AWS Security Hub
API Reference
API Version 2018-10-26
AWS Security Hub: API Reference
Copyright © Amazon Web Services, Inc. and/or its affiliates. All rights reserved.
Amazon's trademarks and trade dress may not be used in connection with any product or service that is not Amazon's, in any manner that is likely to cause confusion among customers, or in any manner that disparages or discredits Amazon. All other trademarks not owned by Amazon are the property of their respective owners, who may or may not be affiliated with, connected to, or sponsored by Amazon.
Table of Contents
Welcome ... 1
Actions ... 2
AcceptAdministratorInvitation ... 4
Request Syntax ... 4
URI Request Parameters ... 4
Request Body ... 4
Response Syntax ... 4
Response Elements ... 4
Errors ... 5
See Also ... 5
AcceptInvitation ... 6
Request Syntax ... 6
URI Request Parameters ... 6
Request Body ... 6
Response Syntax ... 7
Response Elements ... 7
Errors ... 7
See Also ... 7
BatchDisableStandards ... 9
Request Syntax ... 9
URI Request Parameters ... 9
Request Body ... 9
Response Syntax ... 9
Response Elements ... 10
Errors ... 10
See Also ... 10
BatchEnableStandards ... 12
Request Syntax ... 12
URI Request Parameters ... 12
Request Body ... 12
Response Syntax ... 12
Response Elements ... 13
Errors ... 13
See Also ... 13
BatchImportFindings ... 15
Request Syntax ... 15
URI Request Parameters ... 59
Request Body ... 59
Response Syntax ... 59
Response Elements ... 59
Errors ... 60
See Also ... 60
BatchUpdateFindings ... 61
Request Syntax ... 61
URI Request Parameters ... 62
Request Body ... 62
Response Syntax ... 64
Response Elements ... 64
Errors ... 64
See Also ... 65
CreateActionTarget ... 66
Request Syntax ... 66
URI Request Parameters ... 66
Request Body ... 66
Response Syntax ... 66
Response Elements ... 67
Errors ... 67
See Also ... 67
CreateFindingAggregator ... 69
Request Syntax ... 69
URI Request Parameters ... 69
Request Body ... 69
Response Syntax ... 70
Response Elements ... 70
Errors ... 71
See Also ... 71
CreateInsight ... 72
Request Syntax ... 72
URI Request Parameters ... 81
Request Body ... 81
Response Syntax ... 82
Response Elements ... 82
Errors ... 82
See Also ... 83
CreateMembers ... 84
Request Syntax ... 84
URI Request Parameters ... 84
Request Body ... 85
Response Syntax ... 85
Response Elements ... 85
Errors ... 85
See Also ... 86
DeclineInvitations ... 87
Request Syntax ... 87
URI Request Parameters ... 87
Request Body ... 87
Response Syntax ... 87
Response Elements ... 87
Errors ... 88
See Also ... 88
DeleteActionTarget ... 89
Request Syntax ... 89
URI Request Parameters ... 89
Request Body ... 89
Response Syntax ... 89
Response Elements ... 89
Errors ... 89
See Also ... 90
DeleteFindingAggregator ... 91
Request Syntax ... 91
URI Request Parameters ... 91
Request Body ... 91
Response Syntax ... 91
Response Elements ... 91
Errors ... 91
See Also ... 92
DeleteInsight ... 93
Request Syntax ... 93
URI Request Parameters ... 93
Request Body ... 93
Response Syntax ... 93
Response Elements ... 93
Errors ... 93
See Also ... 94
DeleteInvitations ... 95
Request Syntax ... 95
URI Request Parameters ... 95
Request Body ... 95
Response Syntax ... 95
Response Elements ... 95
Errors ... 96
See Also ... 96
DeleteMembers ... 98
Request Syntax ... 98
URI Request Parameters ... 98
Request Body ... 98
Response Syntax ... 98
Response Elements ... 98
Errors ... 99
See Also ... 99
DescribeActionTargets ... 101
Request Syntax ... 101
URI Request Parameters ... 101
Request Body ... 101
Response Syntax ... 101
Response Elements ... 102
Errors ... 102
See Also ... 103
DescribeHub ... 104
Request Syntax ... 104
URI Request Parameters ... 104
Request Body ... 104
Response Syntax ... 104
Response Elements ... 104
Errors ... 105
See Also ... 105
DescribeOrganizationConfiguration ... 107
Request Syntax ... 107
URI Request Parameters ... 107
Request Body ... 107
Response Syntax ... 107
Response Elements ... 107
Errors ... 107
See Also ... 108
DescribeProducts ... 109
Request Syntax ... 109
URI Request Parameters ... 109
Request Body ... 109
Response Syntax ... 109
Response Elements ... 110
Errors ... 110
See Also ... 110
DescribeStandards ... 112
Request Syntax ... 112
URI Request Parameters ... 112
Request Body ... 112
Response Syntax ... 112
Response Elements ... 112
Errors ... 113
See Also ... 113
DescribeStandardsControls ... 114
Request Syntax ... 114
URI Request Parameters ... 114
Request Body ... 114
Response Syntax ... 114
Response Elements ... 115
Errors ... 115
See Also ... 115
DisableImportFindingsForProduct ... 117
Request Syntax ... 117
URI Request Parameters ... 117
Request Body ... 117
Response Syntax ... 117
Response Elements ... 117
Errors ... 117
See Also ... 118
DisableOrganizationAdminAccount ... 119
Request Syntax ... 119
URI Request Parameters ... 119
Request Body ... 119
Response Syntax ... 119
Response Elements ... 119
Errors ... 119
See Also ... 120
DisableSecurityHub ... 121
Request Syntax ... 121
URI Request Parameters ... 121
Request Body ... 121
Response Syntax ... 121
Response Elements ... 121
Errors ... 121
See Also ... 122
DisassociateFromAdministratorAccount ... 123
Request Syntax ... 123
URI Request Parameters ... 123
Request Body ... 123
Response Syntax ... 123
Response Elements ... 123
Errors ... 123
See Also ... 124
DisassociateFromMasterAccount ... 125
Request Syntax ... 125
URI Request Parameters ... 125
Request Body ... 125
Response Syntax ... 125
Response Elements ... 125
Errors ... 125
See Also ... 126
DisassociateMembers ... 127
Request Syntax ... 127
URI Request Parameters ... 127
Request Body ... 127
Response Syntax ... 127
Response Elements ... 127
Errors ... 127
See Also ... 128
EnableImportFindingsForProduct ... 129
Request Syntax ... 129
URI Request Parameters ... 129
Request Body ... 129
Response Syntax ... 129
Response Elements ... 129
Errors ... 130
See Also ... 130
EnableOrganizationAdminAccount ... 131
Request Syntax ... 131
URI Request Parameters ... 131
Request Body ... 131
Response Syntax ... 131
Response Elements ... 131
Errors ... 131
See Also ... 132
EnableSecurityHub ... 133
Request Syntax ... 133
URI Request Parameters ... 133
Request Body ... 133
Response Syntax ... 134
Response Elements ... 134
Errors ... 134
See Also ... 134
GetAdministratorAccount ... 136
Request Syntax ... 136
URI Request Parameters ... 136
Request Body ... 136
Response Syntax ... 136
Response Elements ... 136
Errors ... 136
See Also ... 137
GetEnabledStandards ... 138
Request Syntax ... 138
URI Request Parameters ... 138
Request Body ... 138
Response Syntax ... 139
Response Elements ... 139
Errors ... 139
See Also ... 140
GetFindingAggregator ... 141
Request Syntax ... 141
URI Request Parameters ... 141
Request Body ... 141
Response Syntax ... 141
Response Elements ... 141
Errors ... 142
See Also ... 143
GetFindings ... 144
Request Syntax ... 144
URI Request Parameters ... 153
Request Body ... 153
Response Syntax ... 154
Response Elements ... 198
Errors ... 198
See Also ... 199
GetInsightResults ... 200
Request Syntax ... 200
URI Request Parameters ... 200
Request Body ... 200
Response Syntax ... 200
Response Elements ... 200
Errors ... 201
See Also ... 201
GetInsights ... 202
Request Syntax ... 202
URI Request Parameters ... 202
Request Body ... 202
