AWS
AWS (Amazon Web Services) is a comprehensive cloud computing platform offering infrastructure-as-a-service (IaaS), platform-as-a-service (PaaS), and software-as-a-service (SaaS) solutions. This data integration platform provides access to 458 datasets covering the complete AWS ecosystem, enabling users to query, analyze, and monitor their cloud infrastructure, security posture, compliance status, and operational resources.
| Category | Cloud |
| Direction | Query source |
| Sign-in | AWS Access Keys/Secret Keys |
| Query languages | SQLite |
| Tables | 586 |
| Query templates | 2543 |
| Website | http://aws.com |
Before you start
Huntbase signs in to AWS with AWS Access Keys/Secret Keys. Create the credential in AWS first, then keep it to hand for the Connect step.
- In the IAM console, create or pick the IAM user that Huntbase will use, and attach the AWS managed policy
ReadOnlyAccessto it. - In the navigation pane, choose Users, then choose the user name.
- On the Security credentials tab, in the Access keys section, choose Create access key.
- On the Access key best practices & alternatives page, choose Other, then choose Next and Create access key.
- On the Retrieve access key page, choose Show and copy both the access key ID and the secret access key.
Permissions:
ReadOnlyAccess(AWS managed policy)
- The secret access key is shown only once, when you create the key. If you lose it, create a new access key.
- Each IAM user can have two access keys. If Create access key is unavailable, delete an existing key first.
- Each connection covers a single AWS account.
For the vendor's own instructions, see AWS IAM access key documentation.
Use a dedicated, read-only credential for Huntbase where the product allows it. Huntbase only needs to read.
Connect AWS
- Go to Connections and click New connection, or click New connection on the AWS product page.
- On Product, pick AWS and choose the Owner.
- On Details, give the connection a Name and, optionally, a Description.
- On Connect, fill in the settings and credentials described below.
- On Verify, review the summary and click Create & check.
For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.
Settings
Where your AWS lives:
| Field | Required | Notes |
|---|---|---|
| Default Region | Yes | An AWS Region code, such as us-east-1. |
Credentials
The only Method is AWS Access Keys/Secret Keys. Enter a Credential label (for example Production), then fill in:
| Field | Required | Notes |
|---|---|---|
| Secret Access Key | Yes | Secret — not shown again after you save it. |
| Access Key ID | Yes | Secret — not shown again after you save it. |
Query it
Once connected, AWS can serve these languages in a query tab, and Scout can use it when you ask in Auto:
| Language | Use it for |
|---|---|
| SQLite | SQL over the 586 tables listed below, alongside every other connected source. |
Example: SQLite
Find policy statements that grant Full Control (:) access — Identify policies that potentially grant unrestricted access, allowing for a comprehensive review of security settings.
SELECT 1 WHERE 0; -- Query unavailable: no SQLite equivalent provided
AWS ships with 2543 query templates. Find them in Library › Queries — see Query templates.
What syncs automatically
AWS comes with a content pack. These queries run on a schedule on each new connection so the entities they find appear in the Activity Feed without you asking. You can turn syncing off from the connection's Synchronisation Settings card.
| Query | Finds |
|---|---|
| Sync IAM users | user |
| Sync IAM access keys | programmatic credential, user |
| Sync recent Security Hub findings | finding, product |
| Sync S3 buckets | databucket, account |
| Sync VPC security group rules | firewall rule, group |
| Sync console users without MFA | user |
Tables
AWS adds 586 tables. Browse their columns from Schema in the query bar's ⋯ menu.
