| Column Name | Column Data Type |
resource_arns Input Column
The ARNs (Amazon Resource Names) of the resources that were attacked. If you leave this blank, all applicable resources for this account will be included. | VARCHAR[] |
Show child fields- resource_arns[]
|
_aws_profile Input Column
The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role. | STRUCT( "type" VARCHAR, "name" VARCHAR, "account_id" VARCHAR, "via_profile_name" VARCHAR, "assumed_role_arn" VARCHAR, "organization" STRUCT( "account_name" VARCHAR, "id" VARCHAR, "tags" STRUCT( "key" VARCHAR, "value" VARCHAR )[], "master_account" STRUCT( "id" VARCHAR, "email" VARCHAR ), "parents" STRUCT( "type" VARCHAR, "id" VARCHAR, "name" VARCHAR, "tags" STRUCT( "key" VARCHAR, "value" VARCHAR )[] )[] ) ) |
Show child fields- _aws_profile.account_id
The AWS account id
- _aws_profile.assumed_role_arn
The ARN of the assumed role
- _aws_profile.name
The unique name of the profile.
- _aws_profile.organization
Information about this profile's membership in the AWS organization. Show child fields- _aws_profile.organization.account_name
The name of account speciifed by the organization
- _aws_profile.organization.id
The organization id
- _aws_profile.organization.master_account
Show child fields- _aws_profile.organization.master_account.email
The organization master account email address
- _aws_profile.organization.master_account.id
The organization master account id
- _aws_profile.organization.parents[]
Show child fields- _aws_profile.organization.parents[].id
The id of the parent
- _aws_profile.organization.parents[].name
The name of the parent
- _aws_profile.organization.parents[].tags[]
Show child fields- _aws_profile.organization.parents[].tags[].key
- _aws_profile.organization.parents[].tags[].value
- _aws_profile.organization.parents[].type
The type of parent can be an organization unit or a root
- _aws_profile.organization.tags[]
Show child fields- _aws_profile.organization.tags[].key
- _aws_profile.organization.tags[].value
- _aws_profile.type
The type of profile, either 'credentials' or 'assumed_role'
- _aws_profile.via_profile_name
This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.
|
_input_end_time Input Column
| STRUCT( "from_inclusive" TIMESTAMP_S, "to_exclusive" TIMESTAMP_S ) |
Show child fields- _input_end_time.from_inclusive
The start time, in Unix time in seconds.
- _input_end_time.to_exclusive
The end time, in Unix time in seconds.
|
_input_start_time Input Column
| STRUCT( "from_inclusive" TIMESTAMP_S, "to_exclusive" TIMESTAMP_S ) |
Show child fields- _input_start_time.from_inclusive
The start time, in Unix time in seconds.
- _input_start_time.to_exclusive
The end time, in Unix time in seconds.
|
attack_id
The unique identifier (ID) of the attack. | VARCHAR |
attack_vectors
The list of attacks for a specified time period. | STRUCT( "vector_type" VARCHAR )[] |
Show child fields- attack_vectors[]
Show child fields- attack_vectors[].vector_type
The attack type. Valid values: -
UDP_TRAFFIC -
UDP_FRAGMENT -
GENERIC_UDP_REFLECTION -
DNS_REFLECTION -
NTP_REFLECTION -
CHARGEN_REFLECTION -
SSDP_REFLECTION -
PORT_MAPPER -
RIP_REFLECTION -
SNMP_REFLECTION -
MSSQL_REFLECTION -
NET_BIOS_REFLECTION -
SYN_FLOOD -
ACK_FLOOD -
REQUEST_FLOOD -
HTTP_REFLECTION -
UDS_REFLECTION -
MEMCACHED_REFLECTION
|
end_time
The end time of the attack, in Unix time in seconds. | TIMESTAMP_S |
resource_arn
The ARN (Amazon Resource Name) of the resource that was attacked. | VARCHAR |
start_time
The start time of the attack, in Unix time in seconds. | TIMESTAMP_S |