Amazon Detective website screenshot

Amazon Detective

Amazon Detective is a security investigation service that makes it easy to analyze, investigate, and quickly identify the root cause of potential security issues or suspicious activities. It automatically collects log data from your AWS resources and uses machine learning, statistical analysis, and graph theory to build interactive visualizations that help you conduct faster and more efficient security investigations.

Amazon Detective publishes 7 APIs on the APIs.io network, including Datasources API, Graph API, Investigations API, and 4 more. Tagged areas include Forensics, Investigation, and Security.

The Amazon Detective catalog on APIs.io includes 1 JSON-LD context and 2 Spectral governance rulesets.

Amazon Detective’s developer surface includes authentication, developer portal, documentation, support, developer console, signup flow, engineering blog, and 22 more developer resources.

67.4/100 exemplar ▼ -6.7 Agent 44/100 agent ready Full breakdown ↓
scored 2026-07-28 · rubric v0.6
AccessFreemiumSelf serve⚡ Free to try
7 APIs 8 Features 5 Use Cases
ForensicsInvestigationSecurity

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-28 · rubric v0.6
Composite quality — 67.4/100 · exemplar
Contract Quality 17.6 / 25
Developer Ergonomics 9.1 / 20
Commercial Clarity 16.3 / 20
Operational Transparency 8.9 / 13
Governance 8.3 / 12
Discoverability 7.2 / 10
Agent readiness — 44/100 · agent ready
Machine-Readable Contract 18 / 18
Agentic Access Contract 10 / 10
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 8 / 8
Request/Response Examples 7 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/amazon-detective: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 7

Individual APIs this provider publishes, each with its own machine-readable definition.

Amazon Detective Datasources API

Data source package management operations

Amazon Detective Graph API

Behavior graph management operations

Amazon Detective Investigations API

Security investigation operations

Amazon Detective Invitations API

Invitation management for member accounts

Amazon Detective Members API

Member account management operations

Amazon Detective Organizations API

AWS Organizations integration operations

Amazon Detective Tags API

Resource tagging operations

Scroll for all 7

Postman Collections 1

Ready-to-run Postman collections for exercising this provider's APIs.

Open Collections 1

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

Amazon Detective

OPEN COLLECTION

Arazzo Workflows 7

Multi-step API workflows described with the Arazzo specification.

Amazon Detective Archive a Resolved Investigation

Find a behavior graph's investigations, inspect one, and archive it when it has succeeded.

ARAZZO

Amazon Detective Enable a Data Source Package

Start a data source package on a behavior graph and verify its ingest state.

ARAZZO

Amazon Detective Onboard a Behavior Graph with Member Accounts

Create a new behavior graph and invite member accounts, then confirm their membership status.

ARAZZO

Amazon Detective Member Accepts a Behavior Graph Invitation

List open invitations for a member account, accept one, and confirm enrollment.

ARAZZO

Amazon Detective Run an Investigation and Collect Indicators

Start an investigation on an entity, poll until it completes, then list its indicators.

ARAZZO

Amazon Detective Start Monitoring a Member Account

Invite a member account, enable data ingest for it, and confirm it is being monitored.

ARAZZO

Amazon Detective Tag a Behavior Graph

Discover behavior graphs, apply tag values to one, and read the tags back.

ARAZZO

Scroll for all 7

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Amazon Detective Rate Limits

5 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Features 8

Notable capabilities this provider offers.

Behavior Graph Analysis

Automatically builds a behavior graph from log data using machine learning and graph theory to visualize security issues.

Security Investigations

Start and manage structured investigations on IAM users and roles with scoped time ranges and severity scoring.

Indicators of Compromise

Automatically identifies indicators including impossible travel, flagged IP addresses, new geolocations, new user agents, and TTP observations.

Multi-Account Support

Aggregate security data from multiple AWS accounts using an administrator account and member account model.

AWS Organizations Integration

Automatically enable new organization accounts as member accounts in the organization behavior graph.

Data Source Packages

Ingest security telemetry from CloudTrail, VPC Flow Logs, GuardDuty findings, EKS audit logs, and Active Directory audit logs.

