersion": "1",
"name": "dwfix-doc"
},
"responseElements": {
"description": {
"defaultVersion": "1",
"name": "dwfix-doc"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateDocumentMetadata
#Description
Amazon Web Services Systems Manager Change Manager is no longer open to new customers.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "InvalidDocument",
"errorMessage": "Document with name dw-probe does not exist.",
"eventCategory": "Management",
"eventID": "5e7f9604-850d-48bf-929f-a342000b95c3",
"eventName": "UpdateDocumentMetadata",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T19:26:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "04812531-5e69-49e1-a017-59cfeec59f9e",
"requestParameters": {
"documentReviews": {
"action": "SendForReview"
},
"name": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateMaintenanceWindow
#Description
Updates an existing maintenance window.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "1 validation error detected: Value at 'windowId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^mw-[0-9a-f]{17}$",
"eventCategory": "Management",
"eventID": "70bd3309-bce0-4003-8ec4-06d9b12f97ea",
"eventName": "UpdateMaintenanceWindow",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T19:26:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "e549ed4a-e274-4f08-a1b4-df338edd515b",
"requestParameters": {
"windowId": "dddddddddddddddddddd"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateMaintenanceWindowTarget
#Description
Modifies the target of an existing maintenance window.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "2 validation errors detected: Value at 'windowTargetId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[0-9a-fA-F]{8}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{12}$; Value at 'windowId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^mw-[0-9a-f]{17}$",
"eventCategory": "Management",
"eventID": "a4ee984c-0dd3-4468-8740-1d3efbea4415",
"eventName": "UpdateMaintenanceWindowTarget",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T19:26:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "8c4564f1-8297-419e-8a3e-8a6ac189182e",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateMaintenanceWindowTask
#Description
Modifies a task assigned to a maintenance window.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ValidationException",
"errorMessage": "2 validation errors detected: Value at 'windowTaskId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^[0-9a-fA-F]{8}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{4}\\-[0-9a-fA-F]{12}$; Value at 'windowId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^mw-[0-9a-f]{17}$",
"eventCategory": "Management",
"eventID": "00087560-fd52-4da0-ab11-bcaa618b8170",
"eventName": "UpdateMaintenanceWindowTask",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T19:26:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "192ac16d-8161-48a4-b4b2-ab8dbd562588",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateManagedInstanceRole
#Description
Changes the Identity and Access Management (IAM) role that is assigned to the on-premises server, edge device, or virtual machines (VM).
UpdateOpsItem
#Description
Edit or change an OpsItem.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "d5028510-6a4d-4b78-a452-34fc6b9900d8",
"eventName": "UpdateOpsItem",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T20:58:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "2a11e502-ab7c-42d6-8ab1-a2121844de6e",
"requestParameters": {
"description": "dwfix test ops item updated",
"opsItemId": "oi-e32d6871b32d",
"priority": 2,
"status": "InProgress",
"title": "dwfix-item-ea8e728b-updated"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b,n cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateOpsMetadata
#Description
Amazon Web Services Systems Manager calls this API operation when you edit OpsMetadata in Application Manager.
UpdatePatchBaseline
#Description
Modifies an existing patch baseline.
UpdateResourceDataSync
#Description
Update a resource data sync.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ResourceDataSyncInvalidConfigurationException",
"errorMessage": "Invalid Sync type.Values could be [SyncFromSource, SyncToDestination]",
"eventCategory": "Management",
"eventID": "7badd339-fe3f-44bd-b276-78b42d439fb5",
"eventName": "UpdateResourceDataSync",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T19:26:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "a7aae984-682d-47d7-af8f-06ed1bc1523c",
"requestParameters": {
"syncName": "ddddd",
"syncSource": {
"enableAllOpsDataSources": false,
"includeFutureRegions": false,
"sourceRegions": [
"ddddd"
],
"sourceType": "ddddd"
},
"syncType": "ddddd"
},
"resources": [
{
"ARN": "arn:aws:ssm:us-west-1:123456789012:resource-data-sync/ddddd",
"accountId": "123456789012"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateServiceSetting
#Description
ServiceSetting is an account-level setting for an Amazon Web Services service.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "e9fad6de-1013-49b5-91e0-a26a8f6325c3",
"eventName": "UpdateServiceSetting",
"eventSource": "ssm.amazonaws.com",
"eventTime": "2026-06-29T19:26:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "f294fde1-1451-434e-9063-88ded9635362",
"requestParameters": {
"settingId": "ddddd",
