Skip to content

aws.guardduty.describe_malware_scans

Example SQL Queries

SELECT * FROM
aws.guardduty.describe_malware_scans
WHERE
"detector_id" = 'VALUE';

Description

Returns a list of malware scans. Each member account can view the malware scans for their own accounts. An administrator can view the malware scans for all the member accounts.

There might be regional differences because some data sources might not be available in all the Amazon Web Services Regions where GuardDuty is presently supported. For more information, see Regions and endpoints.

Table Definition

Column NameColumn Data Type
detector_id Required Input Column

The unique ID of the detector that the request is associated with.

VARCHAR
filter_criteria Input Column

Represents the criteria to be used in the filter for describing scan entries.

STRUCT(
"filter_criterion" STRUCT(
"criterion_key" VARCHAR,
"filter_condition" STRUCT(
"equals_value" VARCHAR,
"greater_than" BIGINT,
"less_than" BIGINT
)
)[]
)
Show child fields
filter_criteria.filter_criterion[]
Show child fields
filter_criteria.filter_criterion[].criterion_key

An enum value representing possible scan properties to match with given scan entries.

Replace the enum value CLUSTER_NAME with EKS_CLUSTER_NAME. CLUSTER_NAME has been deprecated.

filter_criteria.filter_criterion[].filter_condition

Contains information about the condition.

Show child fields
filter_criteria.filter_criterion[].filter_condition.equals_value

Represents an equal condition to be applied to a single field when querying for scan entries.

filter_criteria.filter_criterion[].filter_condition.greater_than

Represents a greater than condition to be applied to a single field when querying for scan entries.

filter_criteria.filter_criterion[].filter_condition.less_than

Represents a less than condition to be applied to a single field when querying for scan entries.

sort_criteria Input Column

Represents the criteria used for sorting scan entries. The attributeName is required and it must be scanStartTime.

STRUCT(
"attribute_name" VARCHAR,
"order_by" VARCHAR
)
Show child fields
sort_criteria.attribute_name

Represents the finding attribute, such as accountId, that sorts the findings.

sort_criteria.order_by

The order by which the sorted findings are to be displayed.

_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

_aws_region Input Column

The AWS region to use.

VARCHAR
account_id

The ID for the account that belongs to the scan.

VARCHAR
admin_detector_id

The unique detector ID of the administrator account that the request is associated with. Note that this value will be the same as the one used for DetectorId if the account is an administrator.

VARCHAR
attached_volumes

List of volumes that were attached to the original instance to be scanned.

STRUCT(
"volume_arn" VARCHAR,
"volume_type" VARCHAR,
"device_name" VARCHAR,
"volume_size_in_gb" BIGINT,
"encryption_type" VARCHAR,
"snapshot_arn" VARCHAR,
"kms_key_arn" VARCHAR
)[]
Show child fields
attached_volumes[]
Show child fields
attached_volumes[].device_name

The device name for the EBS volume.

attached_volumes[].encryption_type

EBS volume encryption type.

attached_volumes[].kms_key_arn

KMS key ARN used to encrypt the EBS volume.

attached_volumes[].snapshot_arn

Snapshot ARN of the EBS volume.

attached_volumes[].volume_arn

EBS volume ARN information.

attached_volumes[].volume_size_in_gb

EBS volume size in GB.

attached_volumes[].volume_type

The EBS volume type.

failure_reason

Represents the reason for FAILED scan status.

VARCHAR
file_count

Represents the number of files that were scanned.

BIGINT
resource_details

Represents the resources that were scanned in the scan entry.

STRUCT(
"instance_arn" VARCHAR
)
Show child fields
resource_details.instance_arn

Instance ARN that was scanned in the scan entry.

scan_end_time

The timestamp of when the scan was finished.

TIMESTAMP_S
scan_id

The unique scan ID associated with a scan entry.

VARCHAR
scan_result_details

Represents the result of the scan.

STRUCT(
"scan_result" VARCHAR
)
Show child fields
scan_result_details.scan_result

An enum value representing possible scan results.

scan_start_time

The timestamp of when the scan was triggered.

TIMESTAMP_S
scan_status

An enum value representing possible scan statuses.

VARCHAR
scan_type

Specifies the scan type that invoked the malware scan.

VARCHAR
total_bytes

Represents total bytes that were scanned.

BIGINT
trigger_details

Specifies the reason why the scan was initiated.

STRUCT(
"guard_duty_finding_id" VARCHAR,
"description" VARCHAR
)
Show child fields
trigger_details.description

The description of the scan trigger.

trigger_details.guard_duty_finding_id

The ID of the GuardDuty finding that triggered the malware scan.