Amazon Detective
Amazon Detective is a security investigation service that makes it easy to analyze, investigate, and quickly identify the root cause of potential security issues or suspicious activities. It automatically collects log data from your AWS resources and uses machine learning, statistical analysis, and graph theory to build interactive visualizations that help you conduct faster and more efficient security investigations.
Amazon Detective publishes 7 APIs on the APIs.io network, including Datasources API, Graph API, Investigations API, and 4 more. Tagged areas include Forensics, Investigation, and Security.
The Amazon Detective catalog on APIs.io includes 1 JSON-LD context and 2 Spectral governance rulesets.
Amazon Detective’s developer surface includes authentication, developer portal, documentation, support, developer console, signup flow, engineering blog, and 22 more developer resources.
Kin Score
APIs 7
Individual APIs this provider publishes, each with its own machine-readable definition.
Amazon Detective Datasources API
Data source package management operations
Amazon Detective Graph API
Behavior graph management operations
Amazon Detective Investigations API
Security investigation operations
Amazon Detective Invitations API
Invitation management for member accounts
Amazon Detective Members API
Member account management operations
Amazon Detective Organizations API
AWS Organizations integration operations
Amazon Detective Tags API
Resource tagging operations
Scroll for all 7
Postman Collections 1
Ready-to-run Postman collections for exercising this provider's APIs.
Amazon Detective
POSTMANOpen Collections 1
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
Amazon Detective
OPEN COLLECTIONArazzo Workflows 7
Multi-step API workflows described with the Arazzo specification.
Amazon Detective Archive a Resolved Investigation
Find a behavior graph's investigations, inspect one, and archive it when it has succeeded.
ARAZZOAmazon Detective Enable a Data Source Package
Start a data source package on a behavior graph and verify its ingest state.
ARAZZOAmazon Detective Onboard a Behavior Graph with Member Accounts
Create a new behavior graph and invite member accounts, then confirm their membership status.
ARAZZOAmazon Detective Member Accepts a Behavior Graph Invitation
List open invitations for a member account, accept one, and confirm enrollment.
ARAZZOAmazon Detective Run an Investigation and Collect Indicators
Start an investigation on an entity, poll until it completes, then list its indicators.
ARAZZOAmazon Detective Start Monitoring a Member Account
Invite a member account, enable data ingest for it, and confirm it is being monitored.
ARAZZOAmazon Detective Tag a Behavior Graph
Discover behavior graphs, apply tag values to one, and read the tags back.
ARAZZOScroll for all 7
Pricing Plans 1
Published pricing tiers and plan structures.
Rate Limits 1
Documented rate limits and quota policies.
Amazon Detective Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals for API financial operations.
Amazon Detective Finops
FINOPSFeatures 8
Notable capabilities this provider offers.
Behavior Graph Analysis
Automatically builds a behavior graph from log data using machine learning and graph theory to visualize security issues.
Security Investigations
Start and manage structured investigations on IAM users and roles with scoped time ranges and severity scoring.
Indicators of Compromise
Automatically identifies indicators including impossible travel, flagged IP addresses, new geolocations, new user agents, and TTP observations.
Multi-Account Support
Aggregate security data from multiple AWS accounts using an administrator account and member account model.
AWS Organizations Integration
Automatically enable new organization accounts as member accounts in the organization behavior graph.
Data Source Packages
Ingest security telemetry from CloudTrail, VPC Flow Logs, GuardDuty findings, EKS audit logs, and Active Directory audit logs.
Interactive Visualizations
Provides interactive graph visualizations in the AWS console to explore entity relationships and security events.
Investigation Severity Scoring
Assigns severity levels (Informational, Low, Medium, High, Critical) based on likelihood and impact of compromise indicators.
Scroll for all 8
Semantic Vocabularies 1
JSON-LD contexts and semantic vocabularies used across these APIs.
Amazon Detective Context
JSON-LDSpectral Rules 2
Spectral governance rulesets for linting and validating these APIs.
Amazon Detective API Rules
SPECTRALAmazon Detective API Rules
SPECTRALJSON Schema 54
Standalone JSON Schema definitions for this provider's data models.