Response Syntax ... 202
Response Elements ... 212
Errors ... 212
See Also ... 213
GetInvitationsCount ... 214
Request Syntax ... 214
URI Request Parameters ... 214
Request Body ... 214
Response Syntax ... 214
Response Elements ... 214
Errors ... 214
See Also ... 215
GetMasterAccount ... 216
Request Syntax ... 216
URI Request Parameters ... 216
Request Body ... 216
Response Syntax ... 216
Response Elements ... 216
Errors ... 217
See Also ... 217
GetMembers ... 218
Request Syntax ... 218
URI Request Parameters ... 218
Request Body ... 218
Response Syntax ... 218
Response Elements ... 219
Errors ... 219
See Also ... 220
InviteMembers ... 221
Request Syntax ... 221
URI Request Parameters ... 221
Request Body ... 221
Response Syntax ... 221
Response Elements ... 222
Errors ... 222
See Also ... 222
ListEnabledProductsForImport ... 224
Request Syntax ... 224
URI Request Parameters ... 224
Request Body ... 224
Response Syntax ... 224
Response Elements ... 224
Errors ... 225
See Also ... 225
ListFindingAggregators ... 226
Request Syntax ... 226
URI Request Parameters ... 226
Request Body ... 226
Response Syntax ... 226
Response Elements ... 226
Errors ... 227
See Also ... 227
ListInvitations ... 228
Request Syntax ... 228
URI Request Parameters ... 228
Request Body ... 228
Response Syntax ... 228
Response Elements ... 228
Errors ... 229
See Also ... 229
ListMembers ... 231
Request Syntax ... 231
URI Request Parameters ... 231
Request Body ... 231
Response Syntax ... 231
Response Elements ... 232
Errors ... 232
See Also ... 232
ListOrganizationAdminAccounts ... 234
Request Syntax ... 234
URI Request Parameters ... 234
Request Body ... 234
Response Syntax ... 234
Response Elements ... 234
Errors ... 235
See Also ... 235
ListTagsForResource ... 236
Request Syntax ... 236
URI Request Parameters ... 236
Request Body ... 236
Response Syntax ... 236
Response Elements ... 236
Errors ... 237
See Also ... 237
TagResource ... 238
Request Syntax ... 238
URI Request Parameters ... 238
Request Body ... 238
Response Syntax ... 238
Response Elements ... 239
Errors ... 239
See Also ... 239
UntagResource ... 240
Request Syntax ... 240
URI Request Parameters ... 240
Request Body ... 240
Response Syntax ... 240
Response Elements ... 240
Errors ... 240
See Also ... 241
UpdateActionTarget ... 242
Request Syntax ... 242
URI Request Parameters ... 242
Request Body ... 242
Response Syntax ... 242
Response Elements ... 243
Errors ... 243
See Also ... 243
UpdateFindingAggregator ... 244
Request Syntax ... 244
URI Request Parameters ... 244
Request Body ... 244
Response Syntax ... 245
Response Elements ... 245
Errors ... 246
See Also ... 246
UpdateFindings ... 248
Request Syntax ... 248
URI Request Parameters ... 257
Request Body ... 257
Response Syntax ... 258
Response Elements ... 258
Errors ... 258
See Also ... 259
UpdateInsight ... 260
Request Syntax ... 260
URI Request Parameters ... 269
Request Body ... 269
Response Syntax ... 270
Response Elements ... 270
Errors ... 270
See Also ... 271
UpdateOrganizationConfiguration ... 272
Request Syntax ... 272
URI Request Parameters ... 272
Request Body ... 272
Response Syntax ... 272
Response Elements ... 272
Errors ... 272
See Also ... 273
UpdateSecurityHubConfiguration ... 274
Request Syntax ... 274
URI Request Parameters ... 274
Request Body ... 274
Response Syntax ... 274
Response Elements ... 274
Errors ... 274
See Also ... 275
UpdateStandardsControl ... 276
Request Syntax ... 276
URI Request Parameters ... 276
Request Body ... 276
Response Syntax ... 276
Response Elements ... 277
Errors ... 277
See Also ... 277
Data Types ... 278
AccountDetails ... 288
Contents ... 288
See Also ... 288
Action ... 289
Contents ... 289
See Also ... 290
ActionLocalIpDetails ... 291
Contents ... 291
See Also ... 291
ActionLocalPortDetails ... 292
Contents ... 292
See Also ... 292
ActionRemoteIpDetails ... 293
Contents ... 293
See Also ... 293
ActionRemotePortDetails ... 294
Contents ... 294
See Also ... 294
ActionTarget ... 295
Contents ... 295
See Also ... 295
Adjustment ... 296
Contents ... 296
See Also ... 296
AdminAccount ... 297
Contents ... 297
See Also ... 297
AvailabilityZone ... 298
Contents ... 298
See Also ... 298
AwsApiCallAction ... 299
Contents ... 299
See Also ... 300
AwsApiCallActionDomainDetails ... 301
Contents ... 301
See Also ... 301
AwsApiGatewayAccessLogSettings ... 302
Contents ... 302
See Also ... 302
AwsApiGatewayCanarySettings ... 303
Contents ... 303
See Also ... 303
AwsApiGatewayEndpointConfiguration ... 304
Contents ... 304
See Also ... 304
AwsApiGatewayMethodSettings ... 305
Contents ... 305
See Also ... 307
AwsApiGatewayRestApiDetails ... 308
Contents ... 308
See Also ... 309
AwsApiGatewayStageDetails ... 310
Contents ... 310
See Also ... 312
AwsApiGatewayV2ApiDetails ... 313
Contents ... 313
See Also ... 314
AwsApiGatewayV2RouteSettings ... 316
Contents ... 316
See Also ... 316
AwsApiGatewayV2StageDetails ... 318
Contents ... 318
See Also ... 320
AwsAutoScalingAutoScalingGroupAvailabilityZonesListDetails ... 321
Contents ... 321
See Also ... 321
AwsAutoScalingAutoScalingGroupDetails ... 322
Contents ... 322
See Also ... 323
AwsAutoScalingAutoScalingGroupMixedInstancesPolicyDetails ... 324
Contents ... 324
See Also ... 324
AwsAutoScalingAutoScalingGroupMixedInstancesPolicyInstancesDistributionDetails ... 325
Contents ... 325
See Also ... 326
AwsAutoScalingAutoScalingGroupMixedInstancesPolicyLaunchTemplateDetails ... 327
Contents ... 327
See Also ... 327
AwsAutoScalingAutoScalingGroupMixedInstancesPolicyLaunchTemplateLaunchTemplateSpecification 328 Contents ... 328
See Also ... 328
AwsAutoScalingAutoScalingGroupMixedInstancesPolicyLaunchTemplateOverridesListDetails ... 329
Contents ... 329
See Also ... 329
AwsAutoScalingLaunchConfigurationBlockDeviceMappingsDetails ... 330
Contents ... 330
See Also ... 330
AwsAutoScalingLaunchConfigurationBlockDeviceMappingsEbsDetails ... 331
Contents ... 331
See Also ... 332
AwsAutoScalingLaunchConfigurationDetails ... 333
Contents ... 333
See Also ... 335
AwsAutoScalingLaunchConfigurationInstanceMonitoringDetails ... 337
Contents ... 337
See Also ... 337
AwsAutoScalingLaunchConfigurationMetadataOptions ... 338
Contents ... 338
See Also ... 338
AwsCertificateManagerCertificateDetails ... 339
Contents ... 339
See Also ... 343
AwsCertificateManagerCertificateDomainValidationOption ... 344
Contents ... 344
See Also ... 345
AwsCertificateManagerCertificateExtendedKeyUsage ... 346
Contents ... 346
See Also ... 346
AwsCertificateManagerCertificateKeyUsage ... 347
Contents ... 347
See Also ... 347
AwsCertificateManagerCertificateOptions ... 348
Contents ... 348
See Also ... 348
AwsCertificateManagerCertificateRenewalSummary ... 349
Contents ... 349
See Also ... 349
AwsCertificateManagerCertificateResourceRecord ... 351
Contents ... 351
See Also ... 351
AwsCloudFrontDistributionCacheBehavior ... 352
Contents ... 352
See Also ... 352
AwsCloudFrontDistributionCacheBehaviors ... 353
Contents ... 353
See Also ... 353
AwsCloudFrontDistributionDefaultCacheBehavior ... 354
Contents ... 354
See Also ... 354
AwsCloudFrontDistributionDetails ... 355
Contents ... 355
See Also ... 356
AwsCloudFrontDistributionLogging ... 358
Contents ... 358
See Also ... 358
AwsCloudFrontDistributionOriginGroup ... 359
