Amazon GuardDuty Sample Event Messages
Use these sample event messages to verify a successful integration with JSA.
Due to formatting issues, paste the message format into a text editor and then remove any carriage return or line feed characters.
Amazon GuardDuty sample message when you use the Amazon AWS S3 REST API protocol
Sample 1: The following sample event message shows that an IAM entity requested an API to disable S3 and block public access on a bucket.
{"schemaVersion":"2.0","accountId":"111111111111","region":"region","partition":"aws","id":"6ab9
71cccd774293fcb8a9eaff944711","arn":"arn:aws:guardduty:region:111111111111:detector/
42b0d9e4fcad1600d444fc52278999c2/finding/6ab971cccd774293fcb8a9eaff944711","type":"Policy:S3/
BucketBlockPublicAccessDisabled","resource":{"resourceType":"AccessKey","accessKeyDetails":
{"accessKeyId":"GeneratedFindingAccessKeyId","principalId":"GeneratedFindingPrincipalId","userTy
pe":"IAMUser","userName":"GeneratedFindingUserName"},"s3BucketDetails":
[{"arn":"arn:aws:s3:::bucketName","name":"bucketName","type":"Destination","createdAt":"15136126
92","owner":{"id":"CanonicalId of Owner"},"tags":
[{"key":"foo","value":"bar"}],"defaultServerSideEncryption":
{"encryptionType":"SSEAlgorithm","kmsMasterKeyArn":"arn:aws:kms:region:123456789012:key/keyid"},"
publicAccess":{"permissionConfiguration":{"bucketLevelPermissions":{"accessControlList":
{"allowsPublicReadAccess":false,"allowsPublicWriteAccess":false},"bucketPolicy":
{"allowsPublicReadAccess":false,"allowsPublicWriteAccess":false},"blockPublicAccess":
{"ignorePublicAcls":false,"restrictPublicBuckets":false,"blockPublicAcls":false,"blockPublicPoli
cy":false}},"accountLevelPermissions":{"blockPublicAccess":
{"ignorePublicAcls":false,"restrictPublicBuckets":false,"blockPublicAcls":false,"blockPublicPoli
cy":false}}},"effectivePermission":"NOT_PUBLIC"}],"instanceDetails":
{"instanceId":"i-99999999","instanceType":"m3.xlarge","outpostArn":"arn:aws:outposts:regionname:
123456789000:outpost/
op-0fbc006e9abbc73c3","launchTime":"2016-08-02T02:05:06Z","platform":null,"productCodes":
[{"productCodeId":"GeneratedFindingProductCodeId","productCodeType":"GeneratedFindingProductCode
Type"}],"iamInstanceProfile":
{"arn":"GeneratedFindingInstanceProfileArn","id":"GeneratedFindingInstanceProfileId"},"networkIn
terfaces":[{"ipv6Addresses":
[],"networkInterfaceId":"test","privateDnsName":"GeneratedFindingPrivateDnsName","privateIpAddre
ss":"10.0.0.1","privateIpAddresses":
[{"privateDnsName":"GeneratedFindingPrivateName","privateIpAddress":"10.0.0.1"}],"subnetId":"Gen
eratedFindingSubnetId","vpcId":"GeneratedFindingVPCId","securityGroups":
[{"groupName":"GeneratedFindingSecurityGroupName","groupId":"GeneratedFindingSecurityId"}],"publ
icDnsName":"GeneratedFindingPublicDNSName","publicIp":"10.51.100.0"}],"tags":
[{"key":"GeneratedFindingInstaceTag1","value":"GeneratedFindingInstaceValue1"},
{"key":"GeneratedFindingInstaceTag2","value":"GeneratedFindingInstaceTagValue2"},
{"key":"GeneratedFindingInstaceTag3","value":"GeneratedFindingInstaceTagValue3"},
{"key":"GeneratedFindingInstaceTag4","value":"GeneratedFindingInstaceTagValue4"},
{"key":"GeneratedFindingInstaceTag5","value":"GeneratedFindingInstaceTagValue5"},
{"key":"GeneratedFindingInstaceTag6","value":"GeneratedFindingInstaceTagValue6"},
{"key":"GeneratedFindingInstaceTag7","value":"GeneratedFindingInstaceTagValue7"},
{"key":"GeneratedFindingInstaceTag8","value":"GeneratedFindingInstaceTagValue8"},
{"key":"GeneratedFindingInstaceTag9","value":"GeneratedFindingInstaceTagValue9"}],"instanceState