"settingValue": "ddddd"
},
"resources": [
{
"ARN": "arn:aws:ssm:us-west-1:123456789012:servicesetting/ddddd",
"accountId": "123456789012"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateDataChannel
#Description
CreateDataChannel recorded by CloudTrail for AWS Systems Manager. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "acb21d7e-ce79-4791-8351-7b39ba29ccb4",
"eventSource": "ssm.amazonaws.com",
"eventName": "CreateDataChannel",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "7b36a593-1d38-401d-a6e0-9c20eef28bff",
"userAgent": "Go-http-client/1.1",
"tlsDetails": {
"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
}
}
GetManifest
#Description
GetManifest recorded by CloudTrail for AWS Systems Manager. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "e5dd7b28-893f-4a06-88c6-97aa82c94757",
"eventSource": "ssm.amazonaws.com",
"eventName": "GetManifest",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "f67ea885-9be4-45d0-90c0-244ef40c790a",
"userAgent": "aws-sdk-go/1.55.5 (go1.25.11; linux; amd64) amazon-ssm-agent/3.3.4793.0",
"errorCode": "ResourceNotFoundException",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com"
}
}
ListInstanceAssociations
#Description
ListInstanceAssociations recorded by CloudTrail for AWS Systems Manager. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "28ae8683-6dc5-4727-8618-4033f801d967",
"eventSource": "ssm.amazonaws.com",
"eventName": "ListInstanceAssociations",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "8d0fdc95-308a-493c-88b4-2ff4494b4325",
"userAgent": "aws-sdk-go/1.55.5 (go1.25.11; linux; arm64) amazon-ssm-agent/3.3.4793.0",
"tlsDetails": {
"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com"
},
"resources": [
{
"accountId": "123456789012",
"ARN": "arn:aws:ec2:us-east-1:123456789012:instance/EXAMPLE"
}
]
}
ManagedInstanceConnectionLost
#Description
ManagedInstanceConnectionLost recorded by CloudTrail for AWS Systems Manager. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "7807cbce-0176-47a9-81bb-8b40145bb777",
"eventSource": "ssm.amazonaws.com",
"eventName": "ManagedInstanceConnectionLost",
"awsRegion": "us-east-1",
"eventType": "AwsServiceEvent",
"readOnly": false,
"managementEvent": true,
"userAgent": "ssm.amazonaws.com",
"resources": [
{
"accountId": "123456789012",
"type": "AWS::SSM::ManagedInstance",
"ARN": "arn:aws:ssm:us-east-1:123456789012:managed-instance/EXAMPLE"
}
]
}
OpenDataChannel
#Description
OpenDataChannel recorded by CloudTrail for AWS Systems Manager. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "a9cabdee-3bfd-4f0e-8cbd-dfd4aa328186",
"eventSource": "ssm.amazonaws.com",
"eventName": "OpenDataChannel",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "c00a8c89-0a85-4060-a5e8-06ef40971e3c",
"userAgent": "ssm.amazonaws.com"
}
PutConfigurePackageResult
#Description
PutConfigurePackageResult recorded by CloudTrail for AWS Systems Manager. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "eb38ed1b-2f60-44c3-8830-476f126d067e",
"eventSource": "ssm.amazonaws.com",
"eventName": "PutConfigurePackageResult",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "21a662a1-1f6f-40f8-8691-b975a00b5606",
"userAgent": "aws-sdk-go/1.55.5 (go1.25.11; linux; amd64) amazon-ssm-agent/3.3.4793.0",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com"
}
}
UpdateInstanceAssociationStatus
#Description
UpdateInstanceAssociationStatus recorded by CloudTrail for AWS Systems Manager. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "0a6c984f-4c3e-4088-be42-fdbdf7949f78",
"eventSource": "ssm.amazonaws.com",
"eventName": "UpdateInstanceAssociationStatus",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "1ea2ed77-d0c8-49f9-b277-407f6bc90c1d",
"userAgent": "aws-sdk-go/1.55.5 (go1.25.11 X:nodwarf5; linux; amd64) amazon-ssm-agent/3.3.4624.0",
"tlsDetails": {
"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com"
},
"resources": [
{
"accountId": "123456789012",
"ARN": "arn:aws:ssm:us-east-1:123456789012:association/EXAMPLE"
},
{
"accountId": "123456789012",
"ARN": "arn:aws:ec2:us-east-1:123456789012:instance/EXAMPLE"
}
]
}
UpdateInstanceInformation
#Description
UpdateInstanceInformation recorded by CloudTrail for AWS Systems Manager. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "f7a02705-b749-4158-988e-c28a1ce719a7",
"eventSource": "ssm.amazonaws.com",
"eventName": "UpdateInstanceInformation",
"awsRegion": "ca-central-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "ab1d152d-6e08-484e-83af-2cd8b6f7465b",
"userAgent": "aws-sdk-go/1.55.5 (go1.25.11; windows; amd64) exec-env/EC2 amazon-ssm-agent/3.3.4793.0",
"tlsDetails": {
"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ssm.ca-central-1.amazonaws.com"
}
}
CreateCloudConnector
#Description
Creates a cloud connector that establishes a connection between Systems Manager and a third-party cloud environment.
DeleteCloudConnector
#Description
Deletes a cloud connector.
GetCloudConnector
#Description
Returns detailed information about a cloud connector.
ListCloudConnectors
#Description
Returns a list of cloud connectors in the current Amazon Web Services account and Amazon Web Services Region.
UpdateCloudConnector
#Description
Updates an existing cloud connector with new configuration details.
ValidateCloudConnector
#Description
Validates the configuration and connectivity of a cloud connector.