Class IndicatorDetail
- All Implemented Interfaces:
Serializable,SdkPojo,ToCopyableBuilder<IndicatorDetail.Builder,IndicatorDetail>
Details about the indicators of compromise which are used to determine if a resource is involved in a security incident. An indicator of compromise (IOC) is an artifact observed in or on a network, system, or environment that can (with a high level of confidence) identify malicious activity or a security incident. For the list of indicators of compromise that are generated by Detective investigations, see Detective investigations.
- See Also:
-
Nested Class Summary
Nested Classes -
Method Summary
Modifier and TypeMethodDescriptionstatic IndicatorDetail.Builderbuilder()final booleanfinal booleanequalsBySdkFields(Object obj) Indicates whether some other object is "equal to" this one by SDK fields.final FlaggedIpAddressDetailSuspicious IP addresses that are flagged, which indicates critical or severe threats based on threat intelligence by Detective.final <T> Optional<T> getValueForField(String fieldName, Class<T> clazz) final inthashCode()final ImpossibleTravelDetailIdentifies unusual and impossible user activity for an account.final NewAsoDetailContains details about the new Autonomous System Organization (ASO).final NewGeolocationDetailContains details about the new geographic location.final NewUserAgentDetailContains details about the new user agent.final RelatedFindingDetailContains details about related findings.Contains details about related finding groups.static Class<? extends IndicatorDetail.Builder> Take this object and create a builder that contains all of the current property values of this object.final StringtoString()Returns a string representation of this object.final TTPsObservedDetailDetails about the indicator of compromise.Methods inherited from interface software.amazon.awssdk.utils.builder.ToCopyableBuilder
copy
-
Method Details
-
ttPsObservedDetail
Details about the indicator of compromise.
- Returns:
- Details about the indicator of compromise.
-
impossibleTravelDetail
Identifies unusual and impossible user activity for an account.
- Returns:
- Identifies unusual and impossible user activity for an account.
-
flaggedIpAddressDetail
Suspicious IP addresses that are flagged, which indicates critical or severe threats based on threat intelligence by Detective. This indicator is derived from Amazon Web Services threat intelligence.
- Returns:
- Suspicious IP addresses that are flagged, which indicates critical or severe threats based on threat intelligence by Detective. This indicator is derived from Amazon Web Services threat intelligence.
-
newGeolocationDetail
Contains details about the new geographic location.
- Returns:
- Contains details about the new geographic location.
-
newAsoDetail
Contains details about the new Autonomous System Organization (ASO).
- Returns:
- Contains details about the new Autonomous System Organization (ASO).
-
newUserAgentDetail
Contains details about the new user agent.
- Returns:
- Contains details about the new user agent.
-
toBuilder
Description copied from interface:ToCopyableBuilderTake this object and create a builder that contains all of the current property values of this object.- Specified by:
toBuilderin interfaceToCopyableBuilder<IndicatorDetail.Builder,IndicatorDetail> - Returns:
- a builder for type T
-
builder
-
serializableBuilderClass
-
hashCode
-
equals
-
equalsBySdkFields
Description copied from interface:SdkPojoIndicates whether some other object is "equal to" this one by SDK fields. An SDK field is a modeled, non-inherited field in anSdkPojoclass, and is generated based on a service model.If an
SdkPojoclass does not have any inherited fields,equalsBySdkFieldsandequalsare essentially the same.- Specified by:
equalsBySdkFieldsin interfaceSdkPojo- Parameters:
obj- the object to be compared with- Returns:
- true if the other object equals to this object by sdk fields, false otherwise.
-
toString
-
getValueForField
-
sdkFields
-