Contents ... 359
See Also ... 359
AwsCloudFrontDistributionOriginGroupFailover ... 360
Contents ... 360
See Also ... 360
AwsCloudFrontDistributionOriginGroupFailoverStatusCodes ... 361
Contents ... 361
See Also ... 361
AwsCloudFrontDistributionOriginGroups ... 362
Contents ... 362
See Also ... 362
AwsCloudFrontDistributionOriginItem ... 363
Contents ... 363
See Also ... 363
AwsCloudFrontDistributionOrigins ... 364
Contents ... 364
See Also ... 364
AwsCloudFrontDistributionOriginS3OriginConfig ... 365
Contents ... 365
See Also ... 365
AwsCloudFrontDistributionViewerCertificate ... 366
Contents ... 366
See Also ... 367
AwsCloudTrailTrailDetails ... 368
Contents ... 368
See Also ... 370
AwsCodeBuildProjectArtifactsDetails ... 371
Contents ... 371
See Also ... 372
AwsCodeBuildProjectDetails ... 373
Contents ... 373
See Also ... 374
AwsCodeBuildProjectEnvironment ... 375
Contents ... 375
See Also ... 376
AwsCodeBuildProjectEnvironmentEnvironmentVariablesDetails ... 377
Contents ... 377
See Also ... 377
AwsCodeBuildProjectEnvironmentRegistryCredential ... 378
Contents ... 378
See Also ... 378
AwsCodeBuildProjectLogsConfigCloudWatchLogsDetails ... 379
Contents ... 379
See Also ... 379
AwsCodeBuildProjectLogsConfigDetails ... 380
Contents ... 380
See Also ... 380
AwsCodeBuildProjectLogsConfigS3LogsDetails ... 381
Contents ... 381
See Also ... 381
AwsCodeBuildProjectSource ... 382
Contents ... 382
See Also ... 383
AwsCodeBuildProjectVpcConfig ... 384
Contents ... 384
See Also ... 384
AwsCorsConfiguration ... 385
Contents ... 385
See Also ... 386
AwsDynamoDbTableAttributeDefinition ... 387
Contents ... 387
See Also ... 387
AwsDynamoDbTableBillingModeSummary ... 388
Contents ... 388
See Also ... 388
AwsDynamoDbTableDetails ... 389
Contents ... 389
See Also ... 391
AwsDynamoDbTableGlobalSecondaryIndex ... 392
Contents ... 392
See Also ... 393
AwsDynamoDbTableKeySchema ... 394
Contents ... 394
See Also ... 394
AwsDynamoDbTableLocalSecondaryIndex ... 395
Contents ... 395
See Also ... 395
AwsDynamoDbTableProjection ... 396
Contents ... 396
See Also ... 396
AwsDynamoDbTableProvisionedThroughput ... 397
Contents ... 397
See Also ... 397
AwsDynamoDbTableProvisionedThroughputOverride ... 399
Contents ... 399
See Also ... 399
AwsDynamoDbTableReplica ... 400
Contents ... 400
See Also ... 401
AwsDynamoDbTableReplicaGlobalSecondaryIndex ... 402
Contents ... 402
See Also ... 402
AwsDynamoDbTableRestoreSummary ... 403
Contents ... 403
See Also ... 403
AwsDynamoDbTableSseDescription ... 404
Contents ... 404
See Also ... 404
AwsDynamoDbTableStreamSpecification ... 405
Contents ... 405
See Also ... 405
AwsEc2EipDetails ... 406
Contents ... 406
See Also ... 407
AwsEc2InstanceDetails ... 408
Contents ... 408
See Also ... 409
AwsEc2InstanceNetworkInterfacesDetails ... 410
Contents ... 410
See Also ... 410
AwsEc2NetworkAclAssociation ... 411
Contents ... 411
See Also ... 411
AwsEc2NetworkAclDetails ... 412
Contents ... 412
See Also ... 412
AwsEc2NetworkAclEntry ... 414
Contents ... 414
See Also ... 415
AwsEc2NetworkInterfaceAttachment ... 416
Contents ... 416
See Also ... 417
AwsEc2NetworkInterfaceDetails ... 418
Contents ... 418
See Also ... 419
AwsEc2NetworkInterfaceIpV6AddressDetail ... 420
Contents ... 420
See Also ... 420
AwsEc2NetworkInterfacePrivateIpAddressDetail ... 421
Contents ... 421
See Also ... 421
AwsEc2NetworkInterfaceSecurityGroup ... 422
Contents ... 422
See Also ... 422
AwsEc2SecurityGroupDetails ... 423
Contents ... 423
See Also ... 424
AwsEc2SecurityGroupIpPermission ... 425
Contents ... 425
See Also ... 426
AwsEc2SecurityGroupIpRange ... 427
Contents ... 427
See Also ... 427
AwsEc2SecurityGroupIpv6Range ... 428
Contents ... 428
See Also ... 428
AwsEc2SecurityGroupPrefixListId ... 429
Contents ... 429
See Also ... 429
AwsEc2SecurityGroupUserIdGroupPair ... 430
Contents ... 430
See Also ... 431
AwsEc2SubnetDetails ... 432
Contents ... 432
See Also ... 433
AwsEc2VolumeAttachment ... 435
Contents ... 435
See Also ... 435
AwsEc2VolumeDetails ... 436
Contents ... 436
See Also ... 437
AwsEc2VpcDetails ... 438
Contents ... 438
See Also ... 438
AwsEc2VpcEndpointServiceDetails ... 439
Contents ... 439
See Also ... 440
AwsEc2VpcEndpointServiceServiceTypeDetails ... 441
Contents ... 441
See Also ... 441
AwsEc2VpnConnectionDetails ... 442
Contents ... 442
See Also ... 443
AwsEc2VpnConnectionOptionsDetails ... 444
Contents ... 444
See Also ... 444
AwsEc2VpnConnectionOptionsTunnelOptionsDetails ... 445
Contents ... 445
See Also ... 447
AwsEc2VpnConnectionRoutesDetails ... 448
Contents ... 448
See Also ... 448
AwsEc2VpnConnectionVgwTelemetryDetails ... 449
Contents ... 449
See Also ... 450
AwsEcrContainerImageDetails ... 451
Contents ... 451
See Also ... 452
AwsEcrRepositoryDetails ... 453
Contents ... 453
See Also ... 454
AwsEcrRepositoryImageScanningConfigurationDetails ... 455
Contents ... 455
See Also ... 455
AwsEcrRepositoryLifecyclePolicyDetails ... 456
Contents ... 456
See Also ... 456
AwsEcsClusterClusterSettingsDetails ... 457
Contents ... 457
See Also ... 457
AwsEcsClusterConfigurationDetails ... 458
Contents ... 458
See Also ... 458
AwsEcsClusterConfigurationExecuteCommandConfigurationDetails ... 459
Contents ... 459
See Also ... 459
AwsEcsClusterConfigurationExecuteCommandConfigurationLogConfigurationDetails ... 460
Contents ... 460
See Also ... 460
AwsEcsClusterDefaultCapacityProviderStrategyDetails ... 462
Contents ... 462
See Also ... 462
AwsEcsClusterDetails ... 463
Contents ... 463
See Also ... 463
AwsEcsServiceCapacityProviderStrategyDetails ... 464
Contents ... 464
See Also ... 464
AwsEcsServiceDeploymentConfigurationDeploymentCircuitBreakerDetails ... 465
Contents ... 465
See Also ... 465
AwsEcsServiceDeploymentConfigurationDetails ... 466
Contents ... 466
See Also ... 466
AwsEcsServiceDeploymentControllerDetails ... 467
Contents ... 467
See Also ... 467
AwsEcsServiceDetails ... 468
Contents ... 468
See Also ... 471
AwsEcsServiceLoadBalancersDetails ... 472
Contents ... 472
See Also ... 472
AwsEcsServiceNetworkConfigurationAwsVpcConfigurationDetails ... 474
Contents ... 474
See Also ... 474
AwsEcsServiceNetworkConfigurationDetails ... 475
Contents ... 475
See Also ... 475
AwsEcsServicePlacementConstraintsDetails ... 476
Contents ... 476
See Also ... 476
AwsEcsServicePlacementStrategiesDetails ... 477
Contents ... 477
See Also ... 477
AwsEcsServiceServiceRegistriesDetails ... 478
Contents ... 478
See Also ... 478
AwsEcsTaskDefinitionContainerDefinitionsDependsOnDetails ... 480
Contents ... 480
See Also ... 480
AwsEcsTaskDefinitionContainerDefinitionsDetails ... 481
Contents ... 481
See Also ... 486
AwsEcsTaskDefinitionContainerDefinitionsEnvironmentDetails ... 487
Contents ... 487
See Also ... 487
AwsEcsTaskDefinitionContainerDefinitionsEnvironmentFilesDetails ... 488
Contents ... 488
See Also ... 488
AwsEcsTaskDefinitionContainerDefinitionsExtraHostsDetails ... 489
Contents ... 489
See Also ... 489
AwsEcsTaskDefinitionContainerDefinitionsFirelensConfigurationDetails ... 490
Contents ... 490
See Also ... 490
AwsEcsTaskDefinitionContainerDefinitionsHealthCheckDetails ... 491
Contents ... 491
See Also ... 491
AwsEcsTaskDefinitionContainerDefinitionsLinuxParametersCapabilitiesDetails ... 493
Contents ... 493
See Also ... 493
