Class: Aws::GuardDuty::Types::RuntimeContext

Inherits:
Struct
  • Object
show all
Defined in:
gems/aws-sdk-guardduty/lib/aws-sdk-guardduty/types.rb

Overview

Additional information about the suspicious activity.

Constant Summary collapse

SENSITIVE =
[]

Instance Attribute Summary collapse

Instance Attribute Details

#address_family ⇒ String

Represents the communication protocol associated with the address. For example, the address family AF_INET is used for IP version of 4 protocol.

Returns:

  • (String)


12016
12017
12018
12019
12020
12021
12022
12023
12024
12025
12026
12027
12028
12029
12030
12031
12032
12033
12034
12035
12036
12037
12038
12039
12040
12041
12042
12043
12044
12045
12046
12047
# File 'gems/aws-sdk-guardduty/lib/aws-sdk-guardduty/types.rb', line 12016

class RuntimeContext < Struct.new(
  :modifying_process,
  :modified_at,
  :script_path,
  :library_path,
  :ld_preload_value,
  :socket_path,
  :runc_binary_path,
  :release_agent_path,
  :mount_source,
  :mount_target,
  :file_system_type,
  :flags,
  :module_name,
  :module_file_path,
  :module_sha_256,
  :shell_history_file_path,
  :target_process,
  :address_family,
  :iana_protocol_number,
  :memory_regions,
  :tool_name,
  :tool_category,
  :service_name,
  :command_line_example,
  :threat_file_path,
  :file_operation,
  :file_path,
  :related_file_paths)
  SENSITIVE = []
  include Aws::Structure
end

#command_line_example ⇒ String

Example of the command line involved in the suspicious activity.

Returns:

  • (String)


12016
12017
12018
12019
12020
12021
12022
12023
12024
12025
12026
12027
12028
12029
12030
12031
12032
12033
12034
12035
12036
12037
12038
12039
12040
12041
12042
12043
12044
12045
12046
12047
# File 'gems/aws-sdk-guardduty/lib/aws-sdk-guardduty/types.rb', line 12016

class RuntimeContext < Struct.new(
  :modifying_process,
  :modified_at,
  :script_path,
  :library_path,
  :ld_preload_value,
  :socket_path,
  :runc_binary_path,
  :release_agent_path,
  :mount_source,
  :mount_target,
  :file_system_type,
  :flags,
  :module_name,
  :module_file_path,
  :module_sha_256,
  :shell_history_file_path,
  :target_process,
  :address_family,
  :iana_protocol_number,
  :memory_regions,
  :tool_name,
  :tool_category,
  :service_name,
  :command_line_example,
  :threat_file_path,
  :file_operation,
  :file_path,
  :related_file_paths)
  SENSITIVE = []
  include Aws::Structure
end

#file_operation ⇒ String

Represents the type of file operation that triggered the finding, such as Write, Delete, Rename, Link, or Symlink.

Returns:

  • (String)


12016
12017
12018
12019
12020
12021
12022
12023
12024
12025
12026
12027
12028
12029
12030
12031
12032
12033
12034
12035
12036
12037
12038
12039
12040
12041
12042
12043
12044
12045
12046
12047
# File 'gems/aws-sdk-guardduty/lib/aws-sdk-guardduty/types.rb', line 12016

class RuntimeContext < Struct.new(
  :modifying_process,
  :modified_at,
  :script_path,
  :library_path,
  :ld_preload_value,
  :socket_path,
  :runc_binary_path,
  :release_agent_path,
  :mount_source,
  :mount_target,
  :file_system_type,
  :flags,
  :module_name,
  :module_file_path,
  :module_sha_256,
  :shell_history_file_path,
  :target_process,
  :address_family,
  :iana_protocol_number,
  :memory_regions,
  :tool_name,
  :tool_category,
  :service_name,
  :command_line_example,
  :threat_file_path,
  :file_operation,
  :file_path,
  :related_file_paths)
  SENSITIVE = []
  include Aws::Structure
end

#file_path ⇒ String

The path of the sensitive file that was modified. Modification includes write, delete, rename, link, or symlink operations. This field is indexed for filtering.