Interactive Visualizations

Provides interactive graph visualizations in the AWS console to explore entity relationships and security events.

Investigation Severity Scoring

Assigns severity levels (Informational, Low, Medium, High, Critical) based on likelihood and impact of compromise indicators.

Scroll for all 8

Semantic Vocabularies 1

JSON-LD contexts and semantic vocabularies used across these APIs.

Amazon Detective Context

53 classes · 55 properties

JSON-LD

Spectral Rules 2

Spectral governance rulesets for linting and validating these APIs.

Amazon Detective API Rules

5 rules · 4 warnings 1 info

SPECTRAL

Amazon Detective API Rules

46 rules · 18 errors 19 warnings 9 info

SPECTRAL

JSON Schema 54

Standalone JSON Schema definitions for this provider's data models.

AcceptInvitationRequest

1 properties

JSON SCHEMA

Account

2 properties

JSON SCHEMA

Administrator

3 properties

JSON SCHEMA

BatchGetGraphMemberDatasourcesRequest

2 properties

JSON SCHEMA

BatchGetMembershipDatasourcesRequest

1 properties

JSON SCHEMA

BatchGetMembershipDatasourcesResponse

2 properties

JSON SCHEMA

CreateGraphRequest

1 properties

JSON SCHEMA

CreateGraphResponse

1 properties

JSON SCHEMA

CreateMembersRequest

4 properties

JSON SCHEMA

CreateMembersResponse

2 properties

JSON SCHEMA

DatasourcePackageIngestDetail

2 properties

JSON SCHEMA

DeleteGraphRequest

1 properties

JSON SCHEMA

DeleteMembersRequest

2 properties

JSON SCHEMA

DeleteMembersResponse

2 properties

JSON SCHEMA

DisassociateMembershipRequest

1 properties

JSON SCHEMA

EnableOrganizationAdminAccountRequest

1 properties

JSON SCHEMA

GetInvestigationRequest

2 properties

JSON SCHEMA

GetInvestigationResponse

10 properties

JSON SCHEMA

GetMembersRequest

2 properties

JSON SCHEMA

GetMembersResponse

2 properties

JSON SCHEMA

Graph

2 properties

JSON SCHEMA

Indicator

2 properties

JSON SCHEMA

InvestigationDetail

7 properties

JSON SCHEMA

ListDatasourcePackagesRequest

3 properties

JSON SCHEMA

ListDatasourcePackagesResponse

2 properties

JSON SCHEMA

ListGraphsRequest

2 properties

JSON SCHEMA

ListGraphsResponse

2 properties

JSON SCHEMA

ListIndicatorsRequest

5 properties

JSON SCHEMA

ListIndicatorsResponse

4 properties

JSON SCHEMA

ListInvestigationsRequest

5 properties

JSON SCHEMA

ListInvestigationsResponse

2 properties

JSON SCHEMA

ListInvitationsRequest

2 properties

JSON SCHEMA

ListInvitationsResponse

2 properties

JSON SCHEMA

ListMembersRequest

3 properties

JSON SCHEMA

ListMembersResponse

2 properties

JSON SCHEMA

ListOrganizationAdminAccountsRequest

2 properties

JSON SCHEMA

ListOrganizationAdminAccountsResponse

2 properties

JSON SCHEMA

ListTagsForResourceResponse

1 properties

JSON SCHEMA

MemberDetail

12 properties

JSON SCHEMA

MembershipDatasources

3 properties

JSON SCHEMA

RejectInvitationRequest

1 properties

JSON SCHEMA

StartInvestigationRequest

4 properties

JSON SCHEMA

StartInvestigationResponse

1 properties

JSON SCHEMA

StartMonitoringMemberRequest

2 properties

JSON SCHEMA

TagResourceRequest

1 properties

JSON SCHEMA

TimestampForCollection

1 properties

JSON SCHEMA

UnprocessedAccount

2 properties

JSON SCHEMA

UnprocessedGraph

2 properties

JSON SCHEMA

UpdateDatasourcePackagesRequest

2 properties

JSON SCHEMA

UpdateInvestigationStateRequest

3 properties

JSON SCHEMA

Scroll for all 54

JSON Structure 54

JSON Structure definitions describing this provider's data shapes.