AwsEcsTaskDefinitionContainerDefinitionsLinuxParametersDetails ... 494
Contents ... 494
See Also ... 495
AwsEcsTaskDefinitionContainerDefinitionsLinuxParametersDevicesDetails ... 496
Contents ... 496
See Also ... 496
AwsEcsTaskDefinitionContainerDefinitionsLinuxParametersTmpfsDetails ... 497
Contents ... 497
See Also ... 497
AwsEcsTaskDefinitionContainerDefinitionsLogConfigurationDetails ... 498
Contents ... 498
See Also ... 498
AwsEcsTaskDefinitionContainerDefinitionsLogConfigurationSecretOptionsDetails ... 499
Contents ... 499
See Also ... 499
AwsEcsTaskDefinitionContainerDefinitionsMountPointsDetails ... 500
Contents ... 500
See Also ... 500
AwsEcsTaskDefinitionContainerDefinitionsPortMappingsDetails ... 501
Contents ... 501
See Also ... 501
AwsEcsTaskDefinitionContainerDefinitionsRepositoryCredentialsDetails ... 502
Contents ... 502
See Also ... 502
AwsEcsTaskDefinitionContainerDefinitionsResourceRequirementsDetails ... 503
Contents ... 503
See Also ... 503
AwsEcsTaskDefinitionContainerDefinitionsSecretsDetails ... 504
Contents ... 504
See Also ... 504
AwsEcsTaskDefinitionContainerDefinitionsSystemControlsDetails ... 505
Contents ... 505
See Also ... 505
AwsEcsTaskDefinitionContainerDefinitionsUlimitsDetails ... 506
Contents ... 506
See Also ... 506
AwsEcsTaskDefinitionContainerDefinitionsVolumesFromDetails ... 507
Contents ... 507
See Also ... 507
AwsEcsTaskDefinitionDetails ... 508
Contents ... 508
See Also ... 510
AwsEcsTaskDefinitionInferenceAcceleratorsDetails ... 511
Contents ... 511
See Also ... 511
AwsEcsTaskDefinitionPlacementConstraintsDetails ... 512
Contents ... 512
See Also ... 512
AwsEcsTaskDefinitionProxyConfigurationDetails ... 513
Contents ... 513
See Also ... 513
AwsEcsTaskDefinitionProxyConfigurationProxyConfigurationPropertiesDetails ... 514
Contents ... 514
See Also ... 514
AwsEcsTaskDefinitionVolumesDetails ... 515
Contents ... 515
See Also ... 515
AwsEcsTaskDefinitionVolumesDockerVolumeConfigurationDetails ... 516
Contents ... 516
See Also ... 516
AwsEcsTaskDefinitionVolumesEfsVolumeConfigurationAuthorizationConfigDetails ... 518
Contents ... 518
See Also ... 518
AwsEcsTaskDefinitionVolumesEfsVolumeConfigurationDetails ... 519
Contents ... 519
See Also ... 519
AwsEcsTaskDefinitionVolumesHostDetails ... 521
Contents ... 521
See Also ... 521
AwsEksClusterDetails ... 522
Contents ... 522
See Also ... 523
AwsEksClusterLoggingClusterLoggingDetails ... 524
Contents ... 524
See Also ... 524
AwsEksClusterLoggingDetails ... 525
Contents ... 525
See Also ... 525
AwsEksClusterResourcesVpcConfigDetails ... 526
Contents ... 526
See Also ... 526
AwsElasticBeanstalkEnvironmentDetails ... 527
Contents ... 527
See Also ... 529
AwsElasticBeanstalkEnvironmentEnvironmentLink ... 530
Contents ... 530
See Also ... 530
AwsElasticBeanstalkEnvironmentOptionSetting ... 531
Contents ... 531
See Also ... 531
AwsElasticBeanstalkEnvironmentTier ... 532
Contents ... 532
See Also ... 532
AwsElasticsearchDomainDetails ... 533
Contents ... 533
See Also ... 535
AwsElasticsearchDomainDomainEndpointOptions ... 536
Contents ... 536
See Also ... 536
AwsElasticsearchDomainElasticsearchClusterConfigDetails ... 537
Contents ... 537
See Also ... 538
AwsElasticsearchDomainElasticsearchClusterConfigZoneAwarenessConfigDetails ... 539
Contents ... 539
See Also ... 539
AwsElasticsearchDomainEncryptionAtRestOptions ... 540
Contents ... 540
See Also ... 540
AwsElasticsearchDomainLogPublishingOptions ... 541
Contents ... 541
See Also ... 541
AwsElasticsearchDomainLogPublishingOptionsLogConfig ... 542
Contents ... 542
See Also ... 542
AwsElasticsearchDomainNodeToNodeEncryptionOptions ... 543
Contents ... 543
See Also ... 543
AwsElasticsearchDomainServiceSoftwareOptions ... 544
Contents ... 544
See Also ... 545
AwsElasticsearchDomainVPCOptions ... 546
Contents ... 546
See Also ... 546
AwsElbAppCookieStickinessPolicy ... 547
Contents ... 547
See Also ... 547
AwsElbLbCookieStickinessPolicy ... 548
Contents ... 548
See Also ... 548
AwsElbLoadBalancerAccessLog ... 549
Contents ... 549
See Also ... 549
AwsElbLoadBalancerAttributes ... 550
Contents ... 550
See Also ... 550
AwsElbLoadBalancerBackendServerDescription ... 552
Contents ... 552
See Also ... 552
AwsElbLoadBalancerConnectionDraining ... 553
Contents ... 553
See Also ... 553
AwsElbLoadBalancerConnectionSettings ... 554
Contents ... 554
See Also ... 554
AwsElbLoadBalancerCrossZoneLoadBalancing ... 555
Contents ... 555
See Also ... 555
AwsElbLoadBalancerDetails ... 556
Contents ... 556
See Also ... 558
AwsElbLoadBalancerHealthCheck ... 559
Contents ... 559
See Also ... 559
AwsElbLoadBalancerInstance ... 561
Contents ... 561
See Also ... 561
AwsElbLoadBalancerListener ... 562
Contents ... 562
See Also ... 562
AwsElbLoadBalancerListenerDescription ... 564
Contents ... 564
See Also ... 564
AwsElbLoadBalancerPolicies ... 565
Contents ... 565
See Also ... 565
AwsElbLoadBalancerSourceSecurityGroup ... 566
Contents ... 566
See Also ... 566
AwsElbv2LoadBalancerAttribute ... 567
Contents ... 567
See Also ... 567
AwsElbv2LoadBalancerDetails ... 568
Contents ... 568
See Also ... 569
AwsIamAccessKeyDetails ... 570
Contents ... 570
See Also ... 571
AwsIamAccessKeySessionContext ... 572
Contents ... 572
See Also ... 572
AwsIamAccessKeySessionContextAttributes ... 573
Contents ... 573
See Also ... 573
AwsIamAccessKeySessionContextSessionIssuer ... 574
Contents ... 574
See Also ... 574
AwsIamAttachedManagedPolicy ... 576
Contents ... 576
See Also ... 576
AwsIamGroupDetails ... 577
Contents ... 577
See Also ... 578
AwsIamGroupPolicy ... 579
Contents ... 579
See Also ... 579
AwsIamInstanceProfile ... 580
Contents ... 580
See Also ... 581
AwsIamInstanceProfileRole ... 582
Contents ... 582
See Also ... 583
AwsIamPermissionsBoundary ... 584
Contents ... 584
See Also ... 584
AwsIamPolicyDetails ... 585
Contents ... 585
See Also ... 586
AwsIamPolicyVersion ... 587
Contents ... 587
See Also ... 587
AwsIamRoleDetails ... 588
Contents ... 588
See Also ... 589
AwsIamRolePolicy ... 590
Contents ... 590
See Also ... 590
AwsIamUserDetails ... 591
Contents ... 591
See Also ... 592
AwsIamUserPolicy ... 593
Contents ... 593
See Also ... 593 AwsKmsKeyDetails ... 594 Contents ... 594 See Also ... 595 AwsLambdaFunctionCode ... 596 Contents ... 596 See Also ... 596 AwsLambdaFunctionDeadLetterConfig ... 597 Contents ... 597 See Also ... 597 AwsLambdaFunctionDetails ... 598 Contents ... 598 See Also ... 600 AwsLambdaFunctionEnvironment ... 601 Contents ... 601 See Also ... 601 AwsLambdaFunctionEnvironmentError ... 602 Contents ... 602 See Also ... 602 AwsLambdaFunctionLayer ... 603 Contents ... 603 See Also ... 603 AwsLambdaFunctionTracingConfig ... 604 Contents ... 604 See Also ... 604 AwsLambdaFunctionVpcConfig ... 605 Contents ... 605 See Also ... 605 AwsLambdaLayerVersionDetails ... 606 Contents ... 606 See Also ... 606 AwsNetworkFirewallFirewallDetails ... 607 Contents ... 607 See Also ... 608 AwsNetworkFirewallFirewallPolicyDetails ... 609 Contents ... 609 See Also ... 609 AwsNetworkFirewallFirewallSubnetMappingsDetails ... 611 Contents ... 611 See Also ... 611 AwsNetworkFirewallRuleGroupDetails ... 612 Contents ... 612 See Also ... 613 AwsOpenSearchServiceDomainClusterConfigDetails ... 614 Contents ... 614 See Also ... 615 AwsOpenSearchServiceDomainClusterConfigZoneAwarenessConfigDetails ... 616 Contents ... 616 See Also ... 616 AwsOpenSearchServiceDomainDetails ... 617 Contents ... 617 See Also ... 619 AwsOpenSearchServiceDomainDomainEndpointOptionsDetails ... 620 Contents ... 620 See Also ... 620 AwsOpenSearchServiceDomainEncryptionAtRestOptionsDetails ... 622 Contents ... 622