Returns:

  • (String)


12016
12017
12018
12019
12020
12021
12022
12023
12024
12025
12026
12027
12028
12029
12030
12031
12032
12033
12034
12035
12036
12037
12038
12039
12040
12041
12042
12043
12044
12045
12046
12047
# File 'gems/aws-sdk-guardduty/lib/aws-sdk-guardduty/types.rb', line 12016

class RuntimeContext < Struct.new(
  :modifying_process,
  :modified_at,
  :script_path,
  :library_path,
  :ld_preload_value,
  :socket_path,
  :runc_binary_path,
  :release_agent_path,
  :mount_source,
  :mount_target,
  :file_system_type,
  :flags,
  :module_name,
  :module_file_path,
  :module_sha_256,
  :shell_history_file_path,
  :target_process,
  :address_family,
  :iana_protocol_number,
  :memory_regions,
  :tool_name,
  :tool_category,
  :service_name,
  :command_line_example,
  :threat_file_path,
  :file_operation,
  :file_path,
  :related_file_paths)
  SENSITIVE = []
  include Aws::Structure
end

#file_system_type ⇒ String

Represents the type of mounted fileSystem.

Returns:

  • (String)


12016
12017
12018
12019
12020
12021
12022
12023
12024
12025
12026
12027
12028
12029
12030
12031
12032
12033
12034
12035
12036
12037
12038
12039
12040
12041
12042
12043
12044
12045
12046
12047
# File 'gems/aws-sdk-guardduty/lib/aws-sdk-guardduty/types.rb', line 12016

class RuntimeContext < Struct.new(
  :modifying_process,
  :modified_at,
  :script_path,
  :library_path,
  :ld_preload_value,
  :socket_path,
  :runc_binary_path,
  :release_agent_path,
  :mount_source,
  :mount_target,
  :file_system_type,
  :flags,
  :module_name,
  :module_file_path,
  :module_sha_256,
  :shell_history_file_path,
  :target_process,
  :address_family,
  :iana_protocol_number,
  :memory_regions,
  :tool_name,
  :tool_category,
  :service_name,
  :command_line_example,
  :threat_file_path,
  :file_operation,
  :file_path,
  :related_file_paths)
  SENSITIVE = []
  include Aws::Structure
end

#flags ⇒ Array<String>

Represents options that control the behavior of a runtime operation or action. For example, a filesystem mount operation may contain a read-only flag.

Returns:

  • (Array<String>)


12016
12017
12018
12019
12020
12021
12022
12023
12024
12025
12026
12027
12028
12029
12030
12031
12032
12033
12034
12035
12036
12037
12038
12039
12040
12041
12042
12043
12044
12045
12046
12047
# File 'gems/aws-sdk-guardduty/lib/aws-sdk-guardduty/types.rb', line 12016

class RuntimeContext < Struct.new(
  :modifying_process,
  :modified_at,
  :script_path,
  :library_path,
  :ld_preload_value,
  :socket_path,
  :runc_binary_path,
  :release_agent_path,
  :mount_source,
  :mount_target,
  :file_system_type,
  :flags,
  :module_name,
  :module_file_path,
  :module_sha_256,
  :shell_history_file_path,
  :target_process,
  :address_family,
  :iana_protocol_number,
  :memory_regions,
  :tool_name,
  :tool_category,
  :service_name,
  :command_line_example,
  :threat_file_path,
  :file_operation,
  :file_path,
  :related_file_paths)
  SENSITIVE = []
  include Aws::Structure
end

#iana_protocol_number ⇒ Integer

Specifies a particular protocol within the address family. Usually there is a single protocol in address families. For example, the address family AF_INET only has the IP protocol.