":"running","availabilityZone":"GeneratedFindingInstaceAvailabilityZone","imageId":"ami-99999999
","imageDescription":"GeneratedFindingInstaceImageDescription"}},"service":
{"serviceName":"guardduty","detectorId":"11a1a1a1aaaa1111a111aa11111111a1","action":
{"actionType":"AWS_API_CALL","awsApiCallAction":
{"api":"GeneratedFindingAPIName","serviceName":"GeneratedFindingAPIServiceName","callerType":"Re
mote IP","remoteIpDetails":{"ipAddressV4":"10.51.100.0","organization":
{"asn":"-1","asnOrg":"GeneratedFindingASNOrg","isp":"GeneratedFindingISP","org":"GeneratedFindin
gORG"},"country":{"countryName":"GeneratedFindingCountryName"},"city":
{"cityName":"GeneratedFindingCityName"},"geoLocation":
{"lat":44.972686,"lon":-65.860879}},"affectedResources":
{"AWS::S3::Bucket":"GeneratedFindingS3Bucket"}}},"resourceRole":"TARGET","additionalInfo":
{"unusual":{"hoursOfDay":[1513609200000],"userNames":
["GeneratedFindingUserName"]},"sample":true},"eventFirstSeen":"2020-06-23T23:53:14.222Z","eventL
astSeen":"2020-06-24T00:26:33.501Z","archived":false,"count":2},"severity":2,"createdAt":"2020-0
6-23T23:53:14.222Z","updatedAt":"2020-06-24T00:26:33.501Z","title":"Amazon S3 Block Public
Access was disabled for S3 bucket GeneratedFindingS3Bucket.","description":"Amazon S3 Block
Public Access was disabled for S3 bucket GeneratedFindingS3Bucket by GeneratedFindingUserName
calling GeneratedFindingAPIName. If this behavior is not expected, it may indicate a
configuration mistake or that your credentials are compromised."}|
JSA field name |
Highlighted values in the event payload |
|---|---|
|
Event ID |
Policy:S3/BucketBlockPublicAccessDisabled |
|
Source IP |
10.51.100.0 |
|
Event Time |
2020-06-23T23:53:14.222Z |
|
Username |
GeneratedFindingUserName |
Sample 2: The following sample event message shows that S3 server access logging is disabled for a bucket.
{\"schemaVersion\":\"2.0\",\"accountId\":\"111111111111\",\"region\":\"region\",\"partition\":\"
aws\",\"id\":\"90b971cccd774ee2570756fda343dd2a\",\"arn\":\"arn:aws:guardduty:region:11111111111
1:detector/42b0d9e4fcad1600d444fc52278999c2/finding/
90b971cccd774ee2570756fda343dd2a\",\"type\":\"Stealth:S3/
ServerAccessLoggingDisabled\",\"resource\":{\"resourceType\":\"AccessKey\",\"accessKeyDetails\":
{\"accessKeyId\":\"GeneratedFindingAccessKeyId\",\"principalId\":\"GeneratedFindingPrincipalId\"
,\"userType\":\"IAMUser\",\"userName\":\"GeneratedFindingUserName\"},\"s3BucketDetails\":
[{\"arn\":\"arn:aws:s3:::bucketName\",\"name\":\"bucketName\",\"type\":\"Destination\",\"created
At\":\"1513612692\",\"owner\":{\"id\":\"CanonicalId of Owner\"},\"tags\":
[{\"key\":\"foo\",\"value\":\"bar\"}],\"defaultServerSideEncryption\":
{\"encryptionType\":\"SSEAlgorithm\",\"kmsMasterKeyArn\":\"arn:aws:kms:region:123456789012:key/
key-id\"},\"publicAccess\":{\"permissionConfiguration\":{\"bucketLevelPermissions\":
{\"accessControlList\":
{\"allowsPublicReadAccess\":false,\"allowsPublicWriteAccess\":false},\"bucketPolicy\":
{\"allowsPublicReadAccess\":false,\"allowsPublicWriteAccess\":false},\"blockPublicAccess\":
{\"ignorePublicAcls\":false,\"restrictPublicBuckets\":false,\"blockPublicAcls\":false,\"blockPub
licPolicy\":false}},\"accountLevelPermissions\":{\"blockPublicAccess\":
{\"ignorePublicAcls\":false,\"restrictPublicBuckets\":false,\"blockPublicAcls\":false,\"blockPub
licPolicy\":false}}},\"effectivePermission\":\"NOT_PUBLIC\"}}],\"instanceDetails\":
{\"instanceId\":\"i-99999999\",\"instanceType\":\"m3.xlarge\",\"outpostArn\":\"arn:aws:outposts:
region-name:123456789000:outpost/