All 586 tables
| Table | Contains |
|---|---|
aws_accessanalyzer_analyzer | AWS Access Analyzer |
aws_accessanalyzer_finding | AWS Access Analyzer Finding |
aws_account | AWS Account |
aws_account_alternate_contact | AWS Account Alternate Contact |
aws_account_contact | AWS Account Contact |
aws_acm_certificate | AWS ACM Certificate |
aws_acmpca_certificate_authority | AWS ACM Private Certificate Authority |
aws_amplify_app | AWS Amplify App |
aws_api_gateway_account | AWS API Gateway Account |
aws_api_gateway_api_key | AWS API Gateway API Key |
aws_api_gateway_authorizer | AWS API Gateway Authorizer |
aws_api_gateway_domain_name | AWS API Gateway Domain Name |
aws_api_gateway_method | AWS API Gateway Method |
aws_api_gateway_rest_api | AWS API Gateway Rest API |
aws_api_gateway_stage | AWS API Gateway Stage |
aws_api_gateway_usage_plan | AWS API Gateway Usage Plan |
aws_api_gatewayv2_api | AWS API Gateway Version 2 API |
aws_api_gatewayv2_domain_name | AWS API Gateway Version 2 Domain Name |
aws_api_gatewayv2_integration | AWS API Gateway Version 2 Integration |
aws_api_gatewayv2_route | AWS API Gateway Version 2 Route |
aws_api_gatewayv2_stage | AWS API Gateway Version 2 Stage |
aws_app_runner_service | AWS App Runner Service |
aws_appautoscaling_policy | AWS Application Auto Scaling Policy |
aws_appautoscaling_target | AWS Application Auto Scaling Target |
aws_appconfig_application | AWS AppConfig Application |
aws_appstream_fleet | AWS AppStream Fleet |
aws_appstream_image | AWS AppStream Image |
aws_appsync_api | AWS AppSync API |
aws_appsync_graphql_api | AWS AppSync GraphQL API |
aws_athena_query_execution | AWS Athena Query Execution |
aws_athena_workgroup | AWS Athena Workgroup |
aws_auditmanager_assessment | AWS Audit Manager Assessment |
aws_auditmanager_control | AWS Audit Manager Control |
aws_auditmanager_evidence | AWS Audit Manager Evidence |
aws_auditmanager_evidence_folder | AWS Audit Manager Evidence Folder |
aws_auditmanager_framework | AWS Audit Manager Framework |
aws_availability_zone | AWS Availability Zone |
aws_backup_framework | AWS Backup Framework |
aws_backup_job | AWS Backup Job |
aws_backup_legal_hold | AWS Backup Legal Hold |
aws_backup_plan | AWS Backup Plan |
aws_backup_protected_resource | AWS Backup Protected Resource |
aws_backup_recovery_point | AWS Backup Recovery Point |
aws_backup_report_plan | AWS Backup Report Plan |
aws_backup_selection | AWS Backup Selection |
aws_backup_vault | AWS Backup Vault |
aws_batch_queue | AWS Batch Queue |
aws_bedrock_agent | AWS Bedrock Agent |
aws_bedrock_custom_model | AWS Bedrock Custom Model |
aws_bedrock_foundation_model | AWS Bedrock Foundation Model |
aws_bedrock_guardrail | Amazon Bedrock Guardrail. |
aws_bedrock_imported_model | AWS Bedrock Imported Model |
aws_bedrock_knowledge_base | AWS Bedrock Knowledge Base |
aws_budgets_budget | AWS Budgets Budget |
aws_ce_anomaly_monitor | AWS Cost Explorer Anomaly Monitor |
aws_ce_cost_allocation_tags | AWS Cost Explorer Cost Allocation Tags |
aws_cloudcontrol_resource | AWS Cloud Control Resource |
aws_cloudformation_stack | AWS CloudFormation Stack |
aws_cloudformation_stack_resource | AWS CloudFormation Stack Resource |
aws_cloudformation_stack_set | AWS CloudFormation Stack Set |
aws_cloudfront_cache_policy | AWS CloudFront Cache Policy |
aws_cloudfront_distribution | AWS CloudFront Distribution |
aws_cloudfront_function | AWS CloudFront Function |
aws_cloudfront_origin_access_identity | AWS CloudFront Origin Access Identity |
aws_cloudfront_origin_request_policy | AWS CloudFront Origin Request Policy |
aws_cloudfront_response_headers_policy | AWS Cloudfront Response Headers Policy |
aws_cloudsearch_domain | AWS CloudSearch Domain |
aws_cloudtrail_channel | AWS CloudTrail Channel |
aws_cloudtrail_event_data_store | AWS CloudTrail Event Data Store |
aws_cloudtrail_import | AWS CloudTrail Import |
aws_cloudtrail_lookup_event | AWS CloudTrail Lookup Event |
aws_cloudtrail_query | AWS CloudTrail Query |