Amazon Detective Account Structure

2 properties

JSON STRUCTURE

Amazon Detective Administrator Structure

3 properties

JSON STRUCTURE

Amazon Detective Graph Structure

2 properties

JSON STRUCTURE

Amazon Detective Indicator Structure

2 properties

JSON STRUCTURE

Amazon Detective Member Detail Structure

12 properties

JSON STRUCTURE

Scroll for all 54

Examples 54

Example request and response payloads for these APIs.

Scroll for all 54

Security Posture 4

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Amazon Detective Authentication

apiKey · 1 scheme

SECURITY

Amazon Detective Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Amazon Detective Vulnerability Disclosure

security.txt · contact published

SECURITY

Amazon Detective Trust Center

PCI DSS, HIPAA, FedRAMP, GDPR, FIPS 140

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Amazon Detective Agentic Access

29 operations · 28 acting · 1 human-in-the-loop

29 operations · 28 acting

AGENTIC

Use Cases 5

What developers build with this provider.

Security Incident Investigation

Rapidly investigate security incidents by analyzing entity behavior, network activity, and API call patterns across your AWS environment.

Threat Hunting

Proactively search for suspicious activity and potential threats using behavior analysis and machine learning across your AWS accounts.

Root Cause Analysis

Identify the root cause of security issues by exploring the relationships between resources, users, and events in a behavior graph.

Compliance Forensics

Collect and preserve forensic evidence for compliance investigations using structured investigations with defined scope and time ranges.

Multi-Account Security Operations

Centrally manage security investigations across an AWS Organization from a single administrator account.

