openapi: 3.0.0 info: version: '2017-11-28' x-release: v4 title: Amazon GuardDuty Admin API description: '

Amazon GuardDuty is a continuous security monitoring service that analyzes and processes the following data sources: VPC flow logs, Amazon Web Services CloudTrail management event logs, CloudTrail S3 data event logs, EKS audit logs, DNS logs, and Amazon EBS volume data. It uses threat intelligence feeds, such as lists of malicious IPs and domains, and machine learning to identify unexpected, potentially unauthorized, and malicious activity within your Amazon Web Services environment. This can include issues like escalations of privileges, uses of exposed credentials, or communication with malicious IPs, domains, or presence of malware on your Amazon EC2 instances and container workloads. For example, GuardDuty can detect compromised EC2 instances and container workloads serving malware, or mining bitcoin.

GuardDuty also monitors Amazon Web Services account access behavior for signs of compromise, such as unauthorized infrastructure deployments like EC2 instances deployed in a Region that has never been used, or unusual API calls like a password policy change to reduce password strength.

GuardDuty informs you about the status of your Amazon Web Services environment by producing security findings that you can view in the GuardDuty console or through Amazon EventBridge. For more information, see the Amazon GuardDuty User Guide .

' x-logo: url: https://api.apis.guru/v2/cache/logo/https_twitter.com_awscloud_profile_image.png backgroundColor: '#FFFFFF' termsOfService: https://aws.amazon.com/service-terms/ contact: name: Mike Ralphson email: mike.ralphson@gmail.com url: https://github.com/mermade/aws2openapi x-twitter: PermittedSoc license: name: Apache 2.0 License url: http://www.apache.org/licenses/ x-providerName: amazonaws.com x-serviceName: guardduty x-aws-signingName: guardduty x-origin: - contentType: application/json url: https://raw.githubusercontent.com/aws/aws-sdk-js/master/apis/guardduty-2017-11-28.normal.json converter: url: https://github.com/mermade/aws2openapi version: 1.0.0 x-apisguru-driver: external x-apiClientRegistration: url: https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc2=h_ct x-apisguru-categories: - cloud x-preferred: true servers: - url: http://guardduty.{region}.amazonaws.com variables: region: description: The AWS region enum: - us-east-1 - us-east-2 - us-west-1 - us-west-2 - us-gov-west-1 - us-gov-east-1 - ca-central-1 - eu-north-1 - eu-west-1 - eu-west-2 - eu-west-3 - eu-central-1 - eu-south-1 - af-south-1 - ap-northeast-1 - ap-northeast-2 - ap-northeast-3 - ap-southeast-1 - ap-southeast-2 - ap-east-1 - ap-south-1 - sa-east-1 - me-south-1 default: us-east-1 description: The Amazon GuardDuty multi-region endpoint - url: https://guardduty.{region}.amazonaws.com variables: region: description: The AWS region enum: - us-east-1 - us-east-2 - us-west-1 - us-west-2 - us-gov-west-1 - us-gov-east-1 - ca-central-1 - eu-north-1 - eu-west-1 - eu-west-2 - eu-west-3 - eu-central-1 - eu-south-1 - af-south-1 - ap-northeast-1 - ap-northeast-2 - ap-northeast-3 - ap-southeast-1 - ap-southeast-2 - ap-east-1 - ap-south-1 - sa-east-1 - me-south-1 default: us-east-1 description: The Amazon GuardDuty multi-region endpoint - url: http://guardduty.{region}.amazonaws.com.cn variables: region: description: The AWS region enum: - cn-north-1 - cn-northwest-1 default: cn-north-1 description: The Amazon GuardDuty endpoint for China (Beijing) and China (Ningxia) - url: https://guardduty.