aws_cloudtrail_trail | AWS CloudTrail Trail |
aws_cloudtrail_trail_event | CloudTrail events from cloudwatch service. |
aws_cloudwatch_alarm | AWS CloudWatch Alarm |
aws_cloudwatch_event_rule | AWS CloudWatch Event Rule |
aws_cloudwatch_log_delivery | AWS CloudWatch Log Delivery |
aws_cloudwatch_log_delivery_destination | AWS CloudWatch Log Delivery Destination |
aws_cloudwatch_log_delivery_source | AWS CloudWatch Log Delivery Source |
aws_cloudwatch_log_destination | AWS CloudWatch Log Destination |
aws_cloudwatch_log_event | AWS CloudWatch Log Event |
aws_cloudwatch_log_group | AWS CloudWatch Log Group |
aws_cloudwatch_log_metric_filter | AWS CloudWatch Log Metric Filter |
aws_cloudwatch_log_resource_policy | AWS CloudWatch Log Resource Policy |
aws_cloudwatch_log_stream | AWS CloudWatch Log Stream |
aws_cloudwatch_log_subscription_filter | AWS CloudWatch Log Subscription Filter |
aws_cloudwatch_metric | AWS CloudWatch Metric |
aws_cloudwatch_metric_data_point | AWS CloudWatch Metric Data Point |
aws_cloudwatch_metric_statistic_data_point | AWS CloudWatch Metric Statistic Data Point |
aws_codeartifact_domain | AWS Code Artifact Domain |
aws_codeartifact_repository | AWS CodeArtifact Repository |
aws_codebuild_build | AWS CodeBuild Build |
aws_codebuild_fleet | AWS CodeBuild Fleet |
aws_codebuild_project | AWS CodeBuild Project |
aws_codebuild_report_group | AWS CodeBuild Report Group |
aws_codebuild_source_credential | AWS CodeBuild Source Credential |
aws_codecommit_repository | AWS CodeCommit Repository |
aws_codedeploy_app | AWS CodeDeploy Application |
aws_codedeploy_deployment_config | AWS CodeDeploy Deployment Config |
aws_codedeploy_deployment_group | AWS CodeDeploy Deployment Group |
aws_codepipeline_pipeline | AWS Codepipeline Pipeline |
aws_codestar_notification_rule | AWS CodeStar Notification Rule |
aws_cognito_identity_pool | AWS Cognito Identity Pool |
aws_cognito_identity_provider | AWS Cognito Identity Provider |
aws_cognito_user_group | AWS Cognito User Group |
aws_cognito_user_pool | AWS Cognito User Pool |
aws_config_aggregate_authorization | AWS Config Aggregate Authorization |
aws_config_configuration_recorder | AWS Config Configuration Recorder |
aws_config_conformance_pack | AWS Config Conformance Pack |
aws_config_delivery_channel | AWS Config Delivery Channel |
aws_config_retention_configuration | AWS Config Retention Configuration |
aws_config_rule | AWS Config Rule |
aws_config_rule_compliance_detail | AWS Config Rule Compliance Detail |
aws_connect_instance | AWS Connect Instance |
aws_connect_instance_attribute | AWS Connect Instance Attribute |
aws_cost_by_account_daily | AWS Cost Explorer - Cost by Linked Account (Daily) |
aws_cost_by_account_monthly | AWS Cost Explorer - Cost by Linked Account (Monthly) |
aws_cost_by_record_type_daily | AWS Cost Explorer - Cost by Record Type (Daily) |
aws_cost_by_record_type_monthly | AWS Cost Explorer - Cost by Record Type (Monthly) |
aws_cost_by_region_monthly | AWS Cost Explorer - Cost by Region (Monthly) |
aws_cost_by_resource_daily | AWS Cost Explorer - Cost by Resource (Daily) |
aws_cost_by_resource_hourly | AWS Cost Explorer - Cost by Resource (Hourly) |
aws_cost_by_resource_monthly | AWS Cost Explorer - Cost by Resource (Monthly) |
aws_cost_by_service_daily | AWS Cost Explorer - Cost by Service (Daily) |
aws_cost_by_service_monthly | AWS Cost Explorer - Cost by Service (Monthly) |
aws_cost_by_service_usage_type_daily | AWS Cost Explorer - Cost by Service and Usage Type (Daily) |
aws_cost_by_service_usage_type_monthly | AWS Cost Explorer - Cost by Service and Usage Type (Monthly) |
aws_cost_by_tag | AWS Cost Explorer - Cost By Tags |
aws_cost_forecast_daily | AWS Cost Explorer - Cost Forecast (Daily) |
aws_cost_forecast_monthly | AWS Cost Explorer - Cost Forecast (Monthly) |
aws_cost_usage | AWS Cost Explorer - Cost and Usage |
aws_costoptimizationhub_recommendation | AWS Cost Optimization Hub Recommendation |
aws_datasync_task | AWS DataSync Task |