Resources

Get Started 4

Portal, sign-up, and the first successful call

Documentation 1

Reference material describing how the API behaves

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 9

Pagination, idempotency, versioning, errors, and events

Scroll for all 9

Build 2

SDKs, sample code, and the tooling you integrate with

Access & Security 4

Authentication, authorization, and security posture

Operate 4

Status, limits, changes, and where to get help

Commercial 2

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
name: Amazon Detective
description: Amazon Detective is a security investigation service that makes it easy to analyze, investigate, and quickly
  identify the root cause of potential security issues or suspicious activities. It automatically collects log data from your
  AWS resources and uses machine learning, statistical analysis, and graph theory to build interactive visualizations that
  help you conduct faster and more efficient security investigations.
accessModel:
  pricing: freemium
  onboarding: self-serve
  trial: false
  try_now: true
  public: false
  label: Freemium · Self-serve signup
  confidence: high
  source:
  - plans
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://a0.awsstatic.com/libra-css/images/logos/aws_logo_smile_1200x630.png
url: https://aws.amazon.com/detective/
created: '2024-01-15'
modified: '2026-05-19'
apis:
- aid: amazon-detective:amazon-detective-datasources-api
  name: Amazon Detective Datasources API
  description: Data source package management operations
  humanURL: https://aws.amazon.com/detective/
  baseURL: https://api.detective.amazonaws.com
  tags:
  - Datasources
  properties:
  - type: OpenAPI
    url: openapi/amazon-detective-datasources-api-openapi.yml
  - type: Documentation
    url: https://docs.aws.amazon.com/detective/
  - type: Pricing
    url: https://aws.amazon.com/detective/pricing/
  - type: GettingStarted
    url: https://aws.amazon.com/detective/getting-started/
  - type: FAQ
    url: https://aws.amazon.com/detective/faqs/
  - type: JSONSchema
    url: json-schema/amazon-detective-graph-schema.json
  - type: JSONSchema
    url: json-schema/amazon-detective-member-detail-schema.json
  - type: JSONSchema
    url: json-schema/amazon-detective-investigation-detail-schema.json
  - type: JSONSchema
    url: json-schema/amazon-detective-indicator-schema.json
  - type: JSONSchema
    url: json-schema/amazon-detective-administrator-schema.json
  - type: JSONStructure
    url: json-structure/amazon-detective-graph-structure.json
  - type: JSONStructure
    url: json-structure/amazon-detective-member-detail-structure.json
  - type: JSONStructure
    url: json-structure/amazon-detective-investigation-detail-structure.json
  - type: JSONLD
    url: json-ld/amazon-detective-context.jsonld
  - type: Examples
    url: examples/amazon-detective-graph-example.json
  - type: Examples
    url: examples/amazon-detective-member-detail-example.json
  - type: Examples
    url: examples/amazon-detective-investigation-detail-example.json
- aid: amazon-detective:amazon-detective-graph-api
  name: Amazon Detective Graph API
  description: Behavior graph management operations
  humanURL: https://aws.amazon.com/detective/
  baseURL: https://api.detective.amazonaws.com
  tags:
  - Graph
  properties:
  - type: OpenAPI
    url: openapi/amazon-detective-graph-api-openapi.yml
  - type: Documentation
    url: https://docs.aws.amazon.com/detective/
  - type: Pricing
    url: https://aws.amazon.com/detective/pricing/
  - type: GettingStarted
    url: https://aws.amazon.com/detective/getting-started/
  - type: FAQ
    url: https://aws.amazon.com/detective/faqs/
  - type: JSONSchema
    url: json-schema/amazon-detective-graph-schema.json
  - type: JSONSchema
    url: json-schema/amazon-detective-member-detail-schema.json
  - type: JSONSchema
    url: json-schema/amazon-detective-investigation-detail-schema.json
  - type: JSONSchema
    url: json-schema/amazon-detective-indicator-schema.json
  - type: JSONSchema
    url: json-schema/amazon-detective-administrator-schema.json
  - type: JSONStructure
    url: json-structure/amazon-detective-graph-structure.json
  - type: JSONStructure
    url: json-structure/amazon-detective-member-detail-structure.json
  - type: JSONStructure
    url: json-structure/amazon-detective-investigation-detail-structure.json
  - type: JSONLD
    url: json-ld/amazon-detective-context.jsonld
  - type: Examples
    url: examples/amazon-detective-graph-example.json
  - type: Examples
    url: examples/amazon-detective-member-detail-example.json
  - type: Examples
    url: examples/amazon-detective-investigation-detail-example.json
- aid: amazon-detective:amazon-detective-investigations-api
  name: Amazon Detective Investigations API
