# authorship: generated by API Evangelist tooling. Stamped 2026-08-18 # on the file's own generator header (roadmap#64). An unmarked file is # NOT assumed to be ours -- absence of evidence was never stamped. method: generated vocabulary: "1.0.0" info: provider: Amazon GuardDuty description: Vocabulary for Amazon GuardDuty intelligent threat detection APIs created: "2026-04-19" modified: "2026-04-19" operational: apis: - namespace: amazon-guardduty version: "2017-11-28" baseUrl: https://guardduty.amazonaws.com status: active resources: - name: detectors description: GuardDuty detector instances that monitor accounts actions: [list, create, get, update, delete] - name: findings description: Threat findings generated by GuardDuty analysis actions: [list, get, archive, unarchive, create-sample] - name: filters description: Finding suppression and alerting filters actions: [list, create, get, update, delete] - name: ip-sets description: Trusted IP address sets excluded from threat detection actions: [list, create, get, update, delete] - name: threat-intel-sets description: Threat intelligence feeds for enhanced detection actions: [list, create, get, update, delete] - name: members description: Member accounts in a GuardDuty multi-account organization actions: [list, create, get, delete, invite, accept] actions: - name: list httpMethod: GET pattern: read - name: create httpMethod: POST pattern: write - name: get httpMethod: GET pattern: read - name: update httpMethod: POST pattern: write - name: delete httpMethod: DELETE pattern: destructive - name: archive httpMethod: POST pattern: write - name: invite httpMethod: POST pattern: write enums: severity: - LOW - MEDIUM - HIGH finding-status: - ACTIVE - ARCHIVED detector-status: - ENABLED - DISABLED finding-type-prefixes: - Backdoor - Behavior - CredentialAccess - CryptoCurrency - DefenseEvasion - Discovery - Exfiltration - Impact - InitialAccess - PenTest - Persistence - Policy - PrivilegeEscalation - Recon - Stealth - Trojan - UnauthorizedAccess capability: workflows: - name: Amazon GuardDuty Threat Detection file: capabilities/amazon-guardduty-threat-detection.yaml apis: [amazon-guardduty] tools: 12 personas: [Security Analyst, SOC Engineer, Cloud Security Engineer] personas: - id: security-analyst name: Security Analyst description: Investigates and responds to threat findings from GuardDuty - id: soc-engineer name: SOC Engineer description: Monitors security alerts and manages threat response workflows - id: cloud-security-engineer name: Cloud Security Engineer description: Configures GuardDuty detectors and threat intelligence feeds domains: - name: Threat Detection resources: [detectors, findings] - name: Finding Management resources: [filters, ip-sets, threat-intel-sets] - name: Multi-Account Security resources: [members] namespaces: - namespace: amazon-guardduty type: consumed - namespace: guardduty-threat-detection-api type: rest-exposed port: 8085 - namespace: guardduty-threat-detection-mcp type: mcp-exposed port: 9095 binds: - AWS_ACCESS_KEY_ID - AWS_SECRET_ACCESS_KEY - AWS_REGION crossReference: - resource: detectors operations: [ListDetectors, CreateDetector, GetDetector, UpdateDetector, DeleteDetector] workflows: [Amazon GuardDuty Threat Detection] personas: [Cloud Security Engineer] - resource: findings operations: [ListFindings, GetFindings, ArchiveFindings, GetFindingsStatistics] workflows: [Amazon GuardDuty Threat Detection] personas: [Security Analyst, SOC Engineer] - resource: filters operations: [ListFilters, CreateFilter, GetFilter, UpdateFilter, DeleteFilter] workflows: [Amazon GuardDuty Threat Detection] personas: [Cloud Security Engineer, SOC Engineer]