aws_dax_cluster | AWS DAX Cluster |
aws_dax_parameter | AWS DAX Parameter |
aws_dax_parameter_group | AWS DAX Parameter Group |
aws_dax_subnet_group | AWS DAX Subnet Group |
aws_directory_service_certificate | AWS Directory Service Certificate |
aws_directory_service_directory | AWS Directory Service Directory |
aws_directory_service_log_subscription | AWS Directory Service Log Subscription |
aws_dlm_lifecycle_policy | AWS DLM Lifecycle Policy |
aws_dms_certificate | AWS DMS Certificate |
aws_dms_endpoint | AWS DMS Endpoint |
aws_dms_replication_instance | AWS DMS Replication Instance |
aws_dms_replication_task | AWS DMS Replication Task |
aws_docdb_cluster | AWS DocumentDB Cluster |
aws_docdb_cluster_instance | AWS DocumentDB Cluster Instance |
aws_docdb_cluster_snapshot | AWS DocumentDB Cluster Snapshot |
aws_drs_job | AWS DRS Job |
aws_drs_recovery_instance | AWS DRS recovery instance |
aws_drs_recovery_snapshot | AWS DRS Recovery Snapshot |
aws_drs_source_server | AWS DRS Source Server |
aws_dynamodb_backup | AWS DynamoDB Backup |
aws_dynamodb_global_table | AWS DynamoDB Global Table |
aws_dynamodb_metric_account_provisioned_read_capacity_util | AWS DynamoDB Metric Account Provisioned Read Capacity Utilization |
aws_dynamodb_metric_account_provisioned_write_capacity_util | AWS DynamoDB Metric Account Provisioned Write Capacity Utilization |
aws_dynamodb_table | AWS DynamoDB Table |
aws_dynamodb_table_export | AWS DynamoDB Table Export |
aws_ebs_snapshot | AWS EBS Snapshot |
aws_ebs_volume | AWS EBS Volume |
aws_ebs_volume_metric_read_ops | AWS EBS Volume Cloudwatch Metrics - Read Ops |
aws_ebs_volume_metric_read_ops_daily | AWS EBS Volume Cloudwatch Metrics - Read Ops (Daily) |
aws_ebs_volume_metric_read_ops_hourly | AWS EBS Volume Cloudwatch Metrics - Read Ops (Hourly) |
aws_ebs_volume_metric_write_ops | AWS EBS Volume Cloudwatch Metrics - Write Ops |
aws_ebs_volume_metric_write_ops_daily | AWS EBS Volume Cloudwatch Metrics - Write Ops (Daily) |
aws_ebs_volume_metric_write_ops_hourly | AWS EBS Volume Cloudwatch Metrics - Write Ops (Hourly) |
aws_ec2_ami | AWS EC2 AMI |
aws_ec2_ami_shared | AWS EC2 AMI - All public, private, and shared AMIs |
aws_ec2_application_load_balancer | AWS EC2 Application Load Balancer |
aws_ec2_application_load_balancer_metric_request_count | AWS EC2 Application Load Balancer Metrics - Request Count |
aws_ec2_application_load_balancer_metric_request_count_daily | AWS EC2 Application Load Balancer Metrics - Request Count (Daily) |
aws_ec2_autoscaling_group | AWS EC2 Autoscaling Group |
aws_ec2_capacity_reservation | AWS EC2 Capacity Reservation |
aws_ec2_classic_load_balancer | AWS EC2 Classic Load Balancer |
aws_ec2_client_vpn_endpoint | AWS EC2 Client VPN Endpoint |
aws_ec2_fleet | AWS EC2 Fleet |
aws_ec2_gateway_load_balancer | AWS EC2 Gateway Load Balancer |
aws_ec2_instance | AWS EC2 Instance |
aws_ec2_instance_availability | AWS EC2 Instance Availability |
aws_ec2_instance_metric_cpu_utilization | AWS EC2 Instance Cloudwatch Metrics - CPU Utilization |
aws_ec2_instance_metric_cpu_utilization_daily | AWS EC2 Instance Cloudwatch Metrics - CPU Utilization (Daily) |
aws_ec2_instance_metric_cpu_utilization_hourly | AWS EC2 Instance Cloudwatch Metrics - CPU Utilization (Hourly) |
aws_ec2_instance_type | AWS EC2 Instance Type |
aws_ec2_key_pair | AWS EC2 Key Pair |
aws_ec2_launch_configuration | AWS EC2 Launch Configuration |
aws_ec2_launch_template | AWS EC2 Launch Template |
aws_ec2_launch_template_version | AWS EC2 Launch Template Version |
aws_ec2_load_balancer_listener | AWS EC2 Load Balancer Listener |
aws_ec2_load_balancer_listener_rule | AWS EC2 Load Balancer Listener Rule |
aws_ec2_managed_prefix_list | AWS EC2 Managed Prefix List |
aws_ec2_managed_prefix_list_entry | AWS EC2 Managed Prefix List Entry |
aws_ec2_network_interface | AWS EC2 Network Interface |
aws_ec2_network_load_balancer | AWS EC2 Network Load Balancer |
aws_ec2_network_load_balancer_metric_net_flow_count | AWS EC2 Network Load Balancer Metrics - Net Flow Count |
