Skip to content

GuardDuty  >  Structures  >  RuleDetail

RuleDetail

Structure Class

RuleDetail dataclass

Contains the full details of a custom detection rule, including its detection logic.

Attributes

arn class-attribute instance-attribute
arn: str | None = None

The Amazon Resource Name (ARN) of the rule.

created_at class-attribute instance-attribute
created_at: datetime | None = None

The timestamp when the rule was created.

data_source class-attribute instance-attribute
data_source: str | None = None

The data source that the rule analyzes.

definition class-attribute instance-attribute
definition: RuleDefinition | None = None

The detection logic definition for the rule.

description class-attribute instance-attribute
description: str | None = None

A description of what the rule detects.

language class-attribute instance-attribute
language: str | None = None

The language used for the detection logic expression.

name class-attribute instance-attribute
name: str | None = None

The display name of the rule.

rule_id class-attribute instance-attribute
rule_id: str | None = None

The unique identifier for the rule.

schema class-attribute instance-attribute
schema: str | None = None

The schema version used by the rule definition.

service class-attribute instance-attribute
service: str | None = None

The Amazon Web Services service associated with the rule.

severity class-attribute instance-attribute
severity: str | None = None

The severity level assigned to findings generated by this rule.

tactic class-attribute instance-attribute
tactic: str | None = None

The MITRE ATT&CK tactic associated with the rule.

technique class-attribute instance-attribute
technique: str | None = None

The MITRE ATT&CK technique associated with the rule.

updated_at class-attribute instance-attribute
updated_at: datetime | None = None

The timestamp when the rule was last updated.