Package-level declarations

Types

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard

Contains information on the current access control policies for the bucket.

Link copied to clipboard

An access denied exception object.

Link copied to clipboard
class AccessKey

Contains information about the access keys.

Link copied to clipboard

Contains information about the access keys.

Link copied to clipboard
class Account

Contains information about the account.

Link copied to clipboard

Contains information about the account.

Link copied to clipboard

Provides details of the GuardDuty member account that uses a free trial service.

Link copied to clipboard

Contains information about the account level permissions on the S3 bucket.

Link copied to clipboard

Represents a list of map of accounts with the number of findings associated with each account.

Link copied to clipboard
class Action

Contains information about actions.

Link copied to clipboard
class Actor

Information about the actors involved in an attack sequence.

Link copied to clipboard

Contains information about a process involved in a GuardDuty finding, including process identification, execution details, and file information.

Link copied to clipboard

Information about the installed EKS add-on (GuardDuty security agent).

Link copied to clipboard

The account within the organization specified as the GuardDuty delegated administrator.

Link copied to clipboard

Contains information about the administrator account and invitation.

Link copied to clipboard
sealed class AdminStatus
Link copied to clipboard

Information about the installed GuardDuty security agent.

Link copied to clipboard
class Anomaly

Contains information about the anomalies.

Link copied to clipboard

Contains information about the unusual anomalies.

Link copied to clipboard

Contains information about the behavior of the anomaly that is new to GuardDuty.

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
sealed class AutoEnableMembers
Link copied to clipboard

Contains information about the Autonomous System (AS) associated with the network endpoints involved in an attack sequence.

Link copied to clipboard

Contains information about the API action.

Link copied to clipboard

A bad request exception object.

Link copied to clipboard

Contains information on how the bucker owner's S3 Block Public Access settings are being applied to the S3 bucket. See S3 Block Public Access for more information.

Link copied to clipboard

Contains information about the bucket level permissions for the S3 bucket.

Link copied to clipboard

Contains information on the current bucket policies for the S3 bucket.

Link copied to clipboard
class City

Contains information about the city associated with the IP address.

Link copied to clipboard

Contains information on the status of CloudTrail as a data source for the detector.

Link copied to clipboard
sealed class ClusterStatus
Link copied to clipboard
class Condition

Contains information about the condition.

Link copied to clipboard

A request conflict exception object.

Link copied to clipboard
class Container

Details of a container.

Link copied to clipboard

Contains information about container resources involved in a GuardDuty finding. This structure provides details about containers that were identified as part of suspicious or malicious activity.

Link copied to clipboard

Contains information about the Amazon EC2 instance that is running the Amazon ECS container.

Link copied to clipboard
class Country

Contains information about the country where the remote IP address is located.

Link copied to clipboard

Contains information about the Amazon EC2 instance runtime coverage details.

Link copied to clipboard

Contains information about Amazon ECS cluster runtime coverage details.

Link copied to clipboard

Information about the EKS cluster that has a coverage status.

Link copied to clipboard

Represents a condition that when matched will be added to the response of the operation.

Link copied to clipboard

Represents the criteria used in the filter.

Link copied to clipboard

Represents a condition that when matched will be added to the response of the operation.

Link copied to clipboard
Link copied to clipboard

Information about the resource of the GuardDuty account.

Link copied to clipboard

Information about the resource for each individual EKS cluster.

Link copied to clipboard

Information about the sorting criteria used in the coverage statistics.

Link copied to clipboard
sealed class CoverageSortKey
Link copied to clipboard

Information about the coverage statistics for a resource.

Link copied to clipboard
Link copied to clipboard
sealed class CoverageStatus
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard

Information about the protected resource that is associated with the created Malware Protection plan. Presently, S3Bucket is the only supported protected resource.

Link copied to clipboard

Information about the protected S3 bucket resource.

Link copied to clipboard
sealed class CriterionKey
Link copied to clipboard
sealed class DataSource
Link copied to clipboard

Contains information about which data sources are enabled.

Link copied to clipboard

Contains information on the status of data sources for the detector.

