Skip to content

Relationships

Schema relationships
graph LR
    ThreatFindings -->|"account"| Accounts

Properties

idstring
required·

Truto's stable unified identifier for this object. Opaque; use provider_id to address the object in the provider's own console or API.

accountstring

The account, subscription or project this object belongs to.

References: Accounts → id
categorystring

The provider's own category string, verbatim, with no mapping into a shared taxonomy.

collected_atstring · date-time

When Truto actually read this object from the provider, in UTC ISO 8601 with offset. Not the request time, and not a provider timestamp.

countinteger

How many times this alert pattern has repeated.

created_atstring · date-time

When the alert was raised.

finding_idstring

The provider's own finding identifier.

native_typestring

The provider's own type string, unmodified — e.g. 'AWS::S3::Bucket', 'aws_iam_role', 'Microsoft.Sql/servers'.

providerstring

Which cloud this object was read from.

Possible values:
awsazuregcp
provider_idstring

The provider's own identifier — a full ARN, resource id, or self-link — passed through verbatim, never truncated or normalized.

regionstring

Where the object is. 'global' marks resources with no region (e.g. IAM, a GCP VPC network). If the provider returns no location, the queried region is substituted and flagged in unreadable_fields.

remote_dataRecord<string, any>

Raw data returned from the remote API call.

resource_idstring

The affected resource. Where a finding affects several resources, the primary one is carried here and the rest remain in remote_data.

resource_typestring

The provider's own type string for the affected resource.

sample_evidenceobject

Provider-supplied evidence for the alert. Structure varies by provider and finding type — not a fixed schema.

severitynumber

Severity as the provider expresses it. On AWS GuardDuty this is a raw number (no label field); any label shown elsewhere is derived, not provider-native.

statestring

Whether the alert is active or archived. On AWS this is derived from an optional field, so 'unknown' is a real, expected value.

Possible values:
activearchivedresolvedunknown
tagsobject

Key-value pairs exactly as the customer set them, with no case folding or normalization. An empty object means no tags; tags that could not be read appear in unreadable_fields instead.

titlestring

Human-readable title of the alert.

typestring

The provider's own finding type string, for example 'UnauthorizedAccess:EC2/SSHBruteForce'. Also the fallback for title, which is optional on AWS.

unreadable_fieldsobject[]

Fields on this object that could not be read, and why. An empty array means everything was read. Use this to tell a real value from a missing one.

detailstring

Explanation of the reason, where one adds anything.

fieldstring

The property on this resource that could not be read.

reasonstring

Why the field could not be read. available_on_get: Not read on list to keep the list fast; call GET for this resource's id to get it.

Possible values:
not_supported_by_providernot_configuredpermission_deniednot_collectedcollection_errorpartially_collectedavailable_on_get
updated_atstring · date-time

When the alert was last updated by the provider.