Detective investigations lets you investigate IAM users and IAM roles using indicators of compromise. An indicator of compromise (IOC) is an artifact observed in or on a network, system, or environment that can (with a high level of confidence) identify malicious activity or a security incident. start_investigation
initiates an investigation on an entity in a behavior graph.
See https://www.paws-r-sdk.com/docs/detective_start_investigation/ for full documentation.
detective_start_investigation(
GraphArn,
EntityArn,
ScopeStartTime,
ScopeEndTime
)
[required] The Amazon Resource Name (ARN) of the behavior graph.
[required] The unique Amazon Resource Name (ARN) of the IAM user and IAM role.
[required] The data and time when the investigation began. The value is an UTC
ISO8601 formatted string. For example, 2021-08-18T16:35:56.284Z
.
[required] The data and time when the investigation ended. The value is an UTC
ISO8601 formatted string. For example, 2021-08-18T16:35:56.284Z
.