Resource Type: AWS > GuardDuty > ThreatIntelSet
The ThreatIntelSet resource type represents a list of known malicious IP addresses or domains. This resource is used by GuardDuty to generate findings based on threats that are detected in your AWS environment.
Resource Context
ThreatIntelSet is a part of the GuardDuty service.
Each ThreatIntelSet lives under a Detector.
Controls
The primary controls for AWS > GuardDuty > ThreatIntelSet are:
Quick Actions
- Delete from AWS
- Set Tags
- Skip alarm for Active control
- Skip alarm for Active control [90 days]
- Skip alarm for Approved control
- Skip alarm for Approved control [90 days]
- Skip alarm for Tags control
- Skip alarm for Tags control [90 days]
Category
In Your Workspace
- Controls by Resource Type report
- Policy Settings by Resource Type report
- Resources by Resource Type report
Developers
- tmod:@turbot/aws-guardduty#/resource/types/threatIntelSet
- tmod:@turbot/turbot#/resource/categories/security
- turbot graphql resource --id "tmod:@turbot/aws-guardduty#/resource/types/threatIntelSet"
Get Resource- select * from guardrails_resource where resource_type_uri = 'tmod:@turbot/aws-guardduty#/resource/types/threatIntelSet';
- select * from guardrails_policy_setting where filter = 'resourceTypeId:"tmod:@turbot/aws-guardduty#/resource/types/threatIntelSet"';
- select * from guardrails_notification where resource_type_uri = 'tmod:@turbot/aws-guardduty#/resource/types/threatIntelSet' and notification_type in ('resource_updated', 'resource_created');
Get ResourceGet Policy Settings (By Resource ID)Get Resource Notification
Resource Type URI
Category URI
GraphQL
CLI
Steampipe Query