LAP Registry

Amazon Detective Skill

amazonaws-com-detective

Provider: Amazon Web Services Version: 2018-10-26 Endpoints: 29 Updated: 2026-04-02

Raw .lap | Lean format | API JSON | Open in app

Endpoints

MethodPathDescription
PUT/invitation
POST/graph/datasources/getAccepts an invitation for the member account to contribute data to a behavior graph. This operation can only be called by an invited member account. The request provides the ARN o...
POST/membership/datasources/getGets data source package information for the behavior graph.
POST/graphGets information on the data source package history for an account.
POST/graph/membersCreates a new behavior graph for the calling account, and sets that account as the administrator account. This operation is called by the account that is enabling Detective. The o...
POST/graph/removalCreateMembers is used to send invitations to accounts. For the organization behavior graph, the Detective administrator account uses CreateMembers to enable organization accounts...
POST/graph/members/removalDisables the specified behavior graph and queues it to be deleted. This operation removes the behavior graph from each member account's list of behavior graphs. DeleteGraph can on...
POST/orgs/describeOrganizationConfigurationRemoves the specified member accounts from the behavior graph. The removed accounts no longer contribute data to the behavior graph. This operation can only be called by the admin...
POST/orgs/disableAdminAccountReturns information about the configuration for the organization behavior graph. Currently indicates whether to automatically enable new organization accounts as member accounts....
POST/membership/removalRemoves the Detective administrator account in the current Region. Deletes the organization behavior graph. Can only be called by the organization management account. Removing the...
POST/orgs/enableAdminAccountRemoves the member account from the specified behavior graph. This operation can only be called by an invited member account that has the ENABLED status. DisassociateMembership ca...
POST/investigations/getInvestigationDesignates the Detective administrator account for the organization in the current Region. If the account does not have Detective enabled, then enables Detective for that account...
POST/graph/members/getDetective investigations lets you investigate IAM users and IAM roles using indicators of compromise. An indicator of compromise (IOC) is an artifact observed in or on a network,...
POST/graph/datasources/listReturns the membership details for specified member accounts for a behavior graph.
POST/graphs/listLists data source packages in the behavior graph.
POST/investigations/listIndicatorsReturns the list of behavior graphs that the calling account is an administrator account of. This operation can only be called by an administrator account. Because an account can...
POST/investigations/listInvestigationsGets the indicators from an investigation. You can use the information from the indicators to determine if an IAM user and/or IAM role is involved in an unusual activity that coul...
POST/invitations/listDetective investigations lets you investigate IAM users and IAM roles using indicators of compromise. An indicator of compromise (IOC) is an artifact observed in or on a network,...
POST/graph/members/listRetrieves the list of open and accepted behavior graph invitations for the member account. This operation can only be called by an invited member account. Open invitations are inv...
POST/orgs/adminAccountslistRetrieves the list of member accounts for a behavior graph. For invited accounts, the results do not include member accounts that were removed from the behavior graph. For the org...
GET/tags/{ResourceArn}Returns information about the Detective administrator account for an organization. Can only be called by the organization management account.
POST/invitation/removalReturns the tag values that are assigned to a behavior graph.
POST/investigations/startInvestigationRejects an invitation to contribute the account data to a behavior graph. This operation must be called by an invited member account that has the INVITED status. RejectInvitation...
POST/graph/member/monitoringstateDetective investigations lets you investigate IAM users and IAM roles using indicators of compromise. An indicator of compromise (IOC) is an artifact observed in or on a network,...
POST/tags/{ResourceArn}Sends a request to enable data ingest for a member account that has a status of ACCEPTED_BUT_DISABLED. For valid member accounts, the status is updated as follows. If Detective en...
DELETE/tags/{ResourceArn}Applies tag values to a behavior graph.
POST/graph/datasources/updateRemoves tags from a behavior graph.
POST/investigations/updateInvestigationStateStarts a data source packages for the behavior graph.
POST/orgs/updateOrganizationConfigurationUpdates the state of an investigation.

Install as Skill

Use this API as a Claude Code skill for instant agent access.

CLI Install

lapsh skill-install amazonaws-com-detective

Downloads and installs to ~/.claude/skills/amazonaws-com-detective/

Manual Install

Download: Skill Bundle (JSON)

Or view: SKILL.md

Recent Versions (1)