See Also ... 622 AwsOpenSearchServiceDomainLogPublishingOption ... 623 Contents ... 623 See Also ... 623 AwsOpenSearchServiceDomainLogPublishingOptionsDetails ... 624 Contents ... 624 See Also ... 624 AwsOpenSearchServiceDomainNodeToNodeEncryptionOptionsDetails ... 625 Contents ... 625 See Also ... 625 AwsOpenSearchServiceDomainServiceSoftwareOptionsDetails ... 626 Contents ... 626 See Also ... 627 AwsOpenSearchServiceDomainVpcOptionsDetails ... 628 Contents ... 628 See Also ... 628 AwsRdsDbClusterAssociatedRole ... 629 Contents ... 629 See Also ... 629 AwsRdsDbClusterDetails ... 630 Contents ... 630 See Also ... 635 AwsRdsDbClusterMember ... 636 Contents ... 636 See Also ... 636 AwsRdsDbClusterOptionGroupMembership ... 637 Contents ... 637 See Also ... 637 AwsRdsDbClusterSnapshotDetails ... 638 Contents ... 638 See Also ... 640 AwsRdsDbDomainMembership ... 641 Contents ... 641 See Also ... 641 AwsRdsDbInstanceAssociatedRole ... 642 Contents ... 642 See Also ... 642 AwsRdsDbInstanceDetails ... 643 Contents ... 643 See Also ... 651 AwsRdsDbInstanceEndpoint ... 652 Contents ... 652 See Also ... 652 AwsRdsDbInstanceVpcSecurityGroup ... 653 Contents ... 653 See Also ... 653 AwsRdsDbOptionGroupMembership ... 654 Contents ... 654 See Also ... 654 AwsRdsDbParameterGroup ... 655 Contents ... 655 See Also ... 655 AwsRdsDbPendingModifiedValues ... 656 Contents ... 656 See Also ... 658 AwsRdsDbProcessorFeature ... 659 Contents ... 659
See Also ... 659 AwsRdsDbSnapshotDetails ... 660 Contents ... 660 See Also ... 664 AwsRdsDbStatusInfo ... 665 Contents ... 665 See Also ... 665 AwsRdsDbSubnetGroup ... 666 Contents ... 666 See Also ... 667 AwsRdsDbSubnetGroupSubnet ... 668 Contents ... 668 See Also ... 668 AwsRdsDbSubnetGroupSubnetAvailabilityZone ... 669 Contents ... 669 See Also ... 669 AwsRdsEventSubscriptionDetails ... 670 Contents ... 670 See Also ... 671 AwsRdsPendingCloudWatchLogsExports ... 672 Contents ... 672 See Also ... 672 AwsRedshiftClusterClusterNode ... 673 Contents ... 673 See Also ... 673 AwsRedshiftClusterClusterParameterGroup ... 674 Contents ... 674 See Also ... 674 AwsRedshiftClusterClusterParameterStatus ... 675 Contents ... 675 See Also ... 675 AwsRedshiftClusterClusterSecurityGroup ... 676 Contents ... 676 See Also ... 676 AwsRedshiftClusterClusterSnapshotCopyStatus ... 677 Contents ... 677 See Also ... 677 AwsRedshiftClusterDeferredMaintenanceWindow ... 678 Contents ... 678 See Also ... 678 AwsRedshiftClusterDetails ... 679 Contents ... 679 See Also ... 685 AwsRedshiftClusterElasticIpStatus ... 686 Contents ... 686 See Also ... 686 AwsRedshiftClusterEndpoint ... 687 Contents ... 687 See Also ... 687 AwsRedshiftClusterHsmStatus ... 688 Contents ... 688 See Also ... 688 AwsRedshiftClusterIamRole ... 689 Contents ... 689 See Also ... 689 AwsRedshiftClusterPendingModifiedValues ... 690 Contents ... 690
See Also ... 691 AwsRedshiftClusterResizeInfo ... 692 Contents ... 692 See Also ... 692 AwsRedshiftClusterRestoreStatus ... 693 Contents ... 693 See Also ... 694 AwsRedshiftClusterVpcSecurityGroup ... 695 Contents ... 695 See Also ... 695 AwsS3AccountPublicAccessBlockDetails ... 696 Contents ... 696 See Also ... 696 AwsS3BucketBucketLifecycleConfigurationDetails ... 697 Contents ... 697 See Also ... 697 AwsS3BucketBucketLifecycleConfigurationRulesAbortIncompleteMultipartUploadDetails ... 698 Contents ... 698 See Also ... 698 AwsS3BucketBucketLifecycleConfigurationRulesDetails ... 699 Contents ... 699 See Also ... 700 AwsS3BucketBucketLifecycleConfigurationRulesFilterDetails ... 701 Contents ... 701 See Also ... 701 AwsS3BucketBucketLifecycleConfigurationRulesFilterPredicateDetails ... 702 Contents ... 702 See Also ... 702 AwsS3BucketBucketLifecycleConfigurationRulesFilterPredicateOperandsDetails ... 703 Contents ... 703 See Also ... 703 AwsS3BucketBucketLifecycleConfigurationRulesFilterPredicateOperandsTagDetails ... 704 Contents ... 704 See Also ... 704 AwsS3BucketBucketLifecycleConfigurationRulesFilterPredicateTagDetails ... 705 Contents ... 705 See Also ... 705 AwsS3BucketBucketLifecycleConfigurationRulesNoncurrentVersionTransitionsDetails ... 706 Contents ... 706 See Also ... 706 AwsS3BucketBucketLifecycleConfigurationRulesTransitionsDetails ... 707 Contents ... 707 See Also ... 707 AwsS3BucketBucketVersioningConfiguration ... 708 Contents ... 708 See Also ... 708 AwsS3BucketDetails ... 709 Contents ... 709 See Also ... 710 AwsS3BucketLoggingConfiguration ... 711 Contents ... 711 See Also ... 711 AwsS3BucketNotificationConfiguration ... 712 Contents ... 712 See Also ... 712 AwsS3BucketNotificationConfigurationDetail ... 713 Contents ... 713
See Also ... 713 AwsS3BucketNotificationConfigurationFilter ... 714 Contents ... 714 See Also ... 714 AwsS3BucketNotificationConfigurationS3KeyFilter ... 715 Contents ... 715 See Also ... 715 AwsS3BucketNotificationConfigurationS3KeyFilterRule ... 716 Contents ... 716 See Also ... 716 AwsS3BucketServerSideEncryptionByDefault ... 717 Contents ... 717 See Also ... 717 AwsS3BucketServerSideEncryptionConfiguration ... 718 Contents ... 718 See Also ... 718 AwsS3BucketServerSideEncryptionRule ... 719 Contents ... 719 See Also ... 719 AwsS3BucketWebsiteConfiguration ... 720 Contents ... 720 See Also ... 720 AwsS3BucketWebsiteConfigurationRedirectTo ... 721 Contents ... 721 See Also ... 721 AwsS3BucketWebsiteConfigurationRoutingRule ... 722 Contents ... 722 See Also ... 722 AwsS3BucketWebsiteConfigurationRoutingRuleCondition ... 723 Contents ... 723 See Also ... 723 AwsS3BucketWebsiteConfigurationRoutingRuleRedirect ... 724 Contents ... 724 See Also ... 724 AwsS3ObjectDetails ... 726 Contents ... 726 See Also ... 727 AwsSecretsManagerSecretDetails ... 728 Contents ... 728 See Also ... 729 AwsSecretsManagerSecretRotationRules ... 730 Contents ... 730 See Also ... 730 AwsSecurityFinding ... 731 Contents ... 731 See Also ... 737 AwsSecurityFindingFilters ... 739 Contents ... 739 See Also ... 751 AwsSecurityFindingIdentifier ... 752 Contents ... 752 See Also ... 752 AwsSnsTopicDetails ... 753 Contents ... 753 See Also ... 753 AwsSnsTopicSubscription ... 754 Contents ... 754
See Also ... 754 AwsSqsQueueDetails ... 755 Contents ... 755 See Also ... 755 AwsSsmComplianceSummary ... 756 Contents ... 756 See Also ... 758 AwsSsmPatch ... 759 Contents ... 759 See Also ... 759 AwsSsmPatchComplianceDetails ... 760 Contents ... 760 See Also ... 760 AwsWafRateBasedRuleDetails ... 761 Contents ... 761 See Also ... 762 AwsWafRateBasedRuleMatchPredicate ... 763 Contents ... 763 See Also ... 763 AwsWafRegionalRateBasedRuleDetails ... 764 Contents ... 764 See Also ... 765 AwsWafRegionalRateBasedRuleMatchPredicate ... 766 Contents ... 766 See Also ... 766 AwsWafWebAclDetails ... 767 Contents ... 767 See Also ... 767 AwsWafWebAclRule ... 768 Contents ... 768 See Also ... 769 AwsXrayEncryptionConfigDetails ... 770 Contents ... 770 See Also ... 770 BatchUpdateFindingsUnprocessedFinding ... 771 Contents ... 771 See Also ... 771 BooleanFilter ... 772 Contents ... 772 See Also ... 772 Cell ... 773 Contents ... 773 See Also ... 773 CidrBlockAssociation ... 774 Contents ... 774 See Also ... 774 City ... 775 Contents ... 775 See Also ... 775 ClassificationResult ... 776 Contents ... 776 See Also ... 776 ClassificationStatus ... 778 Contents ... 778 See Also ... 778 Compliance ... 779 Contents ... 779