  description: Security investigation operations
  humanURL: https://aws.amazon.com/detective/
  baseURL: https://api.detective.amazonaws.com
  tags:
  - Investigations
  properties:
  - type: OpenAPI
    url: openapi/amazon-detective-investigations-api-openapi.yml
  - type: Documentation
    url: https://docs.aws.amazon.com/detective/
  - type: Pricing
    url: https://aws.amazon.com/detective/pricing/
  - type: GettingStarted
    url: https://aws.amazon.com/detective/getting-started/
  - type: FAQ
    url: https://aws.amazon.com/detective/faqs/
  - type: JSONSchema
    url: json-schema/amazon-detective-graph-schema.json
  - type: JSONSchema
    url: json-schema/amazon-detective-member-detail-schema.json
  - type: JSONSchema
    url: json-schema/amazon-detective-investigation-detail-schema.json
  - type: JSONSchema
    url: json-schema/amazon-detective-indicator-schema.json
  - type: JSONSchema
    url: json-schema/amazon-detective-administrator-schema.json
  - type: JSONStructure
    url: json-structure/amazon-detective-graph-structure.json
  - type: JSONStructure
    url: json-structure/amazon-detective-member-detail-structure.json
  - type: JSONStructure
    url: json-structure/amazon-detective-investigation-detail-structure.json
  - type: JSONLD
    url: json-ld/amazon-detective-context.jsonld
  - type: Examples
    url: examples/amazon-detective-graph-example.json
  - type: Examples
    url: examples/amazon-detective-member-detail-example.json
  - type: Examples
    url: examples/amazon-detective-investigation-detail-example.json
- aid: amazon-detective:amazon-detective-invitations-api
  name: Amazon Detective Invitations API
  description: Invitation management for member accounts
  humanURL: https://aws.amazon.com/detective/
  baseURL: https://api.detective.amazonaws.com
  tags:
  - Invitations
  properties:
  - type: OpenAPI
    url: openapi/amazon-detective-invitations-api-openapi.yml
  - type: Documentation
    url: https://docs.aws.amazon.com/detective/
  - type: Pricing
    url: https://aws.amazon.com/detective/pricing/
  - type: GettingStarted
    url: https://aws.amazon.com/detective/getting-started/
  - type: FAQ
    url: https://aws.amazon.com/detective/faqs/
  - type: JSONSchema
    url: json-schema/amazon-detective-graph-schema.json
  - type: JSONSchema
    url: json-schema/amazon-detective-member-detail-schema.json
  - type: JSONSchema
    url: json-schema/amazon-detective-investigation-detail-schema.json
  - type: JSONSchema
    url: json-schema/amazon-detective-indicator-schema.json
  - type: JSONSchema
    url: json-schema/amazon-detective-administrator-schema.json
  - type: JSONStructure
    url: json-structure/amazon-detective-graph-structure.json
  - type: JSONStructure
    url: json-structure/amazon-detective-member-detail-structure.json
  - type: JSONStructure
    url: json-structure/amazon-detective-investigation-detail-structure.json
  - type: JSONLD
    url: json-ld/amazon-detective-context.jsonld
  - type: Examples
    url: examples/amazon-detective-graph-example.json
  - type: Examples
    url: examples/amazon-detective-member-detail-example.json
  - type: Examples
    url: examples/amazon-detective-investigation-detail-example.json
- aid: amazon-detective:amazon-detective-members-api
  name: Amazon Detective Members API
  description: Member account management operations
  humanURL: https://aws.amazon.com/detective/
  baseURL: https://api.detective.amazonaws.com
  tags:
  - Members
  properties:
  - type: OpenAPI
    url: openapi/amazon-detective-members-api-openapi.yml
  - type: Documentation
    url: https://docs.aws.amazon.com/detective/
  - type: Pricing
    url: https://aws.amazon.com/detective/pricing/
  - type: GettingStarted
    url: https://aws.amazon.com/detective/getting-started/
  - type: FAQ
    url: https://aws.amazon.com/detective/faqs/
  - type: JSONSchema
    url: json-schema/amazon-detective-graph-schema.json
  - type: JSONSchema
    url: json-schema/amazon-detective-member-detail-schema.json
  - type: JSONSchema
    url: json-schema/amazon-detective-investigation-detail-schema.json
  - type: JSONSchema
    url: json-schema/amazon-detective-indicator-schema.json
  - type: JSONSchema
    url: json-schema/amazon-detective-administrator-schema.json
  - type: JSONStructure
    url: json-structure/amazon-detective-graph-structure.json
  - type: JSONStructure
    url: json-structure/amazon-detective-member-detail-structure.json
  - type: JSONStructure
    url: json-structure/amazon-detective-investigation-detail-structure.json
  - type: JSONLD
    url: json-ld/amazon-detective-context.jsonld
  - type: Examples
    url: examples/amazon-detective-graph-example.json
  - type: Examples
    url: examples/amazon-detective-member-detail-example.json
  - type: Examples