Link copied to clipboard

Contains information about which data sources are enabled for the GuardDuty member account.

Link copied to clipboard

Contains information about which data sources are enabled for the GuardDuty member account.

Link copied to clipboard
sealed class DataSourceStatus
Link copied to clipboard

Represents list a map of dates with a count of total findings generated on each date.

Link copied to clipboard
Link copied to clipboard

Contains information on the server side encryption method used in the S3 bucket. See S3 Server-Side Encryption for more information.

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard

Contains information about the publishing destination, including the ID, type, and status.

Link copied to clipboard

Contains the Amazon Resource Name (ARN) of the resource to publish to, such as an S3 bucket, and the ARN of the KMS key to use to encrypt published findings.

Link copied to clipboard
sealed class DestinationType
Link copied to clipboard
class Detection

Contains information about the detected behavior.

Link copied to clipboard

Information about the additional configuration for a feature in your GuardDuty account.

Link copied to clipboard

Information about the additional configuration.

Link copied to clipboard
sealed class DetectorFeature
Link copied to clipboard

Contains information about a GuardDuty feature.

Link copied to clipboard

Contains information about a GuardDuty feature.

Link copied to clipboard
Link copied to clipboard
sealed class DetectorStatus
Link copied to clipboard

Contains information on the status of DNS logs as a data source.

Link copied to clipboard

Contains information about the DNS_REQUEST action described in this finding.

Link copied to clipboard

Contains information about the domain.

Link copied to clipboard
Link copied to clipboard

Contains list of scanned and skipped EBS volumes with details.

Link copied to clipboard

Contains details from the malware scan that created a finding.

Link copied to clipboard

Describes the configuration of scanning EBS volumes as a data source.

Link copied to clipboard

Details about the potentially impacted Amazon EC2 instance resource.

Link copied to clipboard

Contains information about the elastic network interface of the Amazon EC2 instance.

Link copied to clipboard

Contains information about the details of the ECS Cluster.

Link copied to clipboard

Contains information about the task in an ECS cluster.

Link copied to clipboard

Contains information about the Amazon EKS cluster involved in a GuardDuty finding, including cluster identification, status, and network configuration.

Link copied to clipboard

Details about the EKS cluster involved in a Kubernetes finding.

Link copied to clipboard
class Evidence

Contains information about the reason that the finding was generated.

Link copied to clipboard

Contains information about Amazon Web Services Fargate details associated with an Amazon ECS cluster.

Link copied to clipboard
Link copied to clipboard
sealed class FeatureStatus
Link copied to clipboard
sealed class Feedback
Link copied to clipboard
sealed class FilterAction
Link copied to clipboard

Contains information about the condition.

Link copied to clipboard

Represents the criteria to be used in the filter for describing scan entries.

Link copied to clipboard

Represents a condition that when matched will be added to the response of the operation. Irrespective of using any filter criteria, an administrator account can view the scan entries for all of its member accounts. However, each member account can view the scan entries only for their own account.

Link copied to clipboard
class Finding

Contains information about the finding that is generated when abnormal or suspicious activity is detected.

Link copied to clipboard

Contains information about the criteria used for querying findings.

Link copied to clipboard
Link copied to clipboard
sealed class FindingResourceType
Link copied to clipboard

Contains information about finding statistics.

Link copied to clipboard
Link copied to clipboard

Information about each finding type associated with the groupedByFindingType statistics.

Link copied to clipboard

Contains information on the status of VPC flow logs as a data source.

Link copied to clipboard

Contains information about the free trial period for a feature.

Link copied to clipboard
Link copied to clipboard

Contains information about the location of the remote IP address. By default, GuardDuty returns Geolocation with Lat and Lon as 0.0.

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
sealed class GroupByType
Link copied to clipboard

Base class for all service related exceptions thrown by the GuardDuty client

Link copied to clipboard

Contains details of the highest severity threat detected during scan and number of infected files.

Link copied to clipboard
class HostPath

Represents a pre-existing file or directory on the host machine that the volume maps to.