See Also ... 779 ContainerDetails ... 780 Contents ... 780 See Also ... 780 Country ... 781 Contents ... 781 See Also ... 781 CustomDataIdentifiersDetections ... 782 Contents ... 782 See Also ... 782 CustomDataIdentifiersResult ... 783 Contents ... 783 See Also ... 783 Cvss ... 784 Contents ... 784 See Also ... 784 DataClassificationDetails ... 786 Contents ... 786 See Also ... 786 DateFilter ... 787 Contents ... 787 See Also ... 787 DateRange ... 788 Contents ... 788 See Also ... 788 DnsRequestAction ... 789 Contents ... 789 See Also ... 789 FindingAggregator ... 790 Contents ... 790 See Also ... 790 FindingProviderFields ... 791 Contents ... 791 See Also ... 792 FindingProviderSeverity ... 793 Contents ... 793 See Also ... 793 FirewallPolicyDetails ... 794 Contents ... 794 See Also ... 794 FirewallPolicyStatefulRuleGroupReferencesDetails ... 796 Contents ... 796 See Also ... 796 FirewallPolicyStatelessCustomActionsDetails ... 797 Contents ... 797 See Also ... 797 FirewallPolicyStatelessRuleGroupReferencesDetails ... 798 Contents ... 798 See Also ... 798 GeoLocation ... 799 Contents ... 799 See Also ... 799 IcmpTypeCode ... 800 Contents ... 800 See Also ... 800 ImportFindingsError ... 801 Contents ... 801
See Also ... 801 Insight ... 802 Contents ... 802 See Also ... 802 InsightResults ... 803 Contents ... 803 See Also ... 803 InsightResultValue ... 804 Contents ... 804 See Also ... 804 Invitation ... 805 Contents ... 805 See Also ... 805 IpFilter ... 806 Contents ... 806 See Also ... 806 IpOrganizationDetails ... 807 Contents ... 807 See Also ... 807 Ipv6CidrBlockAssociation ... 808 Contents ... 808 See Also ... 808 KeywordFilter ... 809 Contents ... 809 See Also ... 809 LoadBalancerState ... 810 Contents ... 810 See Also ... 810 Malware ... 811 Contents ... 811 See Also ... 811 MapFilter ... 812 Contents ... 812 See Also ... 812 Member ... 814 Contents ... 814 See Also ... 815 Network ... 816 Contents ... 816 See Also ... 817 NetworkConnectionAction ... 819 Contents ... 819 See Also ... 819 NetworkHeader ... 821 Contents ... 821 See Also ... 821 NetworkPathComponent ... 822 Contents ... 822 See Also ... 822 NetworkPathComponentDetails ... 823 Contents ... 823 See Also ... 823 Note ... 824 Contents ... 824 See Also ... 824 NoteUpdate ... 825 Contents ... 825
See Also ... 825 NumberFilter ... 826 Contents ... 826 See Also ... 826 Occurrences ... 827 Contents ... 827 See Also ... 827 Page ... 828 Contents ... 828 See Also ... 828 PatchSummary ... 829 Contents ... 829 See Also ... 830 PortProbeAction ... 831 Contents ... 831 See Also ... 831 PortProbeDetail ... 832 Contents ... 832 See Also ... 832 PortRange ... 833 Contents ... 833 See Also ... 833 PortRangeFromTo ... 834 Contents ... 834 See Also ... 834 ProcessDetails ... 835 Contents ... 835 See Also ... 836 Product ... 837 Contents ... 837 See Also ... 838 Range ... 839 Contents ... 839 See Also ... 839 Recommendation ... 840 Contents ... 840 See Also ... 840 Record ... 841 Contents ... 841 See Also ... 841 RelatedFinding ... 842 Contents ... 842 See Also ... 842 Remediation ... 843 Contents ... 843 See Also ... 843 Resource ... 844 Contents ... 844 See Also ... 845 ResourceDetails ... 846 Contents ... 846 See Also ... 853 Result ... 854 Contents ... 854 See Also ... 854 RuleGroupDetails ... 855 Contents ... 855
See Also ... 855 RuleGroupSource ... 856 Contents ... 856 See Also ... 856 RuleGroupSourceCustomActionsDetails ... 857 Contents ... 857 See Also ... 857 RuleGroupSourceListDetails ... 858 Contents ... 858 See Also ... 858 RuleGroupSourceStatefulRulesDetails ... 859 Contents ... 859 See Also ... 859 RuleGroupSourceStatefulRulesHeaderDetails ... 860 Contents ... 860 See Also ... 861 RuleGroupSourceStatefulRulesOptionsDetails ... 862 Contents ... 862 See Also ... 862 RuleGroupSourceStatelessRuleDefinition ... 863 Contents ... 863 See Also ... 863 RuleGroupSourceStatelessRuleMatchAttributes ... 864 Contents ... 864 See Also ... 864 RuleGroupSourceStatelessRuleMatchAttributesDestinationPorts ... 866 Contents ... 866 See Also ... 866 RuleGroupSourceStatelessRuleMatchAttributesDestinations ... 867 Contents ... 867 See Also ... 867 RuleGroupSourceStatelessRuleMatchAttributesSourcePorts ... 868 Contents ... 868 See Also ... 868 RuleGroupSourceStatelessRuleMatchAttributesSources ... 869 Contents ... 869 See Also ... 869 RuleGroupSourceStatelessRuleMatchAttributesTcpFlags ... 870 Contents ... 870 See Also ... 870 RuleGroupSourceStatelessRulesAndCustomActionsDetails ... 871 Contents ... 871 See Also ... 871 RuleGroupSourceStatelessRulesDetails ... 872 Contents ... 872 See Also ... 872 RuleGroupVariables ... 873 Contents ... 873 See Also ... 873 RuleGroupVariablesIpSetsDetails ... 874 Contents ... 874 See Also ... 874 RuleGroupVariablesPortSetsDetails ... 875 Contents ... 875 See Also ... 875 SensitiveDataDetections ... 876 Contents ... 876
See Also ... 876 SensitiveDataResult ... 877 Contents ... 877 See Also ... 877 Severity ... 878 Contents ... 878 See Also ... 879 SeverityUpdate ... 880 Contents ... 880 See Also ... 880 SoftwarePackage ... 882 Contents ... 882 See Also ... 883 SortCriterion ... 884 Contents ... 884 See Also ... 884 Standard ... 885 Contents ... 885 See Also ... 885 StandardsControl ... 886 Contents ... 886 See Also ... 887 StandardsStatusReason ... 888 Contents ... 888 See Also ... 888 StandardsSubscription ... 889 Contents ... 889 See Also ... 890 StandardsSubscriptionRequest ... 891 Contents ... 891 See Also ... 891 StatelessCustomActionDefinition ... 892 Contents ... 892 See Also ... 892 StatelessCustomPublishMetricAction ... 893 Contents ... 893 See Also ... 893 StatelessCustomPublishMetricActionDimension ... 894 Contents ... 894 See Also ... 894 StatusReason ... 895 Contents ... 895 See Also ... 895 StringFilter ... 896 Contents ... 896 See Also ... 897 ThreatIntelIndicator ... 898 Contents ... 898 See Also ... 899 Vulnerability ... 900 Contents ... 900 See Also ... 900 VulnerabilityVendor ... 902 Contents ... 902 See Also ... 903 WafAction ... 904 Contents ... 904
See Also ... 904 WafExcludedRule ... 905 Contents ... 905 See Also ... 905 WafOverrideAction ... 906 Contents ... 906 See Also ... 906 Workflow ... 907 Contents ... 907 See Also ... 907 WorkflowUpdate ... 908 Contents ... 908 See Also ... 908 Common Parameters ... 909 Common Errors ... 911
Welcome
Security Hub provides you with a comprehensive view of the security state of your AWS environment and resources. It also provides you with the readiness status of your environment based on controls from supported security standards. Security Hub collects security data from AWS accounts, services, and integrated third-party products and helps you analyze security trends in your environment to identify the highest priority security issues. For more information about Security Hub, see the AWS Security Hub User Guide .