op-0fbc006e9abbc73c3\",\"launchTime\":\"2016-08-02T02:05:06Z\",\"platform\":null,\"productCodes\
":
[{\"productCodeId\":\"GeneratedFindingProductCodeId\",\"productCodeType\":\"GeneratedFindingProd
uctCodeType\"}],\"iamInstanceProfile\":
{\"arn\":\"GeneratedFindingInstanceProfileArn\",\"id\":\"GeneratedFindingInstanceProfileId\"},\"
networkInterfaces\":[{\"ipv6Addresses\":
[],\"networkInterfaceId\":\"test\",\"privateDnsName\":\"GeneratedFindingPrivateDnsName\",\"priva
teIpAddress\":\"10.0.0.1\",\"privateIpAddresses\":
[{\"privateDnsName\":\"GeneratedFindingPrivateName\",\"privateIpAddress\":\"10.0.0.1\"}],\"subne
tId\":\"GeneratedFindingSubnetId\",\"vpcId\":\"GeneratedFindingVPCId\",\"securityGroups\":
[{\"groupName\":\"GeneratedFindingSecurityGroupName\",\"groupId\":\"GeneratedFindingSecurityId\"
}],\"publicDnsName\":\"GeneratedFindingPublicDNSName\",\"publicIp\":\"10.51.100.0\"}],\"tags\":
[{\"key\":\"GeneratedFindingInstaceTag1\",\"value\":\"GeneratedFindingInstaceValue1\"},
{\"key\":\"GeneratedFindingInstaceTag2\",\"value\":\"GeneratedFindingInstaceTagValue2\"},
{\"key\":\"GeneratedFindingInstaceTag3\",\"value\":\"GeneratedFindingInstaceTagValue3\"},
{\"key\":\"GeneratedFindingInstaceTag4\",\"value\":\"GeneratedFindingInstaceTagValue4\"},
{\"key\":\"GeneratedFindingInstaceTag5\",\"value\":\"GeneratedFindingInstaceTagValue5\"},
{\"key\":\"GeneratedFindingInstaceTag6\",\"value\":\"GeneratedFindingInstaceTagValue6\"},
{\"key\":\"GeneratedFindingInstaceTag7\",\"value\":\"GeneratedFindingInstaceTagValue7\"},
{\"key\":\"GeneratedFindingInstaceTag8\",\"value\":\"GeneratedFindingInstaceTagValue8\"},
{\"key\":\"GeneratedFindingInstaceTag9\",\"value\":\"GeneratedFindingInstaceTagValue9\"}],\"inst
anceState\":\"running\",\"availabilityZone\":\"GeneratedFindingInstaceAvailabilityZone\",\"image
Id\":\"ami-99999999\",\"imageDescription\":\"GeneratedFindingInstaceImageDescription\"}},\"servi
ce\":
{\"serviceName\":\"guardduty\",\"detectorId\":\"11a1a1a1aaaa1111a111aa11111111a1\",\"action\":
{\"actionType\":\"AWS_API_CALL\",\"awsApiCallAction\":
{\"api\":\"GeneratedFindingAPIName\",\"serviceName\":\"GeneratedFindingAPIServiceName\",\"caller
Type\":\"Remote IP\",\"remoteIpDetails\":{\"ipAddressV4\":\"10.51.100.0\",\"organization\":
{\"asn\":\"-1\",\"asnOrg\":\"GeneratedFindingASNOrg\",\"isp\":\"GeneratedFindingISP\",\"org\":\"
GeneratedFindingORG\"},\"country\":{\"countryName\":\"GeneratedFindingCountryName\"},\"city\":
{\"cityName\":\"GeneratedFindingCityName\"},\"geoLocation\":
{\"lat\":44.972686,\"lon\":-65.860879}},\"affectedResources\":
{\"AWS::S3::Bucket\":\"GeneratedFindingS3Bucket\"}}},\"resourceRole\":\"TARGET\",\"additionalInf
o\":{\"unusual\":{\"hoursOfDay\":[1513609200000],\"userNames\":
[\"GeneratedFindingUserName\"]},\"sample\":true},\"eventFirstSeen\":\"2020-06-23T23:53:14.222Z\"
,\"eventLastSeen\":\"2020-06-24T00:26:33.501Z\",\"archived\":false,\"count\":2},\"severity\":2,\
"createdAt\":\"2020-06-23T23:53:14.222Z\",\"updatedAt\":\"2020-06-24T00:26:33.501Z\",\"title\":\
"Amazon S3 Server Access Logging was disabled for S3 bucket
GeneratedFindingS3Bucket.\",\"description\":\"Amazon S3 Server Access Logging was disabled for
S3 bucket GeneratedFindingS3Bucket by GeneratedFindingUserName calling PutBucketLogging. This
can lead to lack of visibility into actions taken on the affected S3 bucket and its objects if
an event occurs.\"}|
JSA field name |
Highlighted values in the event payload |
|---|---|
|
Event ID |
Stealth:S3/ServerAccessLoggingDisabled |
|
Source IP |
10.51.100.0 |
|
Event Time |
2020-06-23T23:53:14.222Z |
|
Username |
GeneratedFindingUserName |