ThreatFindings Object
Relationships
graph LR
ThreatFindings -->|"account"| Accounts
Properties
Truto's stable unified identifier for this object. Opaque; use provider_id to address the object in the provider's own console or API.
The provider's own category string, verbatim, with no mapping into a shared taxonomy.
When Truto actually read this object from the provider, in UTC ISO 8601 with offset. Not the request time, and not a provider timestamp.
How many times this alert pattern has repeated.
When the alert was raised.
The provider's own finding identifier.
The provider's own type string, unmodified — e.g. 'AWS::S3::Bucket', 'aws_iam_role', 'Microsoft.Sql/servers'.
Which cloud this object was read from.
awsazuregcp
The provider's own identifier — a full ARN, resource id, or self-link — passed through verbatim, never truncated or normalized.
Where the object is. 'global' marks resources with no region (e.g. IAM, a GCP VPC network). If the provider returns no location, the queried region is substituted and flagged in unreadable_fields.
Raw data returned from the remote API call.
The affected resource. Where a finding affects several resources, the primary one is carried here and the rest remain in remote_data.
The provider's own type string for the affected resource.
Provider-supplied evidence for the alert. Structure varies by provider and finding type — not a fixed schema.
Severity as the provider expresses it. On AWS GuardDuty this is a raw number (no label field); any label shown elsewhere is derived, not provider-native.
Whether the alert is active or archived. On AWS this is derived from an optional field, so 'unknown' is a real, expected value.
activearchivedresolvedunknown
Key-value pairs exactly as the customer set them, with no case folding or normalization. An empty object means no tags; tags that could not be read appear in unreadable_fields instead.
Human-readable title of the alert.
The provider's own finding type string, for example 'UnauthorizedAccess:EC2/SSHBruteForce'. Also the fallback for title, which is optional on AWS.
Fields on this object that could not be read, and why. An empty array means everything was read. Use this to tell a real value from a missing one.
Explanation of the reason, where one adds anything.
The property on this resource that could not be read.
Why the field could not be read. available_on_get: Not read on list to keep the list fast; call GET for this resource's id to get it.
not_supported_by_providernot_configuredpermission_deniednot_collectedcollection_errorpartially_collectedavailable_on_get
When the alert was last updated by the provider.