Link copied to clipboard

Contains information about the EC2 instance profile.

Link copied to clipboard

Contains information about the impersonated user.

Link copied to clipboard
class Indicator

Contains information about the indicators that include a set of signals observed in an attack sequence.

Link copied to clipboard
sealed class IndicatorType
Link copied to clipboard

Contains information about the details of an instance.

Link copied to clipboard

An internal server error exception object.

Link copied to clipboard

Contains information about the invitation to become a member account.

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
sealed class IpSetFormat
Link copied to clipboard
sealed class IpSetStatus
Link copied to clipboard
class ItemPath

Information about the nested item path and hash of the protected resource.

Link copied to clipboard

Information about the Kubernetes API call action described in this finding.

Link copied to clipboard

Describes whether Kubernetes audit logs are enabled as a data source.

Link copied to clipboard

Describes whether Kubernetes audit logs are enabled as a data source.

Link copied to clipboard

Describes whether any Kubernetes data sources are enabled.

Link copied to clipboard

Describes whether any Kubernetes logs will be enabled as a data source.

Link copied to clipboard

Provides details about the Kubernetes resources when it is enabled as a data source.

Link copied to clipboard

Details about Kubernetes resources such as a Kubernetes user or workload resource involved in a Kubernetes finding.

Link copied to clipboard

Information about the Kubernetes API for which you check if you have permission to call.

Link copied to clipboard
Link copied to clipboard

Contains information about the role binding that grants the permission defined in a Kubernetes role.

Link copied to clipboard

Information about the Kubernetes role name and role type.

Link copied to clipboard

Details about the Kubernetes user involved in a Kubernetes finding.

Link copied to clipboard

Contains information about Kubernetes workloads involved in a GuardDuty finding, including pods, deployments, and other Kubernetes resources.

Link copied to clipboard

Details about the Kubernetes workload involved in a Kubernetes finding.

Link copied to clipboard

Information about the Lambda function involved in the finding.

Link copied to clipboard

Information about the runtime process details.

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard

Contains information about the local IP address of the connection.

Link copied to clipboard

Contains information about the port for the local connection.

Link copied to clipboard

Information about the login attempts.

Link copied to clipboard

Describes whether Malware Protection will be enabled as a data source.

Link copied to clipboard

An object that contains information on the status of all Malware Protection data sources.

Link copied to clipboard

Provides details about Malware Protection when it is enabled as a data source.

Link copied to clipboard

Information about whether the tags will be added to the S3 object after scanning.

Link copied to clipboard
Link copied to clipboard

Information about the issue code and message associated to the status of your Malware Protection plan.

Link copied to clipboard

Information about the Malware Protection plan resource.

Link copied to clipboard

Information about adding tags to the scanned S3 object after the scan result.

Link copied to clipboard

Information about the malware scan that generated a GuardDuty finding.

Link copied to clipboard
sealed class ManagementType
Link copied to clipboard
class Master

Contains information about the administrator account and invitation.

Link copied to clipboard
class Member

Contains information about the member account.

Link copied to clipboard

Information about the additional configuration for the member account.

Link copied to clipboard

Information about the additional configuration for the member account.

Link copied to clipboard

Contains information on which data sources are enabled for a member account.

Link copied to clipboard

Contains information about the features for the member account.

Link copied to clipboard

Contains information about the features for the member account.

Link copied to clipboard
sealed class MfaStatus
Link copied to clipboard

Contains information about the network connection.

Link copied to clipboard

Contains information about the NETWORK_CONNECTION action described in the finding.

Link copied to clipboard
sealed class NetworkDirection
Link copied to clipboard

Contains information about network endpoints that were observed in the attack sequence.

Link copied to clipboard

Contains information about network endpoint location.

Link copied to clipboard

Contains information about the elastic network interface of the EC2 instance.

Link copied to clipboard

Contains information about the observed behavior.

Link copied to clipboard
sealed class OrderBy
Link copied to clipboard

Contains information about the ISP organization of the remote IP address.

Link copied to clipboard

A list of additional configurations which will be configured for the organization.

A list of additional configuration which will be configured for the organization.