{region}.amazonaws.com.cn variables: region: description: The AWS region enum: - cn-north-1 - cn-northwest-1 default: cn-north-1 description: The Amazon GuardDuty endpoint for China (Beijing) and China (Ningxia) security: - hmac: [] tags: - name: Admin paths: /admin/disable: parameters: - $ref: '#/components/parameters/X-Amz-Content-Sha256' - $ref: '#/components/parameters/X-Amz-Date' - $ref: '#/components/parameters/X-Amz-Algorithm' - $ref: '#/components/parameters/X-Amz-Credential' - $ref: '#/components/parameters/X-Amz-Security-Token' - $ref: '#/components/parameters/X-Amz-Signature' - $ref: '#/components/parameters/X-Amz-SignedHeaders' post: operationId: DisableOrganizationAdminAccount description: Disables an Amazon Web Services account within the Organization as the GuardDuty delegated administrator. responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/DisableOrganizationAdminAccountResponse' examples: DisableOrganizationAdminAccount200Example: summary: Default DisableOrganizationAdminAccount 200 response x-microcks-default: true value: detectorId: abc123 format: DNS_LOGS '480': description: BadRequestException content: application/json: schema: $ref: '#/components/schemas/BadRequestException' examples: DisableOrganizationAdminAccount480Example: summary: Default DisableOrganizationAdminAccount 480 response x-microcks-default: true value: detectorId: abc123 format: DNS_LOGS '481': description: InternalServerErrorException content: application/json: schema: $ref: '#/components/schemas/InternalServerErrorException' examples: DisableOrganizationAdminAccount481Example: summary: Default DisableOrganizationAdminAccount 481 response x-microcks-default: true value: detectorId: abc123 format: DNS_LOGS parameters: [] requestBody: required: true content: application/json: schema: type: object required: - adminAccountId properties: adminAccountId: description: The Amazon Web Services Account ID for the organizations account to be disabled as a GuardDuty delegated administrator. type: string summary: Amazon GuardDuty Disable Organization Admin Account x-microcks-operation: delay: 0 dispatcher: FALLBACK tags: - Admin /admin/enable: parameters: - $ref: '#/components/parameters/X-Amz-Content-Sha256' - $ref: '#/components/parameters/X-Amz-Date' - $ref: '#/components/parameters/X-Amz-Algorithm' - $ref: '#/components/parameters/X-Amz-Credential' - $ref: '#/components/parameters/X-Amz-Security-Token' - $ref: '#/components/parameters/X-Amz-Signature' - $ref: '#/components/parameters/X-Amz-SignedHeaders' post: operationId: EnableOrganizationAdminAccount description: Enables an Amazon Web Services account within the organization as the GuardDuty delegated administrator. responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/EnableOrganizationAdminAccountResponse' examples: EnableOrganizationAdminAccount200Example: summary: Default EnableOrganizationAdminAccount 200 response x-microcks-default: true value: detectorId: abc123 format: DNS_LOGS '480': description: BadRequestException content: application/json: schema: $ref: '#/components/schemas/BadRequestException' examples: EnableOrganizationAdminAccount480Example: summary: Default EnableOrganizationAdminAccount 480 response x-microcks-default: true value: detectorId: abc123 format: DNS_LOGS '481': description: InternalServerErrorException content: application/json: schema: $ref: '#/components/schemas/InternalServerErrorException' examples: EnableOrganizationAdminAccount481Example: summary: Default EnableOrganizationAdminAccount 481 response x-microcks-default: true value: detectorId: abc123 format: DNS_LOGS parameters: [] requestBody: required: true content: application/json: schema: type: object required: - adminAccountId properties: adminAccountId: description: The Amazon Web Services Account ID for the organization account to be enabled as a GuardDuty delegated administrator. type: string summary: Amazon GuardDuty Enable Organization Admin Account x-microcks-operation: delay: 0 dispatcher: FALLBACK tags: - Admin /admin: parameters: - $ref: '#/components/parameters/X-Amz-Content-Sha256' - $ref: '#/components/parameters/X-Amz-Date' - $ref: '#/components/parameters/X-Amz-Algorithm' - $ref: '#/components/parameters/X-Amz-Credential' - $ref: '#/components/parameters/X-Amz-Security-Token' - $ref: '#/components/parameters/X-Amz-Signature' - $ref: '#/components/parameters/X-Amz-SignedHeaders' get: operationId: ListOrganizationAdminAccounts