IndicatorDetail
Details about the indicators of compromise which are used to determine if a resource is involved in a security incident. An indicator of compromise (IOC) is an artifact observed in or on a network, system, or environment that can (with a high level of confidence) identify malicious activity or a security incident. For the list of indicators of compromise that are generated by Detective investigations, see Detective investigations.
Types
Properties
Suspicious IP addresses that are flagged, which indicates critical or severe threats based on threat intelligence by Detective. This indicator is derived from Amazon Web Services threat intelligence.
Identifies unusual and impossible user activity for an account.
Contains details about the new Autonomous System Organization (ASO).
Contains details about the new geographic location.
Contains details about the new user agent.
Contains details about related findings.
Contains details about related finding groups.
Details about the indicator of compromise.