    url: examples/amazon-detective-investigation-detail-example.json
- aid: amazon-detective:amazon-detective-organizations-api
  name: Amazon Detective Organizations API
  description: AWS Organizations integration operations
  humanURL: https://aws.amazon.com/detective/
  baseURL: https://api.detective.amazonaws.com
  tags:
  - Organizations
  properties:
  - type: OpenAPI
    url: openapi/amazon-detective-organizations-api-openapi.yml
  - type: Documentation
    url: https://docs.aws.amazon.com/detective/
  - type: Pricing
    url: https://aws.amazon.com/detective/pricing/
  - type: GettingStarted
    url: https://aws.amazon.com/detective/getting-started/
  - type: FAQ
    url: https://aws.amazon.com/detective/faqs/
  - type: JSONSchema
    url: json-schema/amazon-detective-graph-schema.json
  - type: JSONSchema
    url: json-schema/amazon-detective-member-detail-schema.json
  - type: JSONSchema
    url: json-schema/amazon-detective-investigation-detail-schema.json
  - type: JSONSchema
    url: json-schema/amazon-detective-indicator-schema.json
  - type: JSONSchema
    url: json-schema/amazon-detective-administrator-schema.json
  - type: JSONStructure
    url: json-structure/amazon-detective-graph-structure.json
  - type: JSONStructure
    url: json-structure/amazon-detective-member-detail-structure.json
  - type: JSONStructure
    url: json-structure/amazon-detective-investigation-detail-structure.json
  - type: JSONLD
    url: json-ld/amazon-detective-context.jsonld
  - type: Examples
    url: examples/amazon-detective-graph-example.json
  - type: Examples
    url: examples/amazon-detective-member-detail-example.json
  - type: Examples
    url: examples/amazon-detective-investigation-detail-example.json
- aid: amazon-detective:amazon-detective-tags-api
  name: Amazon Detective Tags API
  description: Resource tagging operations
  humanURL: https://aws.amazon.com/detective/
  baseURL: https://api.detective.amazonaws.com
  tags:
  - Tags
  properties:
  - type: OpenAPI
    url: openapi/amazon-detective-tags-api-openapi.yml
  - type: Documentation
    url: https://docs.aws.amazon.com/detective/
  - type: Pricing
    url: https://aws.amazon.com/detective/pricing/
  - type: GettingStarted
    url: https://aws.amazon.com/detective/getting-started/
  - type: FAQ
    url: https://aws.amazon.com/detective/faqs/
  - type: JSONSchema
    url: json-schema/amazon-detective-graph-schema.json
  - type: JSONSchema
    url: json-schema/amazon-detective-member-detail-schema.json
  - type: JSONSchema
    url: json-schema/amazon-detective-investigation-detail-schema.json
  - type: JSONSchema
    url: json-schema/amazon-detective-indicator-schema.json
  - type: JSONSchema
    url: json-schema/amazon-detective-administrator-schema.json
  - type: JSONStructure
    url: json-structure/amazon-detective-graph-structure.json
  - type: JSONStructure
    url: json-structure/amazon-detective-member-detail-structure.json
  - type: JSONStructure
    url: json-structure/amazon-detective-investigation-detail-structure.json
  - type: JSONLD
    url: json-ld/amazon-detective-context.jsonld
  - type: Examples
    url: examples/amazon-detective-graph-example.json
  - type: Examples
    url: examples/amazon-detective-member-detail-example.json
  - type: Examples
    url: examples/amazon-detective-investigation-detail-example.json
common:
- type: AgenticAccess
  url: agentic-access/amazon-detective-agentic-access.yml
- type: TrustCenter
  url: security/amazon-detective-trust-center.yml
- type: VulnerabilityDisclosure
  url: security/amazon-detective-vulnerability-disclosure.yml
- type: DomainSecurity
  url: security/amazon-detective-domain-security.yml
- type: Authentication
  url: authentication/amazon-detective-authentication.yml
- type: PostmanWorkspace
  url: https://www.postman.com/kinlaneapi/amazon-detective/overview
- type: Arazzo
  url: arazzo/amazon-detective-archive-resolved-investigation-workflow.yml
  name: Amazon Detective Archive a Resolved Investigation
- type: Arazzo
  url: arazzo/amazon-detective-enable-datasource-package-workflow.yml
  name: Amazon Detective Enable a Data Source Package
- type: Arazzo
  url: arazzo/amazon-detective-graph-onboard-members-workflow.yml
  name: Amazon Detective Onboard a Behavior Graph with Member Accounts
- type: Arazzo
  url: arazzo/amazon-detective-member-accept-invitation-workflow.yml
  name: Amazon Detective Member Accepts a Behavior Graph Invitation
- type: Arazzo
  url: arazzo/amazon-detective-run-investigation-workflow.yml
  name: Amazon Detective Run an Investigation and Collect Indicators
- type: Arazzo
  url: arazzo/amazon-detective-start-monitoring-member-workflow.yml
  name: Amazon Detective Start Monitoring a Member Account
- type: Arazzo
  url: arazzo/amazon-detective-tag-behavior-graph-workflow.yml