Returns:

  • (Integer)


12016
12017
12018
12019
12020
12021
12022
12023
12024
12025
12026
12027
12028
12029
12030
12031
12032
12033
12034
12035
12036
12037
12038
12039
12040
12041
12042
12043
12044
12045
12046
12047
# File 'gems/aws-sdk-guardduty/lib/aws-sdk-guardduty/types.rb', line 12016

class RuntimeContext < Struct.new(
  :modifying_process,
  :modified_at,
  :script_path,
  :library_path,
  :ld_preload_value,
  :socket_path,
  :runc_binary_path,
  :release_agent_path,
  :mount_source,
  :mount_target,
  :file_system_type,
  :flags,
  :module_name,
  :module_file_path,
  :module_sha_256,
  :shell_history_file_path,
  :target_process,
  :address_family,
  :iana_protocol_number,
  :memory_regions,
  :tool_name,
  :tool_category,
  :service_name,
  :command_line_example,
  :threat_file_path,
  :file_operation,
  :file_path,
  :related_file_paths)
  SENSITIVE = []
  include Aws::Structure
end

#ld_preload_value ⇒ String

The value of the LD_PRELOAD environment variable.

Returns:

  • (String)


12016
12017
12018
12019
12020
12021
12022
12023
12024
12025
12026
12027
12028
12029
12030
12031
12032
12033
12034
12035
12036
12037
12038
12039
12040
12041
12042
12043
12044
12045
12046
12047
# File 'gems/aws-sdk-guardduty/lib/aws-sdk-guardduty/types.rb', line 12016

class RuntimeContext < Struct.new(
  :modifying_process,
  :modified_at,
  :script_path,
  :library_path,
  :ld_preload_value,
  :socket_path,
  :runc_binary_path,
  :release_agent_path,
  :mount_source,
  :mount_target,
  :file_system_type,
  :flags,
  :module_name,
  :module_file_path,
  :module_sha_256,
  :shell_history_file_path,
  :target_process,
  :address_family,
  :iana_protocol_number,
  :memory_regions,
  :tool_name,
  :tool_category,
  :service_name,
  :command_line_example,
  :threat_file_path,
  :file_operation,
  :file_path,
  :related_file_paths)
  SENSITIVE = []
  include Aws::Structure
end

#library_path ⇒ String

The path to the new library that was loaded.

Returns:

  • (String)


12016
12017
12018
12019
12020
12021
12022
12023
12024
12025
12026
12027
12028
12029
12030
12031
12032
12033
12034
12035
12036
12037
12038
12039
12040
12041
12042
12043
12044
12045
12046
12047
# File 'gems/aws-sdk-guardduty/lib/aws-sdk-guardduty/types.rb', line 12016

class RuntimeContext < Struct.new(
  :modifying_process,
  :modified_at,
  :script_path,
  :library_path,
  :ld_preload_value,
  :socket_path,
  :runc_binary_path,
  :release_agent_path,
  :mount_source,
  :mount_target,
  :file_system_type,
  :flags,
  :module_name,
  :module_file_path,
  :module_sha_256,
  :shell_history_file_path,
  :target_process,
  :address_family,
  :iana_protocol_number,
  :memory_regions,
  :tool_name,
  :tool_category,
  :service_name,
  :command_line_example,
  :threat_file_path,
  :file_operation,
  :file_path,
  :related_file_paths)
  SENSITIVE = []
  include Aws::Structure
end

#memory_regions ⇒ Array<String>

Specifies the Region of a process's address space such as stack and heap.

Returns:

  • (Array<String>)


12016
12017
12018
12019
12020
12021
12022
12023
12024
12025
12026
12027
12028
12029
12030
12031
12032
12033
12034
12035
12036
12037
12038
12039
12040
12041
12042
12043
12044
12045
12046
12047
# File 'gems/aws-sdk-guardduty/lib/aws-sdk-guardduty/types.rb', line 12016

class RuntimeContext < Struct.new(
  :modifying_process,
  :modified_at,
  :script_path,
  :library_path,
  :ld_preload_value,
  :socket_path,
  :runc_binary_path,
  :release_agent_path,
  :mount_source,
  :mount_target,
  :file_system_type,
  :flags,
  :module_name,
  :module_file_path,
  :module_sha_256,
  :shell_history_file_path,
  :target_process,
  :address_family,
  :iana_protocol_number,
  :memory_regions,
  :tool_name,
  :tool_category,
  :service_name,
  :command_line_example,
  :threat_file_path,
  :file_operation,
  :file_path,
  :related_file_paths)
  SENSITIVE = []
  include Aws::Structure
end

#modified_at ⇒ Time

The timestamp at which the process modified the current process. The timestamp is in UTC date string format.