When you use operations in the Security Hub API, the requests are executed only in the AWS Region that is currently active or in the specific AWS Region that you specify in your request. Any configuration or settings change that results from the operation is applied only to that Region. To make the same change in other Regions, execute the same command for each Region to apply the change to.
For example, if your Region is set to us-west-2, when you use CreateMembers to add a member account to Security Hub, the association of the member account with the administrator account is created only in the us-west-2 Region. Security Hub must be enabled for the member account in the same Region that the invitation was sent from.
The following throttling limits apply to using Security Hub API operations.
• BatchEnableStandards - RateLimit of 1 request per second, BurstLimit of 1 request per second.
• GetFindings - RateLimit of 3 requests per second. BurstLimit of 6 requests per second.
• UpdateFindings - RateLimit of 1 request per second. BurstLimit of 5 requests per second.
• UpdateStandardsControl - RateLimit of 1 request per second, BurstLimit of 5 requests per second.
• All other operations - RateLimit of 10 requests per second. BurstLimit of 30 requests per second.
This document was last published on March 6, 2022.
Actions
The following actions are supported:
• AcceptAdministratorInvitation (p. 4)
• AcceptInvitation (p. 6)
• BatchDisableStandards (p. 9)
• BatchEnableStandards (p. 12)
• BatchImportFindings (p. 15)
• BatchUpdateFindings (p. 61)
• CreateActionTarget (p. 66)
• CreateFindingAggregator (p. 69)
• CreateInsight (p. 72)
• CreateMembers (p. 84)
• DeclineInvitations (p. 87)
• DeleteActionTarget (p. 89)
• DeleteFindingAggregator (p. 91)
• DeleteInsight (p. 93)
• DeleteInvitations (p. 95)
• DeleteMembers (p. 98)
• DescribeActionTargets (p. 101)
• DescribeHub (p. 104)
• DescribeOrganizationConfiguration (p. 107)
• DescribeProducts (p. 109)
• DescribeStandards (p. 112)
• DescribeStandardsControls (p. 114)
• DisableImportFindingsForProduct (p. 117)
• DisableOrganizationAdminAccount (p. 119)
• DisableSecurityHub (p. 121)
• DisassociateFromAdministratorAccount (p. 123)
• DisassociateFromMasterAccount (p. 125)
• DisassociateMembers (p. 127)
• EnableImportFindingsForProduct (p. 129)
• EnableOrganizationAdminAccount (p. 131)
• EnableSecurityHub (p. 133)
• GetAdministratorAccount (p. 136)
• GetEnabledStandards (p. 138)
• GetFindingAggregator (p. 141)
• GetFindings (p. 144)
• GetInsightResults (p. 200)
• GetInsights (p. 202)
• GetInvitationsCount (p. 214)
• GetMasterAccount (p. 216)
• GetMembers (p. 218)
• InviteMembers (p. 221)
• ListEnabledProductsForImport (p. 224)
• ListFindingAggregators (p. 226)
• ListInvitations (p. 228)
• ListMembers (p. 231)
• ListOrganizationAdminAccounts (p. 234)
• ListTagsForResource (p. 236)
• TagResource (p. 238)
• UntagResource (p. 240)
• UpdateActionTarget (p. 242)
• UpdateFindingAggregator (p. 244)
• UpdateFindings (p. 248)
• UpdateInsight (p. 260)
• UpdateOrganizationConfiguration (p. 272)
• UpdateSecurityHubConfiguration (p. 274)
• UpdateStandardsControl (p. 276)
AcceptAdministratorInvitation
Accepts the invitation to be a member account and be monitored by the Security Hub administrator account that the invitation was sent from.
This operation is only used by member accounts that are not added through Organizations.
When the member account accepts the invitation, permission is granted to the administrator account to view findings generated in the member account.
Request Syntax
POST /administrator HTTP/1.1 Content-type: application/json {
"AdministratorId": "string", "InvitationId": "string"
}
URI Request Parameters
The request does not use any URI parameters.
Request Body
The request accepts the following data in JSON format.
AdministratorId (p. 4)
The account ID of the Security Hub administrator account that sent the invitation.
Type: String Pattern: .*\S.*
Required: Yes InvitationId (p. 4)
The identifier of the invitation sent from the Security Hub administrator account.
Type: String Pattern: .*\S.*
Required: Yes
Response Syntax
HTTP/1.1 200
Response Elements
If the action is successful, the service sends back an HTTP 200 response with an empty HTTP body.
Errors
For information about the errors that are common to all actions, see Common Errors (p. 911).
InternalException Internal server error.
HTTP Status Code: 500 InvalidAccessException
There is an issue with the account used to make the request. Either Security Hub is not enabled for the account, or the account does not have permission to perform this action.
HTTP Status Code: 401 InvalidInputException
The request was rejected because you supplied an invalid or out-of-range value for an input parameter.
HTTP Status Code: 400 LimitExceededException
The request was rejected because it attempted to create resources beyond the current AWS account or throttling limits. The error code describes the limit exceeded.
HTTP Status Code: 429 ResourceNotFoundException
The request was rejected because we can't find the specified resource.
HTTP Status Code: 404
See Also
For more information about using this API in one of the language-specific AWS SDKs, see the following:
• AWS Command Line Interface
• AWS SDK for .NET
• AWS SDK for C++
• AWS SDK for Go
• AWS SDK for Java V2
• AWS SDK for JavaScript
• AWS SDK for PHP V3
• AWS SDK for Python
• AWS SDK for Ruby V3
AcceptInvitation
This method is deprecated. Instead, use AcceptAdministratorInvitation.
The Security Hub console continues to use AcceptInvitation. It will eventually change to use AcceptAdministratorInvitation. Any IAM policies that specifically control access to this function must continue to use AcceptInvitation. You should also add AcceptAdministratorInvitation to your policies to ensure that the correct permissions are in place after the console begins to use AcceptAdministratorInvitation.
Accepts the invitation to be a member account and be monitored by the Security Hub administrator account that the invitation was sent from.
This operation is only used by member accounts that are not added through Organizations.
When the member account accepts the invitation, permission is granted to the administrator account to view findings generated in the member account.