aws_ec2_network_load_balancer_metric_net_flow_count_daily | AWS EC2 Network Load Balancer Metrics - Net Flow Count (Daily) |
aws_ec2_placement_group | AWS EC2 Placement Group |
aws_ec2_regional_settings | AWS EC2 Regional Settings |
aws_ec2_reserved_instance | AWS EC2 Reserved Instance |
aws_ec2_spot_fleet_request | AWS EC2 Spot Fleet Request |
aws_ec2_spot_price | AWS EC2 Spot Price History |
aws_ec2_ssl_policy | AWS EC2 SSL Policy |
aws_ec2_target_group | AWS EC2 Target Group |
aws_ec2_transit_gateway | AWS EC2 Transit Gateway |
aws_ec2_transit_gateway_route | AWS EC2 Transit Gateway Route |
aws_ec2_transit_gateway_route_table | AWS EC2 Transit Gateway Route Table |
aws_ec2_transit_gateway_vpc_attachment | AWS EC2 Transit Gateway VPC Attachment |
aws_ecr_image | AWS ECR Image |
aws_ecr_image_scan_finding | AWS ECR Image Scan Finding |
aws_ecr_registry | AWS ECR Private Registry |
aws_ecr_registry_scanning_configuration | AWS ECR Registry Scanning Configuration |
aws_ecr_repository | AWS ECR Repository |
aws_ecrpublic_repository | AWS ECR Public Repository |
aws_ecs_cluster | AWS ECS Cluster |
aws_ecs_cluster_metric_cpu_utilization | AWS ECS Cluster Cloudwatch Metrics - CPU Utilization |
aws_ecs_cluster_metric_cpu_utilization_daily | AWS ECS Cluster Cloudwatch Metrics - CPU Utilization (Daily) |
aws_ecs_cluster_metric_cpu_utilization_hourly | AWS ECS Cluster Cloudwatch Metrics - CPU Utilization (Hourly) |
aws_ecs_container_instance | AWS ECS Container Instance |
aws_ecs_service | AWS ECS Service |
aws_ecs_task | AWS ECS Task |
aws_ecs_task_definition | AWS ECS Task Definition |
aws_efs_access_point | AWS EFS Access Point |
aws_efs_file_system | AWS Elastic File System |
aws_efs_mount_target | AWS EFS Mount Target |
aws_eks_access_entry | AWS EKS Access Entry |
aws_eks_access_policy_association | AWS EKS Access Policy Association |
aws_eks_addon | AWS EKS Addon |
aws_eks_addon_version | AWS EKS Addon Version |
aws_eks_cluster | AWS Elastic Kubernetes Service Cluster |
aws_eks_fargate_profile | AWS Elastic Kubernetes Service Fargate Profile |
aws_eks_identity_provider_config | AWS EKS Identity Provider Config |
aws_eks_node_group | AWS EKS Node Group |
aws_eks_pod_identity_association | AWS EKS Pod Identity Association |
aws_elastic_beanstalk_application | AWS Elastic Beanstalk Application |
aws_elastic_beanstalk_application_version | AWS Elastic Beanstalk Application Version |
aws_elastic_beanstalk_environment | AWS ElasticBeanstalk Environment |
aws_elasticache_cluster | AWS ElastiCache Cluster |
aws_elasticache_parameter_group | AWS ElastiCache Parameter Group |
aws_elasticache_redis_metric_cache_hits_hourly | AWS Elasticache Redis CacheHits metric (Hourly) |
aws_elasticache_redis_metric_curr_connections_hourly | AWS Elasticache Redis CurrConnections metric (Hourly) |
aws_elasticache_redis_metric_engine_cpu_utilization_daily | AWS Elasticache Redis EngineCPUUtilization metric (Daily) |
aws_elasticache_redis_metric_engine_cpu_utilization_hourly | AWS Elasticache Redis EngineCPUUtilization metric (Hourly) |
aws_elasticache_redis_metric_get_type_cmds_hourly | AWS Elasticache Redis GetTypeCmds metric(Hourly) |
aws_elasticache_redis_metric_list_based_cmds_hourly | AWS Elasticache Redis ListBasedCmds metric (Hourly) |
aws_elasticache_redis_metric_new_connections_hourly | AWS Elasticache Redis NewConnections metric (Hourly) |
aws_elasticache_replication_group | AWS ElastiCache Replication Group |
aws_elasticache_reserved_cache_node | AWS ElastiCache Reserved Cache Node |
aws_elasticache_serverless_cache | AWS ElastiCache Serverless Cache |
aws_elasticache_subnet_group | AWS ElastiCache Subnet Group |
aws_elasticache_update_action | AWS ElastiCache Update Action |
aws_elasticsearch_domain | AWS Elasticsearch Domain |
aws_emr_block_public_access_configuration | AWS EMR Block Public Access Configuration |
aws_emr_cluster | AWS EMR Cluster |
