Detective / Client / list_indicators
list_indicators¶
- Detective.Client.list_indicators(**kwargs)¶
- Gets the indicators from an investigation. You can use the information from the indicators to determine if an IAM user and/or IAM role is involved in an unusual activity that could indicate malicious behavior and its impact. - See also: AWS API Documentation - Request Syntax- response = client.list_indicators( GraphArn='string', InvestigationId='string', IndicatorType='TTP_OBSERVED'|'IMPOSSIBLE_TRAVEL'|'FLAGGED_IP_ADDRESS'|'NEW_GEOLOCATION'|'NEW_ASO'|'NEW_USER_AGENT'|'RELATED_FINDING'|'RELATED_FINDING_GROUP', NextToken='string', MaxResults=123 ) - Parameters:
- GraphArn (string) – - [REQUIRED] - The Amazon Resource Name (ARN) of the behavior graph. 
- InvestigationId (string) – - [REQUIRED] - The investigation ID of the investigation report. 
- IndicatorType (string) – For the list of indicators of compromise that are generated by Detective investigations, see Detective investigations. 
- NextToken (string) – - Lists if there are more results available. The value of nextToken is a unique pagination token for each page. Repeat the call using the returned token to retrieve the next page. Keep all other arguments unchanged. - Each pagination token expires after 24 hours. Using an expired pagination token will return a Validation Exception error. 
- MaxResults (integer) – Lists the maximum number of indicators in a page. 
 
- Return type:
- dict 
- Returns:
- Response Syntax- { 'GraphArn': 'string', 'InvestigationId': 'string', 'NextToken': 'string', 'Indicators': [ { 'IndicatorType': 'TTP_OBSERVED'|'IMPOSSIBLE_TRAVEL'|'FLAGGED_IP_ADDRESS'|'NEW_GEOLOCATION'|'NEW_ASO'|'NEW_USER_AGENT'|'RELATED_FINDING'|'RELATED_FINDING_GROUP', 'IndicatorDetail': { 'TTPsObservedDetail': { 'Tactic': 'string', 'Technique': 'string', 'Procedure': 'string', 'IpAddress': 'string', 'APIName': 'string', 'APISuccessCount': 123, 'APIFailureCount': 123 }, 'ImpossibleTravelDetail': { 'StartingIpAddress': 'string', 'EndingIpAddress': 'string', 'StartingLocation': 'string', 'EndingLocation': 'string', 'HourlyTimeDelta': 123 }, 'FlaggedIpAddressDetail': { 'IpAddress': 'string', 'Reason': 'AWS_THREAT_INTELLIGENCE' }, 'NewGeolocationDetail': { 'Location': 'string', 'IpAddress': 'string', 'IsNewForEntireAccount': True|False }, 'NewAsoDetail': { 'Aso': 'string', 'IsNewForEntireAccount': True|False }, 'NewUserAgentDetail': { 'UserAgent': 'string', 'IsNewForEntireAccount': True|False }, 'RelatedFindingDetail': { 'Arn': 'string', 'Type': 'string', 'IpAddress': 'string' }, 'RelatedFindingGroupDetail': { 'Id': 'string' } } }, ] } - Response Structure- (dict) – - GraphArn (string) – - The Amazon Resource Name (ARN) of the behavior graph. 
- InvestigationId (string) – - The investigation ID of the investigation report. 
- NextToken (string) – - Lists if there are more results available. The value of nextToken is a unique pagination token for each page. Repeat the call using the returned token to retrieve the next page. Keep all other arguments unchanged. - Each pagination token expires after 24 hours. Using an expired pagination token will return a Validation Exception error. 
- Indicators (list) – - Lists the indicators of compromise. - (dict) – - Detective investigations triages indicators of compromises such as a finding and surfaces only the most critical and suspicious issues, so you can focus on high-level investigations. An - Indicatorlets you determine if an Amazon Web Services resource is involved in unusual activity that could indicate malicious behavior and its impact.- IndicatorType (string) – - The type of indicator. 
- IndicatorDetail (dict) – - Details about the indicators of compromise that are used to determine if a resource is involved in a security incident. An indicator of compromise (IOC) is an artifact observed in or on a network, system, or environment that can (with a high level of confidence) identify malicious activity or a security incident. - TTPsObservedDetail (dict) – - Details about the indicator of compromise. - Tactic (string) – - The tactic used, identified by the investigation. 
- Technique (string) – - The technique used, identified by the investigation. 
- Procedure (string) – - The procedure used, identified by the investigation. 
- IpAddress (string) – - The IP address where the tactics, techniques, and procedure (TTP) was observed. 
- APIName (string) – - The name of the API where the tactics, techniques, and procedure (TTP) was observed. 
- APISuccessCount (integer) – - The total number of successful API requests. 
- APIFailureCount (integer) – - The total number of failed API requests. 
 
- ImpossibleTravelDetail (dict) – - Identifies unusual and impossible user activity for an account. - StartingIpAddress (string) – - IP address where the resource was first used in the impossible travel. 
- EndingIpAddress (string) – - IP address where the resource was last used in the impossible travel. 
- StartingLocation (string) – - Location where the resource was first used in the impossible travel. 
- EndingLocation (string) – - Location where the resource was last used in the impossible travel. 
- HourlyTimeDelta (integer) – - Returns the time difference between the first and last timestamp the resource was used. 
 
- FlaggedIpAddressDetail (dict) – - Suspicious IP addresses that are flagged, which indicates critical or severe threats based on threat intelligence by Detective. This indicator is derived from Amazon Web Services threat intelligence. - IpAddress (string) – - IP address of the suspicious entity. 
- Reason (string) – - Details the reason the IP address was flagged as suspicious. 
 
- NewGeolocationDetail (dict) – - Contains details about the new geographic location. - Location (string) – - Location where the resource was accessed. 
- IpAddress (string) – - IP address using which the resource was accessed. 
- IsNewForEntireAccount (boolean) – - Checks if the geolocation is new for the entire account. 
 
- NewAsoDetail (dict) – - Contains details about the new Autonomous System Organization (ASO). - Aso (string) – - Details about the new Autonomous System Organization (ASO). 
- IsNewForEntireAccount (boolean) – - Checks if the Autonomous System Organization (ASO) is new for the entire account. 
 
- NewUserAgentDetail (dict) – - Contains details about the new user agent. - UserAgent (string) – - New user agent which accessed the resource. 
- IsNewForEntireAccount (boolean) – - Checks if the user agent is new for the entire account. 
 
- RelatedFindingDetail (dict) – - Contains details about related findings. - Arn (string) – - The Amazon Resource Name (ARN) of the related finding. 
- Type (string) – - The type of finding. 
- IpAddress (string) – - The IP address of the finding. 
 
- RelatedFindingGroupDetail (dict) – - Contains details about related finding groups. - Id (string) – - The unique identifier for the finding group. 
 
 
 
 
 
 
 - Exceptions