Class Indicator
- java.lang.Object
-
- software.amazon.awssdk.services.securityhub.model.Indicator
-
- All Implemented Interfaces:
Serializable,SdkPojo,ToCopyableBuilder<Indicator.Builder,Indicator>
@Generated("software.amazon.awssdk:codegen") public final class Indicator extends Object implements SdkPojo, Serializable, ToCopyableBuilder<Indicator.Builder,Indicator>
Contains information about the indicators observed in an Amazon GuardDuty Extended Threat Detection attack sequence. Indicators include a set of signals, which can be API activities or findings that GuardDuty uses to detect an attack sequence finding. GuardDuty generates an attack sequence finding when multiple signals align to a potentially suspicious activity. To receive GuardDuty attack sequence findings in Security Hub, you must have GuardDuty and GuardDuty S3 Protection enabled. For more information, see GuardDuty Extended Threat Detection in the Amazon GuardDuty User Guide.
- See Also:
- Serialized Form
-
-
Nested Class Summary
Nested Classes Modifier and Type Class Description static interfaceIndicator.Builder
-
Method Summary
All Methods Static Methods Instance Methods Concrete Methods Modifier and Type Method Description static Indicator.Builderbuilder()booleanequals(Object obj)booleanequalsBySdkFields(Object obj)<T> Optional<T>getValueForField(String fieldName, Class<T> clazz)inthashCode()booleanhasValues()For responses, this returns true if the service returned a value for the Values property.Stringkey()The name of the indicator that’s present in the attack sequence finding.Map<String,SdkField<?>>sdkFieldNameToField()List<SdkField<?>>sdkFields()static Class<? extends Indicator.Builder>serializableBuilderClass()Stringtitle()The title describing the indicator.Indicator.BuildertoBuilder()StringtoString()Returns a string representation of this object.Stringtype()The type of indicator.List<String>values()Values associated with each indicator key.-
Methods inherited from class java.lang.Object
clone, finalize, getClass, notify, notifyAll, wait, wait, wait
-
Methods inherited from interface software.amazon.awssdk.utils.builder.ToCopyableBuilder
copy
-
-
-
-
Method Detail
-
key
public final String key()
The name of the indicator that’s present in the attack sequence finding.
- Returns:
- The name of the indicator that’s present in the attack sequence finding.
-
hasValues
public final boolean hasValues()
For responses, this returns true if the service returned a value for the Values property. This DOES NOT check that the value is non-empty (for which, you should check theisEmpty()method on the property). This is useful because the SDK will never return a null collection or map, but you may need to differentiate between the service returning nothing (or null) and the service returning an empty collection or map. For requests, this returns true if a value for the property was specified in the request builder, and false if a value was not specified.
-
values
public final List<String> values()
Values associated with each indicator key. For example, if the indicator key is
SUSPICIOUS_NETWORK, then the value will be the name of the network. If the indicator key isATTACK_TACTIC, then the value will be one of the MITRE tactics.Attempts to modify the collection returned by this method will result in an UnsupportedOperationException.
This method will never return null. If you would like to know whether the service returned this field (so that you can differentiate between null and empty), you can use the
hasValues()method.- Returns:
- Values associated with each indicator key. For example, if the indicator key is
SUSPICIOUS_NETWORK, then the value will be the name of the network. If the indicator key isATTACK_TACTIC, then the value will be one of the MITRE tactics.
-
title
public final String title()
The title describing the indicator.
- Returns:
- The title describing the indicator.
-
type
public final String type()
The type of indicator.
- Returns:
- The type of indicator.
-
toBuilder
public Indicator.Builder toBuilder()
- Specified by:
toBuilderin interfaceToCopyableBuilder<Indicator.Builder,Indicator>
-
builder
public static Indicator.Builder builder()
-
serializableBuilderClass
public static Class<? extends Indicator.Builder> serializableBuilderClass()
-
equalsBySdkFields
public final boolean equalsBySdkFields(Object obj)
- Specified by:
equalsBySdkFieldsin interfaceSdkPojo
-
toString
public final String toString()
Returns a string representation of this object. This is useful for testing and debugging. Sensitive data will be redacted from this string using a placeholder value.
-
sdkFieldNameToField
public final Map<String,SdkField<?>> sdkFieldNameToField()
- Specified by:
sdkFieldNameToFieldin interfaceSdkPojo
-
-