Returns:

  • (Time)


12016
12017
12018
12019
12020
12021
12022
12023
12024
12025
12026
12027
12028
12029
12030
12031
12032
12033
12034
12035
12036
12037
12038
12039
12040
12041
12042
12043
12044
12045
12046
12047
# File 'gems/aws-sdk-guardduty/lib/aws-sdk-guardduty/types.rb', line 12016

class RuntimeContext < Struct.new(
  :modifying_process,
  :modified_at,
  :script_path,
  :library_path,
  :ld_preload_value,
  :socket_path,
  :runc_binary_path,
  :release_agent_path,
  :mount_source,
  :mount_target,
  :file_system_type,
  :flags,
  :module_name,
  :module_file_path,
  :module_sha_256,
  :shell_history_file_path,
  :target_process,
  :address_family,
  :iana_protocol_number,
  :memory_regions,
  :tool_name,
  :tool_category,
  :service_name,
  :command_line_example,
  :threat_file_path,
  :file_operation,
  :file_path,
  :related_file_paths)
  SENSITIVE = []
  include Aws::Structure
end

#modifying_process ⇒ Types::ProcessDetails

Information about the process that modified the current process. This is available for multiple finding types.



12016
12017
12018
12019
12020
12021
12022
12023
12024
12025
12026
12027
12028
12029
12030
12031
12032
12033
12034
12035
12036
12037
12038
12039
12040
12041
12042
12043
12044
12045
12046
12047
# File 'gems/aws-sdk-guardduty/lib/aws-sdk-guardduty/types.rb', line 12016

class RuntimeContext < Struct.new(
  :modifying_process,
  :modified_at,
  :script_path,
  :library_path,
  :ld_preload_value,
  :socket_path,
  :runc_binary_path,
  :release_agent_path,
  :mount_source,
  :mount_target,
  :file_system_type,
  :flags,
  :module_name,
  :module_file_path,
  :module_sha_256,
  :shell_history_file_path,
  :target_process,
  :address_family,
  :iana_protocol_number,
  :memory_regions,
  :tool_name,
  :tool_category,
  :service_name,
  :command_line_example,
  :threat_file_path,
  :file_operation,
  :file_path,
  :related_file_paths)
  SENSITIVE = []
  include Aws::Structure
end

#module_file_path ⇒ String

The path to the module loaded into the kernel.

Returns:

  • (String)


12016
12017
12018
12019
12020
12021
12022
12023
12024
12025
12026
12027
12028
12029
12030
12031
12032
12033
12034
12035
12036
12037
12038
12039
12040
12041
12042
12043
12044
12045
12046
12047
# File 'gems/aws-sdk-guardduty/lib/aws-sdk-guardduty/types.rb', line 12016

class RuntimeContext < Struct.new(
  :modifying_process,
  :modified_at,
  :script_path,
  :library_path,
  :ld_preload_value,
  :socket_path,
  :runc_binary_path,
  :release_agent_path,
  :mount_source,
  :mount_target,
  :file_system_type,
  :flags,
  :module_name,
  :module_file_path,
  :module_sha_256,
  :shell_history_file_path,
  :target_process,
  :address_family,
  :iana_protocol_number,
  :memory_regions,
  :tool_name,
  :tool_category,
  :service_name,
  :command_line_example,
  :threat_file_path,
  :file_operation,
  :file_path,
  :related_file_paths)
  SENSITIVE = []
  include Aws::Structure
end

#module_name ⇒ String

The name of the module loaded into the kernel.

Returns:

  • (String)


12016
12017
12018
12019
12020
12021
12022
12023
12024
12025
12026
12027
12028
12029
12030
12031
12032
12033
12034
12035
12036
12037
12038
12039
12040
12041
12042
12043
12044
12045
12046
12047
# File 'gems/aws-sdk-guardduty/lib/aws-sdk-guardduty/types.rb', line 12016

class RuntimeContext < Struct.new(
  :modifying_process,
  :modified_at,
  :script_path,
  :library_path,
  :ld_preload_value,
  :socket_path,
  :runc_binary_path,
  :release_agent_path,
  :mount_source,
  :mount_target,
  :file_system_type,
  :flags,
  :module_name,
  :module_file_path,
  :module_sha_256,
  :shell_history_file_path,
  :target_process,
  :address_family,
  :iana_protocol_number,
  :memory_regions,
  :tool_name,
  :tool_category,
  :service_name,
  :command_line_example,
  :threat_file_path,
  :file_operation,
  :file_path,
  :related_file_paths)
  SENSITIVE = []
  include Aws::Structure
end

#module_sha_256 ⇒ String

The SHA256 hash of the module.