description: Lists the accounts configured as GuardDuty delegated administrators. responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/ListOrganizationAdminAccountsResponse' examples: ListOrganizationAdminAccounts200Example: summary: Default ListOrganizationAdminAccounts 200 response x-microcks-default: true value: detectorId: abc123 format: DNS_LOGS '480': description: BadRequestException content: application/json: schema: $ref: '#/components/schemas/BadRequestException' examples: ListOrganizationAdminAccounts480Example: summary: Default ListOrganizationAdminAccounts 480 response x-microcks-default: true value: detectorId: abc123 format: DNS_LOGS '481': description: InternalServerErrorException content: application/json: schema: $ref: '#/components/schemas/InternalServerErrorException' examples: ListOrganizationAdminAccounts481Example: summary: Default ListOrganizationAdminAccounts 481 response x-microcks-default: true value: detectorId: abc123 format: DNS_LOGS parameters: - name: maxResults in: query required: false description: The maximum number of results to return in the response. schema: type: integer minimum: 1 maximum: 50 - name: nextToken in: query required: false description: A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request to a list action. For subsequent calls, use the NextToken value returned from the previous request to continue listing results after the first page. schema: type: string - name: MaxResults in: query schema: type: string description: Pagination limit required: false - name: NextToken in: query schema: type: string description: Pagination token required: false summary: Amazon GuardDuty List Organization Admin Accounts x-microcks-operation: delay: 0 dispatcher: FALLBACK tags: - Admin components: schemas: AdminStatus: type: string enum: - ENABLED - DISABLE_IN_PROGRESS minLength: 1 maxLength: 300 AdminAccount: type: object properties: AdminAccountId: allOf: - $ref: '#/components/schemas/String' - xml: name: adminAccountId description: The Amazon Web Services account ID for the account. AdminStatus: allOf: - $ref: '#/components/schemas/AdminStatus' - xml: name: adminStatus description: Indicates whether the account is enabled as the delegated administrator. description: The account within the organization specified as the GuardDuty delegated administrator. String: type: string AdminAccounts: type: array items: $ref: '#/components/schemas/AdminAccount' minItems: 0 maxItems: 1 InternalServerErrorException: {} ListOrganizationAdminAccountsResponse: type: object properties: AdminAccounts: allOf: - $ref: '#/components/schemas/AdminAccounts' - xml: name: adminAccounts description: A list of accounts configured as GuardDuty delegated administrators. NextToken: allOf: - $ref: '#/components/schemas/String' - xml: name: nextToken description: The pagination parameter to be used on the next list operation to retrieve more items. BadRequestException: {} DisableOrganizationAdminAccountResponse: type: object properties: {} EnableOrganizationAdminAccountResponse: type: object properties: {} parameters: X-Amz-Date: name: X-Amz-Date in: header schema: type: string required: false X-Amz-SignedHeaders: name: X-Amz-SignedHeaders in: header schema: type: string required: false X-Amz-Content-Sha256: name: X-Amz-Content-Sha256 in: header schema: type: string required: false X-Amz-Algorithm: name: X-Amz-Algorithm in: header schema: type: string required: false X-Amz-Credential: name: X-Amz-Credential in: header schema: type: string required: false X-Amz-Security-Token: name: X-Amz-Security-Token in: header schema: type: string required: false X-Amz-Signature: name: X-Amz-Signature in: header schema: type: string required: false securitySchemes: hmac: type: apiKey name: Authorization in: header description: Amazon Signature authorization v4 x-amazon-apigateway-authtype: awsSigv4 externalDocs: description: Amazon Web Services documentation url: https://docs.aws.amazon.com/guardduty/ x-hasEquivalentPaths: true