  name: Amazon Detective Tag a Behavior Graph
- type: Portal
  url: https://aws.amazon.com/
- type: Website
  url: https://aws.amazon.com/detective/
- type: Documentation
  url: https://docs.aws.amazon.com/detective/
- type: TermsOfService
  url: https://aws.amazon.com/service-terms/
- type: PrivacyPolicy
  url: https://aws.amazon.com/privacy/
- type: Support
  url: https://aws.amazon.com/premiumsupport/
- type: GitHubOrganization
  url: https://github.com/aws
- type: Console
  url: https://console.aws.amazon.com/detective/
- type: Signup
  url: https://signin.aws.amazon.com/signup?request_type=register
- type: Login
  url: https://aws.amazon.com/console/
- type: StatusPage
  url: https://health.aws.amazon.com/health/status
- type: Contact
  url: https://aws.amazon.com/contact-us/
- type: Blog
  url: https://aws.amazon.com/blogs/security/tag/amazon-detective/
- type: ReleaseNotes
  url: https://docs.aws.amazon.com/detective/latest/userguide/release-notes.html
- type: SpectralRules
  url: rules/amazon-detective-spectral-rules.yml
- type: Vocabulary
  url: vocabulary/amazon-detective-vocabulary.yaml
- type: Features
  data:
  - name: Behavior Graph Analysis
    description: Automatically builds a behavior graph from log data using machine learning and graph theory to visualize
      security issues.
  - name: Security Investigations
    description: Start and manage structured investigations on IAM users and roles with scoped time ranges and severity scoring.
  - name: Indicators of Compromise
    description: Automatically identifies indicators including impossible travel, flagged IP addresses, new geolocations,
      new user agents, and TTP observations.
  - name: Multi-Account Support
    description: Aggregate security data from multiple AWS accounts using an administrator account and member account model.
  - name: AWS Organizations Integration
    description: Automatically enable new organization accounts as member accounts in the organization behavior graph.
  - name: Data Source Packages
    description: Ingest security telemetry from CloudTrail, VPC Flow Logs, GuardDuty findings, EKS audit logs, and Active
      Directory audit logs.
  - name: Interactive Visualizations
    description: Provides interactive graph visualizations in the AWS console to explore entity relationships and security
      events.
  - name: Investigation Severity Scoring
    description: Assigns severity levels (Informational, Low, Medium, High, Critical) based on likelihood and impact of compromise
      indicators.
- type: UseCases
  data:
  - name: Security Incident Investigation
    description: Rapidly investigate security incidents by analyzing entity behavior, network activity, and API call patterns
      across your AWS environment.
  - name: Threat Hunting
    description: Proactively search for suspicious activity and potential threats using behavior analysis and machine learning
      across your AWS accounts.
  - name: Root Cause Analysis
    description: Identify the root cause of security issues by exploring the relationships between resources, users, and events
      in a behavior graph.
  - name: Compliance Forensics
    description: Collect and preserve forensic evidence for compliance investigations using structured investigations with
      defined scope and time ranges.
  - name: Multi-Account Security Operations
    description: Centrally manage security investigations across an AWS Organization from a single administrator account.
- type: Integrations
  data:
  - name: Amazon GuardDuty
    description: Automatically ingests GuardDuty findings into the behavior graph for deeper investigation context.
  - name: AWS CloudTrail
    description: Ingests CloudTrail API call logs to track user and service activity across your AWS environment.
  - name: Amazon VPC Flow Logs
    description: Analyzes VPC flow logs to identify network communication patterns and anomalies.
  - name: Amazon EKS
    description: Optionally ingests EKS audit logs to monitor Kubernetes API server activity.
  - name: AWS Organizations
    description: Integrates with AWS Organizations to manage multi-account behavior graphs and auto-enable new accounts.
  - name: AWS Security Hub
    description: Surfaces Detective investigation context within Security Hub for consolidated security findings.
- type: Integrations
  url: https://aws.amazon.com/marketplace
integrations:
- name: Sign in
- name: Agent Mode
- name: Why AWS Marketplace?
- name: Get started in AWS Marketplace
- name: Industry
- name: Resources
- name: Become a Channel Partner
- name: Sell in AWS Marketplace
- name: Manage Your Account
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
  url: https://apievangelist.com
tags:
- AWS
- Forensics
- Investigation
- Security