Amazon GuardDuty Sample Event Messages
Use these sample event messages to verify a successful integration with JSA.
Due to formatting issues, paste the message format into a text editor and then remove any carriage return or line feed characters.
Amazon GuardDuty sample message when you use the Amazon AWS S3 REST API protocol
Sample 1: The following sample event message shows that an IAM entity requested an API to disable S3 and block public access on a bucket.
{"schemaVersion":"2.0","accountId":"111111111111","region":"region","partition":"aws","id":"6ab9 71cccd774293fcb8a9eaff944711","arn":"arn:aws:guardduty:region:111111111111:detector/ 42b0d9e4fcad1600d444fc52278999c2/finding/6ab971cccd774293fcb8a9eaff944711","type":"Policy:S3/ BucketBlockPublicAccessDisabled","resource":{"resourceType":"AccessKey","accessKeyDetails": {"accessKeyId":"GeneratedFindingAccessKeyId","principalId":"GeneratedFindingPrincipalId","userTy pe":"IAMUser","userName":"GeneratedFindingUserName"},"s3BucketDetails": [{"arn":"arn:aws:s3:::bucketName","name":"bucketName","type":"Destination","createdAt":"15136126 92","owner":{"id":"CanonicalId of Owner"},"tags": [{"key":"foo","value":"bar"}],"defaultServerSideEncryption": {"encryptionType":"SSEAlgorithm","kmsMasterKeyArn":"arn:aws:kms:region:123456789012:key/keyid"}," publicAccess":{"permissionConfiguration":{"bucketLevelPermissions":{"accessControlList": {"allowsPublicReadAccess":false,"allowsPublicWriteAccess":false},"bucketPolicy": {"allowsPublicReadAccess":false,"allowsPublicWriteAccess":false},"blockPublicAccess": {"ignorePublicAcls":false,"restrictPublicBuckets":false,"blockPublicAcls":false,"blockPublicPoli cy":false}},"accountLevelPermissions":{"blockPublicAccess": {"ignorePublicAcls":false,"restrictPublicBuckets":false,"blockPublicAcls":false,"blockPublicPoli cy":false}}},"effectivePermission":"NOT_PUBLIC"}],"instanceDetails": {"instanceId":"i-99999999","instanceType":"m3.xlarge","outpostArn":"arn:aws:outposts:regionname: 123456789000:outpost/ op-0fbc006e9abbc73c3","launchTime":"2016-08-02T02:05:06Z","platform":null,"productCodes": [{"productCodeId":"GeneratedFindingProductCodeId","productCodeType":"GeneratedFindingProductCode Type"}],"iamInstanceProfile": {"arn":"GeneratedFindingInstanceProfileArn","id":"GeneratedFindingInstanceProfileId"},"networkIn terfaces":[{"ipv6Addresses": [],"networkInterfaceId":"test","privateDnsName":"GeneratedFindingPrivateDnsName","privateIpAddre ss":"10.0.0.1","privateIpAddresses": [{"privateDnsName":"GeneratedFindingPrivateName","privateIpAddress":"10.0.0.1"}],"subnetId":"Gen eratedFindingSubnetId","vpcId":"GeneratedFindingVPCId","securityGroups": [{"groupName":"GeneratedFindingSecurityGroupName","groupId":"GeneratedFindingSecurityId"}],"publ icDnsName":"GeneratedFindingPublicDNSName","publicIp":"10.51.100.0"}],"tags": [{"key":"GeneratedFindingInstaceTag1","value":"GeneratedFindingInstaceValue1"}, {"key":"GeneratedFindingInstaceTag2","value":"GeneratedFindingInstaceTagValue2"}, {"key":"GeneratedFindingInstaceTag3","value":"GeneratedFindingInstaceTagValue3"}, {"key":"GeneratedFindingInstaceTag4","value":"GeneratedFindingInstaceTagValue4"}, {"key":"GeneratedFindingInstaceTag5","value":"GeneratedFindingInstaceTagValue5"}, {"key":"GeneratedFindingInstaceTag6","value":"GeneratedFindingInstaceTagValue6"}, {"key":"GeneratedFindingInstaceTag7","value":"GeneratedFindingInstaceTagValue7"}, {"key":"GeneratedFindingInstaceTag8","value":"GeneratedFindingInstaceTagValue8"}, {"key":"GeneratedFindingInstaceTag9","value":"GeneratedFindingInstaceTagValue9"}],"instanceState ":"running","availabilityZone":"GeneratedFindingInstaceAvailabilityZone","imageId":"ami-99999999 ","imageDescription":"GeneratedFindingInstaceImageDescription"}},"service": {"serviceName":"guardduty","detectorId":"11a1a1a1aaaa1111a111aa11111111a1","action": {"actionType":"AWS_API_CALL","awsApiCallAction": {"api":"GeneratedFindingAPIName","serviceName":"GeneratedFindingAPIServiceName","callerType":"Re mote IP","remoteIpDetails":{"ipAddressV4":"10.51.100.0","organization": {"asn":"-1","asnOrg":"GeneratedFindingASNOrg","isp":"GeneratedFindingISP","org":"GeneratedFindin gORG"},"country":{"countryName":"GeneratedFindingCountryName"},"city": {"cityName":"GeneratedFindingCityName"},"geoLocation": {"lat":44.972686,"lon":-65.860879}},"affectedResources": {"AWS::S3::Bucket":"GeneratedFindingS3Bucket"}}},"resourceRole":"TARGET","additionalInfo": {"unusual":{"hoursOfDay":[1513609200000],"userNames": ["GeneratedFindingUserName"]},"sample":true},"eventFirstSeen":"2020-06-23T23:53:14.222Z","eventL astSeen":"2020-06-24T00:26:33.501Z","archived":false,"count":2},"severity":2,"createdAt":"2020-0 6-23T23:53:14.222Z","updatedAt":"2020-06-24T00:26:33.501Z","title":"Amazon S3 Block Public Access was disabled for S3 bucket GeneratedFindingS3Bucket.","description":"Amazon S3 Block Public Access was disabled for S3 bucket GeneratedFindingS3Bucket by GeneratedFindingUserName calling GeneratedFindingAPIName. If this behavior is not expected, it may indicate a configuration mistake or that your credentials are compromised."}
JSA field name |
Highlighted values in the event payload |
---|---|
Event ID |
Policy:S3/BucketBlockPublicAccessDisabled |
Source IP |
10.51.100.0 |
Event Time |
2020-06-23T23:53:14.222Z |
Username |
GeneratedFindingUserName |
Sample 2: The following sample event message shows that S3 server access logging is disabled for a bucket.
{\"schemaVersion\":\"2.0\",\"accountId\":\"111111111111\",\"region\":\"region\",\"partition\":\" aws\",\"id\":\"90b971cccd774ee2570756fda343dd2a\",\"arn\":\"arn:aws:guardduty:region:11111111111 1:detector/42b0d9e4fcad1600d444fc52278999c2/finding/ 90b971cccd774ee2570756fda343dd2a\",\"type\":\"Stealth:S3/ ServerAccessLoggingDisabled\",\"resource\":{\"resourceType\":\"AccessKey\",\"accessKeyDetails\": {\"accessKeyId\":\"GeneratedFindingAccessKeyId\",\"principalId\":\"GeneratedFindingPrincipalId\" ,\"userType\":\"IAMUser\",\"userName\":\"GeneratedFindingUserName\"},\"s3BucketDetails\": [{\"arn\":\"arn:aws:s3:::bucketName\",\"name\":\"bucketName\",\"type\":\"Destination\",\"created At\":\"1513612692\",\"owner\":{\"id\":\"CanonicalId of Owner\"},\"tags\": [{\"key\":\"foo\",\"value\":\"bar\"}],\"defaultServerSideEncryption\": {\"encryptionType\":\"SSEAlgorithm\",\"kmsMasterKeyArn\":\"arn:aws:kms:region:123456789012:key/ key-id\"},\"publicAccess\":{\"permissionConfiguration\":{\"bucketLevelPermissions\": {\"accessControlList\": {\"allowsPublicReadAccess\":false,\"allowsPublicWriteAccess\":false},\"bucketPolicy\": {\"allowsPublicReadAccess\":false,\"allowsPublicWriteAccess\":false},\"blockPublicAccess\": {\"ignorePublicAcls\":false,\"restrictPublicBuckets\":false,\"blockPublicAcls\":false,\"blockPub licPolicy\":false}},\"accountLevelPermissions\":{\"blockPublicAccess\": {\"ignorePublicAcls\":false,\"restrictPublicBuckets\":false,\"blockPublicAcls\":false,\"blockPub licPolicy\":false}}},\"effectivePermission\":\"NOT_PUBLIC\"}}],\"instanceDetails\": {\"instanceId\":\"i-99999999\",\"instanceType\":\"m3.xlarge\",\"outpostArn\":\"arn:aws:outposts: region-name:123456789000:outpost/ op-0fbc006e9abbc73c3\",\"launchTime\":\"2016-08-02T02:05:06Z\",\"platform\":null,\"productCodes\ ": [{\"productCodeId\":\"GeneratedFindingProductCodeId\",\"productCodeType\":\"GeneratedFindingProd uctCodeType\"}],\"iamInstanceProfile\": {\"arn\":\"GeneratedFindingInstanceProfileArn\",\"id\":\"GeneratedFindingInstanceProfileId\"},\" networkInterfaces\":[{\"ipv6Addresses\": [],\"networkInterfaceId\":\"test\",\"privateDnsName\":\"GeneratedFindingPrivateDnsName\",\"priva teIpAddress\":\"10.0.0.1\",\"privateIpAddresses\": [{\"privateDnsName\":\"GeneratedFindingPrivateName\",\"privateIpAddress\":\"10.0.0.1\"}],\"subne tId\":\"GeneratedFindingSubnetId\",\"vpcId\":\"GeneratedFindingVPCId\",\"securityGroups\": [{\"groupName\":\"GeneratedFindingSecurityGroupName\",\"groupId\":\"GeneratedFindingSecurityId\" }],\"publicDnsName\":\"GeneratedFindingPublicDNSName\",\"publicIp\":\"10.51.100.0\"}],\"tags\": [{\"key\":\"GeneratedFindingInstaceTag1\",\"value\":\"GeneratedFindingInstaceValue1\"}, {\"key\":\"GeneratedFindingInstaceTag2\",\"value\":\"GeneratedFindingInstaceTagValue2\"}, {\"key\":\"GeneratedFindingInstaceTag3\",\"value\":\"GeneratedFindingInstaceTagValue3\"}, {\"key\":\"GeneratedFindingInstaceTag4\",\"value\":\"GeneratedFindingInstaceTagValue4\"}, {\"key\":\"GeneratedFindingInstaceTag5\",\"value\":\"GeneratedFindingInstaceTagValue5\"}, {\"key\":\"GeneratedFindingInstaceTag6\",\"value\":\"GeneratedFindingInstaceTagValue6\"}, {\"key\":\"GeneratedFindingInstaceTag7\",\"value\":\"GeneratedFindingInstaceTagValue7\"}, {\"key\":\"GeneratedFindingInstaceTag8\",\"value\":\"GeneratedFindingInstaceTagValue8\"}, {\"key\":\"GeneratedFindingInstaceTag9\",\"value\":\"GeneratedFindingInstaceTagValue9\"}],\"inst anceState\":\"running\",\"availabilityZone\":\"GeneratedFindingInstaceAvailabilityZone\",\"image Id\":\"ami-99999999\",\"imageDescription\":\"GeneratedFindingInstaceImageDescription\"}},\"servi ce\": {\"serviceName\":\"guardduty\",\"detectorId\":\"11a1a1a1aaaa1111a111aa11111111a1\",\"action\": {\"actionType\":\"AWS_API_CALL\",\"awsApiCallAction\": {\"api\":\"GeneratedFindingAPIName\",\"serviceName\":\"GeneratedFindingAPIServiceName\",\"caller Type\":\"Remote IP\",\"remoteIpDetails\":{\"ipAddressV4\":\"10.51.100.0\",\"organization\": {\"asn\":\"-1\",\"asnOrg\":\"GeneratedFindingASNOrg\",\"isp\":\"GeneratedFindingISP\",\"org\":\" GeneratedFindingORG\"},\"country\":{\"countryName\":\"GeneratedFindingCountryName\"},\"city\": {\"cityName\":\"GeneratedFindingCityName\"},\"geoLocation\": {\"lat\":44.972686,\"lon\":-65.860879}},\"affectedResources\": {\"AWS::S3::Bucket\":\"GeneratedFindingS3Bucket\"}}},\"resourceRole\":\"TARGET\",\"additionalInf o\":{\"unusual\":{\"hoursOfDay\":[1513609200000],\"userNames\": [\"GeneratedFindingUserName\"]},\"sample\":true},\"eventFirstSeen\":\"2020-06-23T23:53:14.222Z\" ,\"eventLastSeen\":\"2020-06-24T00:26:33.501Z\",\"archived\":false,\"count\":2},\"severity\":2,\ "createdAt\":\"2020-06-23T23:53:14.222Z\",\"updatedAt\":\"2020-06-24T00:26:33.501Z\",\"title\":\ "Amazon S3 Server Access Logging was disabled for S3 bucket GeneratedFindingS3Bucket.\",\"description\":\"Amazon S3 Server Access Logging was disabled for S3 bucket GeneratedFindingS3Bucket by GeneratedFindingUserName calling PutBucketLogging. This can lead to lack of visibility into actions taken on the affected S3 bucket and its objects if an event occurs.\"}
JSA field name |
Highlighted values in the event payload |
---|---|
Event ID |
Stealth:S3/ServerAccessLoggingDisabled |
Source IP |
10.51.100.0 |
Event Time |
2020-06-23T23:53:14.222Z |
Username |
GeneratedFindingUserName |