Returns:

  • (String)


12016
12017
12018
12019
12020
12021
12022
12023
12024
12025
12026
12027
12028
12029
12030
12031
12032
12033
12034
12035
12036
12037
12038
12039
12040
12041
12042
12043
12044
12045
12046
12047
# File 'gems/aws-sdk-guardduty/lib/aws-sdk-guardduty/types.rb', line 12016

class RuntimeContext < Struct.new(
  :modifying_process,
  :modified_at,
  :script_path,
  :library_path,
  :ld_preload_value,
  :socket_path,
  :runc_binary_path,
  :release_agent_path,
  :mount_source,
  :mount_target,
  :file_system_type,
  :flags,
  :module_name,
  :module_file_path,
  :module_sha_256,
  :shell_history_file_path,
  :target_process,
  :address_family,
  :iana_protocol_number,
  :memory_regions,
  :tool_name,
  :tool_category,
  :service_name,
  :command_line_example,
  :threat_file_path,
  :file_operation,
  :file_path,
  :related_file_paths)
  SENSITIVE = []
  include Aws::Structure
end

#mount_source ⇒ String

The path on the host that is mounted by the container.

Returns:

  • (String)


12016
12017
12018
12019
12020
12021
12022
12023
12024
12025
12026
12027
12028
12029
12030
12031
12032
12033
12034
12035
12036
12037
12038
12039
12040
12041
12042
12043
12044
12045
12046
12047
# File 'gems/aws-sdk-guardduty/lib/aws-sdk-guardduty/types.rb', line 12016

class RuntimeContext < Struct.new(
  :modifying_process,
  :modified_at,
  :script_path,
  :library_path,
  :ld_preload_value,
  :socket_path,
  :runc_binary_path,
  :release_agent_path,
  :mount_source,
  :mount_target,
  :file_system_type,
  :flags,
  :module_name,
  :module_file_path,
  :module_sha_256,
  :shell_history_file_path,
  :target_process,
  :address_family,
  :iana_protocol_number,
  :memory_regions,
  :tool_name,
  :tool_category,
  :service_name,
  :command_line_example,
  :threat_file_path,
  :file_operation,
  :file_path,
  :related_file_paths)
  SENSITIVE = []
  include Aws::Structure
end

#mount_target ⇒ String

The path in the container that is mapped to the host directory.

Returns:

  • (String)


12016
12017
12018
12019
12020
12021
12022
12023
12024
12025
12026
12027
12028
12029
12030
12031
12032
12033
12034
12035
12036
12037
12038
12039
12040
12041
12042
12043
12044
12045
12046
12047
# File 'gems/aws-sdk-guardduty/lib/aws-sdk-guardduty/types.rb', line 12016

class RuntimeContext < Struct.new(
  :modifying_process,
  :modified_at,
  :script_path,
  :library_path,
  :ld_preload_value,
  :socket_path,
  :runc_binary_path,
  :release_agent_path,
  :mount_source,
  :mount_target,
  :file_system_type,
  :flags,
  :module_name,
  :module_file_path,
  :module_sha_256,
  :shell_history_file_path,
  :target_process,
  :address_family,
  :iana_protocol_number,
  :memory_regions,
  :tool_name,
  :tool_category,
  :service_name,
  :command_line_example,
  :threat_file_path,
  :file_operation,
  :file_path,
  :related_file_paths)
  SENSITIVE = []
  include Aws::Structure
end

All file paths modified by the same process that triggered the finding, up to a maximum of 25 paths.