aws_emr_cluster_metric_is_idle | AWS EMR Cluster Cloudwatch Metrics - IsIdle |
aws_emr_instance | AWS EMR Instance |
aws_emr_instance_fleet | AWS EMR Instance Fleet |
aws_emr_instance_group | AWS EMR Instance Group |
aws_emr_security_configuration | AWS EMR Security Configuration |
aws_emr_studio | AWS EMR Studio |
aws_eventbridge_bus | AWS EventBridge Bus |
aws_eventbridge_rule | AWS EventBridge Rule |
aws_fms_app_list | AWS FMS App List |
aws_fms_policy | AWS FMS Policy |
aws_fsx_file_system | AWS FSx File System |
aws_glacier_vault | AWS Glacier Vault |
aws_globalaccelerator_accelerator | AWS Global Accelerator Accelerator |
aws_globalaccelerator_endpoint_group | AWS Global Accelerator Endpoint Group |
aws_globalaccelerator_listener | AWS Global Accelerator Listener |
aws_glue_catalog_database | AWS Glue Catalog Database |
aws_glue_catalog_table | AWS Glue Catalog Table |
aws_glue_connection | AWS Glue Connection |
aws_glue_crawler | AWS Glue Crawler |
aws_glue_data_catalog_encryption_settings | AWS Glue Data Catalog Encryption Settings |
aws_glue_data_quality_ruleset | AWS Glue Data Quality Ruleset |
aws_glue_dev_endpoint | AWS Glue Dev Endpoint |
aws_glue_job | AWS Glue Job |
aws_glue_ml_transform | AWS Glue ML Transform |
aws_glue_security_configuration | AWS Glue Security Configuration |
aws_guardduty_detector | AWS GuardDuty Detector |
aws_guardduty_filter | AWS GuardDuty Filter |
aws_guardduty_finding | AWS GuardDuty Finding |
aws_guardduty_ipset | AWS GuardDuty IPSet |
aws_guardduty_member | AWS GuardDuty Member |
aws_guardduty_publishing_destination | AWS GuardDuty Publishing Destination |
aws_guardduty_threat_intel_set | AWS GuardDuty ThreatIntelSet |
aws_health_affected_entity | AWS Health Affected Entity |
aws_health_event | AWS Health Event |
aws_iam_access_advisor | AWS IAM Access Advisor |
aws_iam_access_key | AWS IAM User Access Key |
aws_iam_account_password_policy | AWS IAM Account Password Policy |
aws_iam_account_summary | AWS IAM Account Summary |
aws_iam_action | AWS IAM Action |
aws_iam_credential_report | AWS IAM Credential Report |
aws_iam_group | AWS IAM Group |
aws_iam_instance_profile | AWS IAM Instance Profile |
aws_iam_open_id_connect_provider | AWS IAM OpenID Connect Provider |
aws_iam_policy | AWS IAM Policy |
aws_iam_policy_attachment | AWS IAM Policy Attachment |
aws_iam_policy_simulator | AWS IAM Policy Simulator |
aws_iam_role | AWS IAM Role |
aws_iam_saml_provider | AWS IAM Saml Provider |
aws_iam_server_certificate | AWS IAM Server Certificate |
aws_iam_service_specific_credential | AWS IAM User Service Specific Credential |
aws_iam_user | AWS IAM User |
aws_iam_virtual_mfa_device | AWS IAM Virtual MFA device |
aws_identitystore_group | AWS Identity Store Group |
aws_identitystore_group_membership | AWS Identity Store Group Membership |
aws_identitystore_user | AWS Identity Store User |
aws_inspector_assessment_run | AWS Inspector Assessment Run |
aws_inspector_assessment_target | AWS Inspector Assessment Target |
aws_inspector_assessment_template | AWS Inspector Assessment Template |
aws_inspector_exclusion | AWS Inspector Exclusion |
aws_inspector_finding | AWS Inspector Finding |
aws_inspector2_coverage | AWS Inspector2 Coverage |
aws_inspector2_coverage_statistics | AWS Inspector2 Coverage Statistics |
aws_inspector2_finding | AWS Inspector2 Finding |
aws_inspector2_member | AWS Inspector2 Member |
aws_inspector2_organization_configuration | AWS Inspector2 Organization Configuration |
aws_iot_fleet_metric | AWS IoT Fleet Metric |
aws_iot_thing | AWS IoT Thing |
aws_iot_thing_group | AWS IoT Thing Group |
aws_iot_thing_type | AWS IoT Thing Type |
aws_keyspaces_keyspace | AWS Keyspaces Keyspace |
aws_keyspaces_table | AWS Keyspaces Table |
aws_kinesis_consumer | AWS Kinesis Consumer |
aws_kinesis_firehose_delivery_stream | AWS Kinesis Firehose Delivery Stream |
aws_kinesis_stream | AWS Kinesis Stream |
aws_kinesis_video_stream | AWS Kinesis Video Stream |
aws_kinesisanalyticsv2_application | AWS Kinesis Analytics V2 Application |
