Automation Rule Criteria Args
Constructors
Properties
The AWS account ID in which a finding was generated. Documented below.
The name of the AWS account in which a finding was generated. Documented below.
The name of the company for the product that generated the finding. For control-based findings, the company is AWS. Documented below.
The unique identifier of a standard in which a control is enabled. Documented below.
The security control ID for which a finding was generated. Security control IDs are the same across standards. Documented below.
The result of a security check. This field is only used for findings generated from controls. Documented below.
The likelihood that a finding accurately identifies the behavior or issue that it was intended to identify. Confidence
is scored on a 0–100 basis using a ratio scale. A value of 0
means 0 percent confidence, and a value of 100
means 100 percent confidence. Documented below.
A timestamp that indicates when this finding record was created. Documented below.
The level of importance that is assigned to the resources that are associated with a finding. Documented below.
A finding's description. Documented below.
A timestamp that indicates when the potential security issue captured by a finding was first observed by the security findings product. Documented below.
The identifier for the solution-specific component that generated a finding. Documented below.
The product-specific identifier for a finding. Documented below.
A timestamp that indicates when the potential security issue captured by a finding was most recently observed by the security findings product. Documented below.
The text of a user-defined note that's added to a finding. Documented below.
The timestamp of when the note was updated. Documented below.
The principal that created a note. Documented below.
The Amazon Resource Name (ARN) for a third-party product that generated a finding in Security Hub. Documented below.
Provides the name of the product that generated the finding. For control-based findings, the product name is Security Hub. Documented below.
Provides the current state of a finding. Documented below.
The product-generated identifier for a related finding. Documented below.
The ARN for the product that generated a related finding. Documented below.
The Amazon Resource Name (ARN) of the application that is related to a finding. Documented below.
The name of the application that is related to a finding. Documented below.
Custom fields and values about the resource that a finding pertains to. Documented below.
The identifier for the given resource type. For AWS resources that are identified by Amazon Resource Names (ARNs), this is the ARN. For AWS resources that lack ARNs, this is the identifier as defined by the AWS service that created the resource. For non-AWS resources, this is a unique identifier that is associated with the resource. Documented below.
The partition in which the resource that the finding pertains to is located. A partition is a group of AWS Regions. Each AWS account is scoped to one partition. Documented below.
The AWS Region where the resource that a finding pertains to is located. Documented below.
A list of AWS tags associated with a resource at the time the finding was processed. Documented below.
The type of resource that the finding pertains to. Documented below.
The severity value of the finding. Documented below.
Provides a URL that links to a page about the current finding in the finding product. Documented below.
A finding's title. Documented below.
One or more finding types in the format of namespace/category/classifier that classify a finding. Documented below.
A timestamp that indicates when the finding record was most recently updated. Documented below.
A list of user-defined name and value string pairs added to a finding. Documented below.
Provides the veracity of a finding. Documented below.
Provides information about the status of the investigation into a finding. Documented below.