Link copied to clipboard

An object that contains information on which data sources will be configured to be automatically enabled for new members within the organization.

An object that contains information on which data sources are automatically enabled for new members within the organization.

Link copied to clipboard

Information about GuardDuty coverage statistics for members in your Amazon Web Services organization.

Link copied to clipboard

Organization-wide EBS volumes scan configuration.

Link copied to clipboard

An object that contains information on the status of whether EBS volumes scanning will be enabled as a data source for an organization.

Link copied to clipboard

A list of features which will be configured for the organization.

Link copied to clipboard

A list of features which will be configured for the organization.

Link copied to clipboard

Information about the number of accounts that have enabled a specific feature.

Information about the coverage statistic for the additional configuration of the feature.

Organization-wide Kubernetes audit logs configuration.

The current configuration of Kubernetes audit logs as a data source for the organization.

Link copied to clipboard

Organization-wide Kubernetes data sources configurations.

The current configuration of all Kubernetes data sources for the organization.

Organization-wide Malware Protection configurations.

An object that contains information on the status of all Malware Protection data source for an organization.

Link copied to clipboard

Describes whether S3 data event logs will be automatically enabled for new members of the organization.

Link copied to clipboard

The current configuration of S3 data event logs as a data source for the organization.

Link copied to clipboard

Organization-wide EC2 instances with findings scan configuration.

An object that contains information on the status of scanning EC2 instances with findings for an organization.

Link copied to clipboard

Information about the coverage statistics of the features for the entire Amazon Web Services organization.

Link copied to clipboard
sealed class OrgFeature
Link copied to clipboard
sealed class OrgFeatureStatus
Link copied to clipboard
class Owner

Contains information on the owner of the bucket.

Link copied to clipboard

Contains information about how permissions are configured for the S3 bucket.

Link copied to clipboard

Contains information about the PORT_PROBE action described in the finding.

Link copied to clipboard

Contains information about the port probe details.

Link copied to clipboard

Contains other private IP address information of the EC2 instance.

Link copied to clipboard

Information about the observed process.

Link copied to clipboard

Contains information about the product code for the EC2 instance.

Link copied to clipboard
sealed class ProfileSubtype
Link copied to clipboard
sealed class ProfileType
Link copied to clipboard

Describes the public access policies that apply to the S3 bucket.

Link copied to clipboard

Describes public access policies that apply to the Amazon S3 bucket.

Link copied to clipboard
sealed class PublicAccessStatus
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
sealed class PublishingStatus
Link copied to clipboard

Contains information about the resource type RDSDBInstance involved in a GuardDuty finding.

Link copied to clipboard

Contains information about the user and authentication details for a database instance involved in the finding.

Link copied to clipboard

Contains information about the resource type RDSLimitlessDB that is involved in a GuardDuty finding.

Link copied to clipboard

Indicates that a login attempt was made to the potentially compromised database from a remote IP address.

Link copied to clipboard

Contains details about the remote Amazon Web Services account that made the API call.

Link copied to clipboard

Contains information about the remote IP address of the connection.

Link copied to clipboard

Contains information about the remote port.

Link copied to clipboard
class Resource

Contains information about the Amazon Web Services resource associated with the activity that prompted GuardDuty to generate a finding.

Link copied to clipboard

Contains information about the Amazon Web Services resource that is associated with the activity that prompted GuardDuty to generate a finding.

Link copied to clipboard

Represents the resources that were scanned in the scan entry.

Link copied to clipboard

The requested resource can't be found.

Link copied to clipboard

Information about each resource type associated with the groupedByResource statistics.

Link copied to clipboard
sealed class ResourceType
Link copied to clipboard

Contains information about the Amazon Web Services resource that is associated with the GuardDuty finding.

Link copied to clipboard

Additional information about the suspicious activity.

Link copied to clipboard

Information about the process and any required context values for a specific finding.

Link copied to clipboard
class S3Bucket

Contains information about the Amazon S3 bucket policies and encryption.

Link copied to clipboard

Contains information on the S3 bucket.