Returns:

  • (Array<String>)


12016
12017
12018
12019
12020
12021
12022
12023
12024
12025
12026
12027
12028
12029
12030
12031
12032
12033
12034
12035
12036
12037
12038
12039
12040
12041
12042
12043
12044
12045
12046
12047
# File 'gems/aws-sdk-guardduty/lib/aws-sdk-guardduty/types.rb', line 12016

class RuntimeContext < Struct.new(
  :modifying_process,
  :modified_at,
  :script_path,
  :library_path,
  :ld_preload_value,
  :socket_path,
  :runc_binary_path,
  :release_agent_path,
  :mount_source,
  :mount_target,
  :file_system_type,
  :flags,
  :module_name,
  :module_file_path,
  :module_sha_256,
  :shell_history_file_path,
  :target_process,
  :address_family,
  :iana_protocol_number,
  :memory_regions,
  :tool_name,
  :tool_category,
  :service_name,
  :command_line_example,
  :threat_file_path,
  :file_operation,
  :file_path,
  :related_file_paths)
  SENSITIVE = []
  include Aws::Structure
end

#release_agent_path ⇒ String

The path in the container that modified the release agent file.

Returns:

  • (String)


12016
12017
12018
12019
12020
12021
12022
12023
12024
12025
12026
12027
12028
12029
12030
12031
12032
12033
12034
12035
12036
12037
12038
12039
12040
12041
12042
12043
12044
12045
12046
12047
# File 'gems/aws-sdk-guardduty/lib/aws-sdk-guardduty/types.rb', line 12016

class RuntimeContext < Struct.new(
  :modifying_process,
  :modified_at,
  :script_path,
  :library_path,
  :ld_preload_value,
  :socket_path,
  :runc_binary_path,
  :release_agent_path,
  :mount_source,
  :mount_target,
  :file_system_type,
  :flags,
  :module_name,
  :module_file_path,
  :module_sha_256,
  :shell_history_file_path,
  :target_process,
  :address_family,
  :iana_protocol_number,
  :memory_regions,
  :tool_name,
  :tool_category,
  :service_name,
  :command_line_example,
  :threat_file_path,
  :file_operation,
  :file_path,
  :related_file_paths)
  SENSITIVE = []
  include Aws::Structure
end

#runc_binary_path ⇒ String

The path to the leveraged runc implementation.

Returns:

  • (String)


12016
12017
12018
12019
12020
12021
12022
12023
12024
12025
12026
12027
12028
12029
12030
12031
12032
12033
12034
12035
12036
12037
12038
12039
12040
12041
12042
12043
12044
12045
12046
12047
# File 'gems/aws-sdk-guardduty/lib/aws-sdk-guardduty/types.rb', line 12016

class RuntimeContext < Struct.new(
  :modifying_process,
  :modified_at,
  :script_path,
  :library_path,
  :ld_preload_value,
  :socket_path,
  :runc_binary_path,
  :release_agent_path,
  :mount_source,
  :mount_target,
  :file_system_type,
  :flags,
  :module_name,
  :module_file_path,
  :module_sha_256,
  :shell_history_file_path,
  :target_process,
  :address_family,
  :iana_protocol_number,
  :memory_regions,
  :tool_name,
  :tool_category,
  :service_name,
  :command_line_example,
  :threat_file_path,
  :file_operation,
  :file_path,
  :related_file_paths)
  SENSITIVE = []
  include Aws::Structure
end

#script_path ⇒ String

The path to the script that was executed.

Returns:

  • (String)


12016
12017
12018
12019
12020
12021
12022
12023
12024
12025
12026
12027
12028
12029
12030
12031
12032
12033
12034
12035
12036
12037
12038
12039
12040
12041
12042
12043
12044
12045
12046
12047
# File 'gems/aws-sdk-guardduty/lib/aws-sdk-guardduty/types.rb', line 12016

class RuntimeContext < Struct.new(
  :modifying_process,
  :modified_at,
  :script_path,
  :library_path,
  :ld_preload_value,
  :socket_path,
  :runc_binary_path,
  :release_agent_path,
  :mount_source,
  :mount_target,
  :file_system_type,
  :flags,
  :module_name,
  :module_file_path,
  :module_sha_256,
  :shell_history_file_path,
  :target_process,
  :address_family,
  :iana_protocol_number,
  :memory_regions,
  :tool_name,
  :tool_category,
  :service_name,
  :command_line_example,
  :threat_file_path,
  :file_operation,
  :file_path,
  :related_file_paths)
  SENSITIVE = []
  include Aws::Structure
end

#service_name ⇒ String

Name of the security service that has been potentially disabled.

