GuardDuty Detector

GuardDuty Detector is the core resource in Amazon GuardDuty that represents an enabled instance of the threat detection service. It continuously monitors AWS accounts, workloads, and data for malicious or unauthorized activity. A detector must be created and enabled in each region where you want GuardDuty to analyze logs and generate findings.

aws.guardduty_detector

Fields

TitleIDTypeData TypeDescription
_keycorestring
account_idcorestring
coverage_statisticscorejsonRepresents the count aggregated by the statusCode and resourceType.
created_atcorestringThe timestamp of when the detector was created.
data_sourcescorejsonDescribes which data sources are enabled for the detector.
featurescorejsonDescribes the features that have been enabled for the detector.
finding_publishing_frequencycorestringThe publishing frequency of the finding.
service_rolecorestringThe GuardDuty service role.
statuscorestringThe detector status.
tagscorehstore
updated_atcorestringThe last-updated timestamp for the detector.