Request Syntax
POST /master HTTP/1.1
Content-type: application/json { "InvitationId": "string", "MasterId": "string"
}
URI Request Parameters
The request does not use any URI parameters.
Request Body
The request accepts the following data in JSON format.
InvitationId (p. 6)
The identifier of the invitation sent from the Security Hub administrator account.
Type: String Pattern: .*\S.*
Required: Yes MasterId (p. 6)
The account ID of the Security Hub administrator account that sent the invitation.
Type: String Pattern: .*\S.*
Required: Yes
Response Syntax
HTTP/1.1 200
Response Elements
If the action is successful, the service sends back an HTTP 200 response with an empty HTTP body.
Errors
For information about the errors that are common to all actions, see Common Errors (p. 911).
InternalException Internal server error.
HTTP Status Code: 500 InvalidAccessException
There is an issue with the account used to make the request. Either Security Hub is not enabled for the account, or the account does not have permission to perform this action.
HTTP Status Code: 401 InvalidInputException
The request was rejected because you supplied an invalid or out-of-range value for an input parameter.
HTTP Status Code: 400 LimitExceededException
The request was rejected because it attempted to create resources beyond the current AWS account or throttling limits. The error code describes the limit exceeded.
HTTP Status Code: 429 ResourceNotFoundException
The request was rejected because we can't find the specified resource.
HTTP Status Code: 404
See Also
For more information about using this API in one of the language-specific AWS SDKs, see the following:
• AWS Command Line Interface
• AWS SDK for .NET
• AWS SDK for C++
• AWS SDK for Go
• AWS SDK for Java V2
• AWS SDK for JavaScript
• AWS SDK for PHP V3
• AWS SDK for Python
• AWS SDK for Ruby V3
BatchDisableStandards
Disables the standards specified by the provided StandardsSubscriptionArns.
For more information, see Security Standards section of the AWS Security Hub User Guide.
Request Syntax
POST /standards/deregister HTTP/1.1 Content-type: application/json {
"StandardsSubscriptionArns": [ "string" ] }
URI Request Parameters
The request does not use any URI parameters.
Request Body
The request accepts the following data in JSON format.
StandardsSubscriptionArns (p. 9)
The ARNs of the standards subscriptions to disable.
Type: Array of strings
Array Members: Minimum number of 1 item. Maximum number of 25 items.
Pattern: .*\S.*
Required: Yes
Response Syntax
HTTP/1.1 200
Content-type: application/json { "StandardsSubscriptions": [ {
"StandardsArn": "string", "StandardsInput": { "string" : "string"
},
"StandardsStatus": "string", "StandardsStatusReason": { "StatusReasonCode": "string"
},
"StandardsSubscriptionArn": "string"
} ]}
Response Elements
If the action is successful, the service sends back an HTTP 200 response.
The following data is returned in JSON format by the service.
StandardsSubscriptions (p. 9)
The details of the standards subscriptions that were disabled.
Type: Array of StandardsSubscription (p. 889) objects
Errors
For information about the errors that are common to all actions, see Common Errors (p. 911).
InternalException Internal server error.
HTTP Status Code: 500 InvalidAccessException
There is an issue with the account used to make the request. Either Security Hub is not enabled for the account, or the account does not have permission to perform this action.
HTTP Status Code: 401 InvalidInputException
The request was rejected because you supplied an invalid or out-of-range value for an input parameter.
HTTP Status Code: 400 LimitExceededException
The request was rejected because it attempted to create resources beyond the current AWS account or throttling limits. The error code describes the limit exceeded.
HTTP Status Code: 429
See Also
For more information about using this API in one of the language-specific AWS SDKs, see the following:
• AWS Command Line Interface
• AWS SDK for .NET
• AWS SDK for C++
• AWS SDK for Go
• AWS SDK for Java V2
• AWS SDK for JavaScript
• AWS SDK for PHP V3
• AWS SDK for Python
• AWS SDK for Ruby V3
BatchEnableStandards
Enables the standards specified by the provided StandardsArn. To obtain the ARN for a standard, use the DescribeStandards operation.
For more information, see the Security Standards section of the AWS Security Hub User Guide.
Request Syntax
POST /standards/register HTTP/1.1 Content-type: application/json {
"StandardsSubscriptionRequests": [ {
"StandardsArn": "string", "StandardsInput": { "string" : "string"
} } ]}
URI Request Parameters
The request does not use any URI parameters.
Request Body
The request accepts the following data in JSON format.
StandardsSubscriptionRequests (p. 12) The list of standards checks to enable.
Type: Array of StandardsSubscriptionRequest (p. 891) objects
Array Members: Minimum number of 1 item. Maximum number of 25 items.
Required: Yes
Response Syntax
HTTP/1.1 200
Content-type: application/json { "StandardsSubscriptions": [ {
"StandardsArn": "string", "StandardsInput": { "string" : "string"
},
"StandardsStatus": "string", "StandardsStatusReason": { "StatusReasonCode": "string"
},
"StandardsSubscriptionArn": "string"
} ] }
Response Elements
If the action is successful, the service sends back an HTTP 200 response.
The following data is returned in JSON format by the service.
StandardsSubscriptions (p. 12)
The details of the standards subscriptions that were enabled.
Type: Array of StandardsSubscription (p. 889) objects
Errors
For information about the errors that are common to all actions, see Common Errors (p. 911).
InternalException Internal server error.
HTTP Status Code: 500 InvalidAccessException
There is an issue with the account used to make the request. Either Security Hub is not enabled for the account, or the account does not have permission to perform this action.
HTTP Status Code: 401 InvalidInputException
The request was rejected because you supplied an invalid or out-of-range value for an input parameter.
HTTP Status Code: 400 LimitExceededException
The request was rejected because it attempted to create resources beyond the current AWS account or throttling limits. The error code describes the limit exceeded.
HTTP Status Code: 429
See Also
For more information about using this API in one of the language-specific AWS SDKs, see the following:
• AWS Command Line Interface
• AWS SDK for .NET
• AWS SDK for C++
• AWS SDK for Go
• AWS SDK for Java V2
• AWS SDK for JavaScript
• AWS SDK for PHP V3
• AWS SDK for Python
• AWS SDK for Ruby V3
BatchImportFindings
Imports security findings generated by a finding provider into Security Hub. This action is requested by the finding provider to import its findings into Security Hub.
BatchImportFindings must be called by one of the following:
• The account that is associated with the findings. The identifier of the associated account is the value of the AwsAccountId attribute for the finding.
• An account that is allow-listed for an official Security Hub partner integration.
The maximum allowed size for a finding is 240 Kb. An error is returned for any finding larger than 240 Kb.
After a finding is created, BatchImportFindings cannot be used to update the following finding fields and objects, which Security Hub customers use to manage their investigation workflow.
• Note
• UserDefinedFields
• VerificationState
• Workflow
Finding providers also should not use BatchImportFindings to update the following attributes.
• Confidence
• Criticality
• RelatedFindings
• Severity
• Types
Instead, finding providers use FindingProviderFields to provide values for these attributes.
Request Syntax
POST /findings/import HTTP/1.1 Content-type: application/json { "Findings": [
{
"Action": {
"ActionType": "string", "AwsApiCallAction": { "AffectedResources": { "string" : "string"
},
"Api": "string",
"CallerType": "string", "DomainDetails": { "Domain": "string"
},
"FirstSeen": "string", "LastSeen": "string", "RemoteIpDetails": {
"City": {
"CityName": "string"
},
"Country": {
"CountryCode": "string", "CountryName": "string"
},
"GeoLocation": { "Lat": number, "Lon": number },
"IpAddressV4": "string", "Organization": { "Asn": number, "AsnOrg": "string", "Isp": "string", "Org": "string"
} },
"ServiceName": "string"
},
"DnsRequestAction": { "Blocked": boolean, "Domain": "string", "Protocol": "string"
},
"NetworkConnectionAction": { "Blocked": boolean,
"ConnectionDirection": "string", "LocalPortDetails": {
"Port": number, "PortName": "string"
},
"Protocol": "string", "RemoteIpDetails": { "City": {
"CityName": "string"
},
"Country": {
"CountryCode": "string", "CountryName": "string"
},
"GeoLocation": { "Lat": number, "Lon": number },
"IpAddressV4": "string", "Organization": { "Asn": number, "AsnOrg": "string", "Isp": "string", "Org": "string"
} },
"RemotePortDetails": { "Port": number, "PortName": "string"
} },
"PortProbeAction": { "Blocked": boolean, "PortProbeDetails": [ {
"LocalIpDetails": { "IpAddressV4": "string"
},