Returns:

  • (String)


12016
12017
12018
12019
12020
12021
12022
12023
12024
12025
12026
12027
12028
12029
12030
12031
12032
12033
12034
12035
12036
12037
12038
12039
12040
12041
12042
12043
12044
12045
12046
12047
# File 'gems/aws-sdk-guardduty/lib/aws-sdk-guardduty/types.rb', line 12016

class RuntimeContext < Struct.new(
  :modifying_process,
  :modified_at,
  :script_path,
  :library_path,
  :ld_preload_value,
  :socket_path,
  :runc_binary_path,
  :release_agent_path,
  :mount_source,
  :mount_target,
  :file_system_type,
  :flags,
  :module_name,
  :module_file_path,
  :module_sha_256,
  :shell_history_file_path,
  :target_process,
  :address_family,
  :iana_protocol_number,
  :memory_regions,
  :tool_name,
  :tool_category,
  :service_name,
  :command_line_example,
  :threat_file_path,
  :file_operation,
  :file_path,
  :related_file_paths)
  SENSITIVE = []
  include Aws::Structure
end

#shell_history_file_path ⇒ String

The path to the modified shell history file.

Returns:

  • (String)


12016
12017
12018
12019
12020
12021
12022
12023
12024
12025
12026
12027
12028
12029
12030
12031
12032
12033
12034
12035
12036
12037
12038
12039
12040
12041
12042
12043
12044
12045
12046
12047
# File 'gems/aws-sdk-guardduty/lib/aws-sdk-guardduty/types.rb', line 12016

class RuntimeContext < Struct.new(
  :modifying_process,
  :modified_at,
  :script_path,
  :library_path,
  :ld_preload_value,
  :socket_path,
  :runc_binary_path,
  :release_agent_path,
  :mount_source,
  :mount_target,
  :file_system_type,
  :flags,
  :module_name,
  :module_file_path,
  :module_sha_256,
  :shell_history_file_path,
  :target_process,
  :address_family,
  :iana_protocol_number,
  :memory_regions,
  :tool_name,
  :tool_category,
  :service_name,
  :command_line_example,
  :threat_file_path,
  :file_operation,
  :file_path,
  :related_file_paths)
  SENSITIVE = []
  include Aws::Structure
end

#socket_path ⇒ String

The path to the docket socket that was accessed.

Returns:

  • (String)


12016
12017
12018
12019
12020
12021
12022
12023
12024
12025
12026
12027
12028
12029
12030
12031
12032
12033
12034
12035
12036
12037
12038
12039
12040
12041
12042
12043
12044
12045
12046
12047
# File 'gems/aws-sdk-guardduty/lib/aws-sdk-guardduty/types.rb', line 12016

class RuntimeContext < Struct.new(
  :modifying_process,
  :modified_at,
  :script_path,
  :library_path,
  :ld_preload_value,
  :socket_path,
  :runc_binary_path,
  :release_agent_path,
  :mount_source,
  :mount_target,
  :file_system_type,
  :flags,
  :module_name,
  :module_file_path,
  :module_sha_256,
  :shell_history_file_path,
  :target_process,
  :address_family,
  :iana_protocol_number,
  :memory_regions,
  :tool_name,
  :tool_category,
  :service_name,
  :command_line_example,
  :threat_file_path,
  :file_operation,
  :file_path,
  :related_file_paths)
  SENSITIVE = []
  include Aws::Structure
end

#target_process ⇒ Types::ProcessDetails

Information about the process that had its memory overwritten by the current process.