AcceptInvitationRequest
JSON SCHEMAAccount
JSON SCHEMAAdministrator
JSON SCHEMABatchGetGraphMemberDatasourcesRequest
JSON SCHEMABatchGetGraphMemberDatasourcesResponse
JSON SCHEMABatchGetMembershipDatasourcesRequest
JSON SCHEMABatchGetMembershipDatasourcesResponse
JSON SCHEMACreateGraphRequest
JSON SCHEMACreateGraphResponse
JSON SCHEMACreateMembersRequest
JSON SCHEMACreateMembersResponse
JSON SCHEMADatasourcePackageIngestDetail
JSON SCHEMADeleteGraphRequest
JSON SCHEMADeleteMembersRequest
JSON SCHEMADeleteMembersResponse
JSON SCHEMADescribeOrganizationConfigurationRequest
JSON SCHEMADescribeOrganizationConfigurationResponse
JSON SCHEMADisassociateMembershipRequest
JSON SCHEMAEnableOrganizationAdminAccountRequest
JSON SCHEMAGetInvestigationRequest
JSON SCHEMAGetInvestigationResponse
JSON SCHEMAGetMembersRequest
JSON SCHEMAGetMembersResponse
JSON SCHEMAGraph
JSON SCHEMAIndicator
JSON SCHEMAInvestigationDetail
JSON SCHEMAListDatasourcePackagesRequest
JSON SCHEMAListDatasourcePackagesResponse
JSON SCHEMAListGraphsRequest
JSON SCHEMAListGraphsResponse
JSON SCHEMAListIndicatorsRequest
JSON SCHEMAListIndicatorsResponse
JSON SCHEMAListInvestigationsRequest
JSON SCHEMAListInvestigationsResponse
JSON SCHEMAListInvitationsRequest
JSON SCHEMAListInvitationsResponse
JSON SCHEMAListMembersRequest
JSON SCHEMAListMembersResponse
JSON SCHEMAListOrganizationAdminAccountsRequest
JSON SCHEMAListOrganizationAdminAccountsResponse
JSON SCHEMAListTagsForResourceResponse
JSON SCHEMAMemberDetail
JSON SCHEMAMembershipDatasources
JSON SCHEMARejectInvitationRequest
JSON SCHEMAStartInvestigationRequest
JSON SCHEMAStartInvestigationResponse
JSON SCHEMAStartMonitoringMemberRequest
JSON SCHEMATagResourceRequest
JSON SCHEMATimestampForCollection
JSON SCHEMAUnprocessedAccount
JSON SCHEMAUnprocessedGraph
JSON SCHEMAUpdateDatasourcePackagesRequest
JSON SCHEMAUpdateInvestigationStateRequest
JSON SCHEMAUpdateOrganizationConfigurationRequest
JSON SCHEMAScroll for all 54
JSON Structure 54
JSON Structure definitions describing this provider's data shapes.
Amazon Detective Accept Invitation Request Structure
JSON STRUCTUREAmazon Detective Account Structure
JSON STRUCTUREAmazon Detective Administrator Structure
JSON STRUCTUREAmazon Detective Create Graph Request Structure
JSON STRUCTUREAmazon Detective Create Graph Response Structure
JSON STRUCTUREAmazon Detective Create Members Request Structure
JSON STRUCTUREAmazon Detective Create Members Response Structure
JSON STRUCTUREAmazon Detective Delete Graph Request Structure
JSON STRUCTUREAmazon Detective Delete Members Request Structure
JSON STRUCTUREAmazon Detective Delete Members Response Structure
JSON STRUCTUREAmazon Detective Get Investigation Request Structure
JSON STRUCTUREAmazon Detective Get Investigation Response Structure
JSON STRUCTUREAmazon Detective Get Members Request Structure
JSON STRUCTUREAmazon Detective Get Members Response Structure
JSON STRUCTUREAmazon Detective Graph Structure
JSON STRUCTUREAmazon Detective Indicator Structure
JSON STRUCTUREAmazon Detective Investigation Detail Structure
JSON STRUCTUREAmazon Detective List Graphs Request Structure
JSON STRUCTUREAmazon Detective List Graphs Response Structure
JSON STRUCTUREAmazon Detective List Indicators Request Structure
JSON STRUCTUREAmazon Detective List Indicators Response Structure
JSON STRUCTUREAmazon Detective List Investigations Request Structure
JSON STRUCTUREAmazon Detective List Investigations Response Structure
JSON STRUCTUREAmazon Detective List Invitations Request Structure
JSON STRUCTUREAmazon Detective List Invitations Response Structure
JSON STRUCTUREAmazon Detective List Members Request Structure
JSON STRUCTUREAmazon Detective List Members Response Structure
JSON STRUCTUREAmazon Detective Member Detail Structure
JSON STRUCTUREAmazon Detective Membership Datasources Structure
JSON STRUCTUREAmazon Detective Reject Invitation Request Structure
JSON STRUCTUREAmazon Detective Start Investigation Request Structure
JSON STRUCTUREAmazon Detective Start Investigation Response Structure
JSON STRUCTUREAmazon Detective Tag Resource Request Structure
JSON STRUCTUREAmazon Detective Timestamp For Collection Structure
JSON STRUCTUREAmazon Detective Unprocessed Account Structure
JSON STRUCTUREAmazon Detective Unprocessed Graph Structure
JSON STRUCTUREScroll for all 54
Examples 54
Example request and response payloads for these APIs.
Scroll for all 54
Security Posture 4
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Agentic Access 1
Recommended x-agentic-access execution contracts for AI agents.
Use Cases 5
What developers build with this provider.
Security Incident Investigation
Rapidly investigate security incidents by analyzing entity behavior, network activity, and API call patterns across your AWS environment.
Threat Hunting
Proactively search for suspicious activity and potential threats using behavior analysis and machine learning across your AWS accounts.
Root Cause Analysis
Identify the root cause of security issues by exploring the relationships between resources, users, and events in a behavior graph.
Compliance Forensics
Collect and preserve forensic evidence for compliance investigations using structured investigations with defined scope and time ranges.
Multi-Account Security Operations
Centrally manage security investigations across an AWS Organization from a single administrator account.
Resources
Get Started 4
Portal, sign-up, and the first successful call
Documentation 1
Reference material describing how the API behaves
Agent Surfaces 1
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 9
Pagination, idempotency, versioning, errors, and events
Scroll for all 9
Build 2
SDKs, sample code, and the tooling you integrate with
Access & Security 4
Authentication, authorization, and security posture
Operate 4
Status, limits, changes, and where to get help
Commercial 2
Pricing, plans, and the legal terms of use
Company 2
The organization behind the API