aws_kms_alias | AWS KMS Alias |
aws_kms_key | AWS KMS Key |
aws_kms_key_rotation | AWS KMS Key Rotation |
aws_lakeformation_permission | AWS Lake Formation Permission |
aws_lakeformation_resource | AWS Lake Formation Resource |
aws_lakeformation_tag | AWS Lake Formation Tag |
aws_lambda_alias | AWS Lambda Alias |
aws_lambda_event_source_mapping | AWS Lambda Event Source Mapping |
aws_lambda_function | AWS Lambda Function |
aws_lambda_function_metric_duration_daily | AWS Lambda Function Cloudwatch Metrics - Duration (Daily) |
aws_lambda_function_metric_errors_daily | AWS Lambda Function Cloudwatch Metrics - Errors (Daily) |
aws_lambda_function_metric_invocations_daily | AWS Lambda Function Cloudwatch Metrics - Invocations (Daily) |
aws_lambda_layer | AWS Lambda Layer |
aws_lambda_layer_version | AWS Lambda Layer Version |
aws_lambda_version | AWS Lambda Version |
aws_lightsail_bucket | AWS Lightsail Bucket |
aws_lightsail_instance | AWS Lightsail Instance |
aws_macie2_classification_job | AWS Macie2 Classification Job |
aws_macie2_finding | AWS Macie2 Finding |
aws_media_store_container | AWS Media Store Container |
aws_memorydb_cluster | AWS MemoryDB Cluster |
aws_mgn_application | AWS MGN Application |
aws_mq_broker | AWS MQ Broker |
aws_msk_cluster | AWS Managed Streaming for Apache Kafka |
aws_msk_serverless_cluster | AWS Serverless Managed Streaming for Apache Kafka |
aws_msk_topic | AWS MSK Topic |
aws_mskconnect_connector | AWS MSK Connect Connector |
aws_neptune_db_cluster | AWS Neptune DB Cluster |
aws_neptune_db_cluster_snapshot | AWS Neptune DB Cluster Snapshot |
aws_networkfirewall_firewall | AWS Network Firewall Firewall |
aws_networkfirewall_firewall_policy | AWS Network Firewall Policy |
aws_networkfirewall_rule_group | AWS Network Firewall Rule Group |
aws_oam_link | AWS OAM Link |
aws_oam_sink | AWS OAM Sink |
aws_opensearch_domain | AWS OpenSearch Domain |
aws_opensearch_reserved_instance | AWS OpenSearch Reserved Instance |
aws_organizations_account | AWS Organizations Account |
aws_organizations_delegated_administrator | AWS Organizations Delegated Administrator |
aws_organizations_delegated_services_for_account | AWS Organizations Delegated Services For Account |
aws_organizations_organizational_unit | AWS Organizations Organizational Unit |
aws_organizations_policy | AWS Organizations Policy |
aws_organizations_policy_target | AWS Organizations Policy Target |
aws_organizations_root | AWS Organizations Root |
aws_pinpoint_app | AWS Pinpoint App |
aws_pipes_pipe | AWS Pipes Pipe |
aws_pricing_product | AWS Pricing Product |
aws_pricing_service_attribute | AWS Pricing Service Attribute |
aws_quicksight_account_setting | AWS QuickSight Account Setting |
aws_quicksight_data_set | AWS QuickSight Dataset |
aws_quicksight_data_source | AWS QuickSight Data Source |
aws_quicksight_group | AWS QuickSight Group |
aws_quicksight_namespace | AWS QuickSight Namespace |
aws_quicksight_user | AWS QuickSight User |
aws_quicksight_vpc_connection | AWS QuickSight VPC Connection |
aws_ram_principal_association | AWS RAM Principal Association |
aws_ram_resource_association | AWS RAM Resource Association |
aws_rds_db_cluster | AWS RDS DB Cluster |
aws_rds_db_cluster_parameter_group | AWS RDS DB Cluster Parameter Group |
aws_rds_db_cluster_snapshot | AWS RDS DB Cluster Snapshot |
aws_rds_db_engine_version | AWS RDS DB Engine Version |
aws_rds_db_event_subscription | AWS RDS DB Event Subscription |
aws_rds_db_instance | AWS RDS DB Instance |
aws_rds_db_instance_automated_backup | AWS RDS DB Instance Automated Backup |
aws_rds_db_instance_metric_connections | AWS RDS DB Instance Cloudwatch Metrics - DB Connections |
aws_rds_db_instance_metric_connections_daily | AWS RDS DB Instance Cloudwatch Metrics - DB Connections (Daily) |
aws_rds_db_instance_metric_connections_hourly | AWS RDS DB Instance Cloudwatch Metrics - DB Connections (Hourly) |
aws_rds_db_instance_metric_cpu_utilization | AWS RDS DB Instance Cloudwatch Metrics - CPU Utilization |