Link copied to clipboard

Describes whether S3 data event logs will be enabled as a data source.

Link copied to clipboard

Describes whether S3 data event logs will be enabled as a data source.

Link copied to clipboard
class S3Object

Contains information about the Amazon S3 object.

Link copied to clipboard

Information about the S3 object that was scanned

Link copied to clipboard
class Scan

Contains information about malware scans associated with GuardDuty Malware Protection for EC2.

Link copied to clipboard

Contains information about the condition.

Link copied to clipboard

Represents the key:value pair to be matched against given resource property.

Link copied to clipboard
sealed class ScanCriterionKey

An enum value representing possible resource properties to match with given scan condition.

Link copied to clipboard

Contains a complete view providing malware scan result details.

Link copied to clipboard

Describes whether Malware Protection for EC2 instances with findings will be enabled as a data source.

Link copied to clipboard

An object that contains information on the status of whether Malware Protection for EC2 instances with findings will be enabled as a data source.

Link copied to clipboard

Contains details of infected file including name, file path and hash.

Link copied to clipboard

Total number of scanned files.

Link copied to clipboard

Contains information about criteria used to filter resources before triggering malware scan.

Link copied to clipboard
sealed class ScanResult
Link copied to clipboard

Represents the result of the scan.

Link copied to clipboard
sealed class ScanStatus
Link copied to clipboard

Contains files infected with the given threat providing details of malware name and severity.

Link copied to clipboard
sealed class ScanType
Link copied to clipboard

Container security context.

Link copied to clipboard

Contains information about the security groups associated with the EC2 instance.

Link copied to clipboard
class Sequence

Contains information about the GuardDuty attack sequence finding.

Link copied to clipboard
class Service

Contains additional information about the generated finding.

Link copied to clipboard

Additional information about the generated finding.

Link copied to clipboard
class Session

Contains information about the authenticated session.

Link copied to clipboard

Information about severity level for each finding type.

Link copied to clipboard
class Signal

Contains information about the signals involved in the attack sequence.

Link copied to clipboard
sealed class SignalType
Link copied to clipboard

Contains information about the criteria used for sorting findings.

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
class Tag

Contains information about a tag key-value pair.

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
class Threat

Information about the detected threats associated with the generated finding.

Link copied to clipboard

Contains details about identified threats organized by threat name.

Link copied to clipboard

An instance of a threat intelligence detail that constitutes evidence for the finding.

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard

Contains total number of infected files.

Link copied to clipboard
class Total

Contains the total usage with the corresponding currency unit for that value.

Link copied to clipboard

Represents the reason the scan was triggered.

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard

Contains information about the accounts that weren't processed.

Link copied to clipboard

Specifies the names of the data sources that couldn't be enabled.

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard

Information about the protected resource that is associated with the created Malware Protection plan. Presently, S3Bucket is the only supported protected resource.

Link copied to clipboard

Information about the protected S3 bucket resource.

Link copied to clipboard

Contains information on the total of usage based on account IDs.

Link copied to clipboard

Contains information about the criteria used to query usage statistics.

Link copied to clipboard

Contains information on the result of usage based on data source type.

Link copied to clipboard
sealed class UsageFeature
Link copied to clipboard

Contains information about the result of the total usage based on the feature.

Link copied to clipboard

Contains information on the sum of usage based on an Amazon Web Services resource.

Link copied to clipboard

Contains the result of GuardDuty usage. If a UsageStatisticType is provided the result for other types will be null.

Link copied to clipboard
sealed class UsageStatisticType
Link copied to clipboard

Contains information on the total of usage based on the topmost 50 account IDs.

Link copied to clipboard

Information about the usage statistics, calculated by top accounts by feature.

Link copied to clipboard
class User

Contains information about the user involved in the attack sequence.

Link copied to clipboard
class Volume

Volume used by the Kubernetes workload.

Link copied to clipboard

Contains EBS volume details.

Link copied to clipboard

Container volume mount.

Link copied to clipboard
class VpcConfig

Amazon Virtual Private Cloud configuration details associated with your Lambda function.