12016
12017
12018
12019
12020
12021
12022
12023
12024
12025
12026
12027
12028
12029
12030
12031
12032
12033
12034
12035
12036
12037
12038
12039
12040
12041
12042
12043
12044
12045
12046
12047
# File 'gems/aws-sdk-guardduty/lib/aws-sdk-guardduty/types.rb', line 12016

class RuntimeContext < Struct.new(
  :modifying_process,
  :modified_at,
  :script_path,
  :library_path,
  :ld_preload_value,
  :socket_path,
  :runc_binary_path,
  :release_agent_path,
  :mount_source,
  :mount_target,
  :file_system_type,
  :flags,
  :module_name,
  :module_file_path,
  :module_sha_256,
  :shell_history_file_path,
  :target_process,
  :address_family,
  :iana_protocol_number,
  :memory_regions,
  :tool_name,
  :tool_category,
  :service_name,
  :command_line_example,
  :threat_file_path,
  :file_operation,
  :file_path,
  :related_file_paths)
  SENSITIVE = []
  include Aws::Structure
end

#threat_file_path ⇒ String

The suspicious file path for which the threat intelligence details were found.

Returns:

  • (String)


12016
12017
12018
12019
12020
12021
12022
12023
12024
12025
12026
12027
12028
12029
12030
12031
12032
12033
12034
12035
12036
12037
12038
12039
12040
12041
12042
12043
12044
12045
12046
12047
# File 'gems/aws-sdk-guardduty/lib/aws-sdk-guardduty/types.rb', line 12016

class RuntimeContext < Struct.new(
  :modifying_process,
  :modified_at,
  :script_path,
  :library_path,
  :ld_preload_value,
  :socket_path,
  :runc_binary_path,
  :release_agent_path,
  :mount_source,
  :mount_target,
  :file_system_type,
  :flags,
  :module_name,
  :module_file_path,
  :module_sha_256,
  :shell_history_file_path,
  :target_process,
  :address_family,
  :iana_protocol_number,
  :memory_regions,
  :tool_name,
  :tool_category,
  :service_name,
  :command_line_example,
  :threat_file_path,
  :file_operation,
  :file_path,
  :related_file_paths)
  SENSITIVE = []
  include Aws::Structure
end

#tool_category ⇒ String

Category that the tool belongs to. Some of the examples are Backdoor Tool, Pentest Tool, Network Scanner, and Network Sniffer.

Returns:

  • (String)


12016
12017
12018
12019
12020
12021
12022
12023
12024
12025
12026
12027
12028
12029
12030
12031
12032
12033
12034
12035
12036
12037
12038
12039
12040
12041
12042
12043
12044
12045
12046
12047
# File 'gems/aws-sdk-guardduty/lib/aws-sdk-guardduty/types.rb', line 12016

class RuntimeContext < Struct.new(
  :modifying_process,
  :modified_at,
  :script_path,
  :library_path,
  :ld_preload_value,
  :socket_path,
  :runc_binary_path,
  :release_agent_path,
  :mount_source,
  :mount_target,
  :file_system_type,
  :flags,
  :module_name,
  :module_file_path,
  :module_sha_256,
  :shell_history_file_path,
  :target_process,
  :address_family,
  :iana_protocol_number,
  :memory_regions,
  :tool_name,
  :tool_category,
  :service_name,
  :command_line_example,
  :threat_file_path,
  :file_operation,
  :file_path,
  :related_file_paths)
  SENSITIVE = []
  include Aws::Structure
end

#tool_name ⇒ String

Name of the potentially suspicious tool.

Returns:

  • (String)


12016
12017
12018
12019
12020
12021
12022
12023
12024
12025
12026
12027
12028
12029
12030
12031
12032
12033
12034
12035
12036
12037
12038
12039
12040
12041
12042
12043
12044
12045
12046
12047
# File 'gems/aws-sdk-guardduty/lib/aws-sdk-guardduty/types.rb', line 12016

class RuntimeContext < Struct.new(
  :modifying_process,
  :modified_at,
  :script_path,
  :library_path,
  :ld_preload_value,
  :socket_path,
  :runc_binary_path,
  :release_agent_path,
  :mount_source,
  :mount_target,
  :file_system_type,
  :flags,
  :module_name,
  :module_file_path,
  :module_sha_256,
  :shell_history_file_path,
  :target_process,
  :address_family,
  :iana_protocol_number,
  :memory_regions,
  :tool_name,
  :tool_category,
  :service_name,
  :command_line_example,
  :threat_file_path,
  :file_operation,
  :file_path,
  :related_file_paths)
  SENSITIVE = []
  include Aws::Structure
end