Skip to content

Guardduty  >  Operations  >  create_threat_entity_set

create_threat_entity_set

Operation

create_threat_entity_set async

create_threat_entity_set(input: CreateThreatEntitySetInput, plugins: list[Plugin] | None = None) -> CreateThreatEntitySetOutput

Creates a new threat entity set. In a threat entity set, you can provide known malicious threat entities for your Amazon Web Services environment. GuardDuty generates findings based on the entries in the threat entity sets. Only users of the administrator account can manage entity sets, which automatically apply to member accounts.

Parameters:

Name Type Description Default
input CreateThreatEntitySetInput

An instance of CreateThreatEntitySetInput.

required
plugins list[Plugin] | None

A list of callables that modify the configuration dynamically. Changes made by these plugins only apply for the duration of the operation execution and will not affect any other operation invocations.

None

Returns:

Type Description
CreateThreatEntitySetOutput

An instance of CreateThreatEntitySetOutput.

Input

CreateThreatEntitySetInput dataclass

Dataclass for CreateThreatEntitySetInput structure.

Attributes

activate class-attribute instance-attribute
activate: bool | None = None

A boolean value that indicates whether GuardDuty should start using the uploaded threat entity set to generate findings.

client_token class-attribute instance-attribute
client_token: str | None = None

The idempotency token for the create request.

detector_id class-attribute instance-attribute
detector_id: str | None = None

The unique ID of the detector of the GuardDuty account for which you want to create a threat entity set.

To find the detectorId in the current Region, see the Settings page in the GuardDuty console, or run the ListDetectors API.

expected_bucket_owner class-attribute instance-attribute
expected_bucket_owner: str | None = None

The Amazon Web Services account ID that owns the Amazon S3 bucket specified in the location parameter.

format class-attribute instance-attribute
format: ThreatEntitySetFormat | None = None

The format of the file that contains the threat entity set.

location class-attribute instance-attribute
location: str | None = None

The URI of the file that contains the threat entity set. The format of the Location URL must be a valid Amazon S3 URL format. Invalid URL formats will result in an error, regardless of whether you activate the entity set or not. For more information about format of the location URLs, see Format of location URL under Step 2: Adding trusted or threat intelligence data in the Amazon GuardDuty User Guide.

name class-attribute instance-attribute
name: str | None = None

A user-friendly name to identify the threat entity set.

The name of your list can include lowercase letters, uppercase letters, numbers, dash (-), and underscore (_).

tags class-attribute instance-attribute
tags: dict[str, str] | None = None

The tags to be added to a new threat entity set resource.

Output

CreateThreatEntitySetOutput dataclass

Dataclass for CreateThreatEntitySetOutput structure.

Attributes

threat_entity_set_id class-attribute instance-attribute
threat_entity_set_id: str | None = None

The ID returned by GuardDuty after creation of the threat entity set resource.