aws_rds_db_instance_metric_cpu_utilization_daily | AWS RDS DB Instance Cloudwatch Metrics - CPU Utilization (Daily) |
aws_rds_db_instance_metric_cpu_utilization_hourly | AWS RDS DB Instance Cloudwatch Metrics - CPU Utilization (Hourly) |
aws_rds_db_instance_metric_read_iops | AWS RDS DB Instance Cloudwatch Metrics - Read IOPS |
aws_rds_db_instance_metric_read_iops_daily | AWS RDS DB Instance Cloudwatch Metrics - Read IOPS (Daily) |
aws_rds_db_instance_metric_read_iops_hourly | AWS RDS DB Instance Cloudwatch Metrics - Read IOPS (Hourly) |
aws_rds_db_instance_metric_write_iops | AWS RDS DB Instance Cloudwatch Metrics - Write IOPS |
aws_rds_db_instance_metric_write_iops_daily | AWS RDS DB Instance Cloudwatch Metrics - Write IOPS (Daily) |
aws_rds_db_instance_metric_write_iops_hourly | AWS RDS DB Instance Cloudwatch Metrics - Write IOPS (Hourly) |
aws_rds_db_option_group | AWS RDS DB Option Group |
aws_rds_db_parameter_group | AWS RDS DB Parameter Group |
aws_rds_db_proxy | AWS RDS DB Proxy |
aws_rds_db_recommendation | AWS RDS DB Recommendation |
aws_rds_db_snapshot | AWS RDS DB Snapshot |
aws_rds_db_subnet_group | AWS RDS DB Subnet Group |
aws_rds_global_cluster | AWS RDS Global Cluster |
aws_rds_pending_maintenance_action | AWS RDS Pending Maintenance Action |
aws_rds_reserved_db_instance | AWS RDS Reserved DB Instance |
aws_redshift_cluster | AWS Redshift Cluster |
aws_redshift_cluster_metric_cpu_utilization_daily | AWS Redshift Cluster Cloudwatch Metrics - CPU Utilization (Daily) |
aws_redshift_event_subscription | AWS Redshift Event Subscription |
aws_redshift_parameter_group | AWS Redshift Parameter Group |
aws_redshift_snapshot | AWS Redshift Snapshot |
aws_redshift_subnet_group | AWS Redshift Subnet Group |
aws_redshiftserverless_namespace | AWS Redshift Serverless Namespace |
aws_redshiftserverless_workgroup | AWS Redshift Serverless Workgroup |
aws_region | AWS Region |
aws_resource_explorer_index | AWS Resource Explorer Index |
aws_resource_explorer_resource | AWS Resource Explorer Resource. |
aws_resource_explorer_search | AWS Resource Explorer Search |
aws_resource_explorer_supported_resource_type | AWS Resource Explorer Supported Resource Type |
aws_rolesanywhere_profile | AWS Roles Anywhere Profile |
aws_rolesanywhere_trust_anchor | AWS Roles Anywhere Trust Anchor |
aws_route53_domain | AWS Route53 Domain |
aws_route53_health_check | AWS Route53 Health Check |
aws_route53_query_log | AWS Route53 Query Logging Configuration |
aws_route53_record | AWS Route53 Record |
aws_route53_resolver_endpoint | AWS Route53 Resolver Endpoint |
aws_route53_resolver_query_log_config | AWS Route53 Resolver Query Logging Configuration |
aws_route53_resolver_rule | AWS Route53 Resolver Rule |
aws_route53_traffic_policy | AWS Route53 Traffic Policy |
aws_route53_traffic_policy_instance | AWS Route53 Traffic Policy Instance |
aws_route53_vpc_association_authorization | AWS Route53 VPC Association Authorization |
aws_route53_zone | AWS Route53 Zone |
aws_s3_access_point | AWS S3 Access Point |
aws_s3_account_settings | AWS S3 Account Block Public Access Settings |
aws_s3_bucket | AWS S3 Bucket |
aws_s3_bucket_intelligent_tiering_configuration | AWS S3 Bucket Intelligent Tiering Configuration |
aws_s3_directory_bucket | AWS S3 Directory Bucket |
aws_s3_multi_region_access_point | AWS S3 Multi Region Access Point |
aws_s3_multipart_upload | AWS S3 Multipart Upload |
aws_s3_object | List AWS S3 Objects in S3 buckets by bucket name. |
aws_s3_object_version | AWS S3 Object Version |
aws_s3tables_namespace | AWS S3Tables Namespace |
aws_s3tables_table | AWS S3Tables Table |
aws_s3tables_table_bucket | AWS S3Tables Table Bucket |
aws_sagemaker_app | AWS Sagemaker App |
aws_sagemaker_domain | AWS Sagemaker Domain |
aws_sagemaker_endpoint_configuration | AWS Sagemaker Endpoint Configuration |
aws_sagemaker_model | AWS Sagemaker Model |
aws_sagemaker_notebook_instance | AWS Sagemaker Notebook Instance |
aws_sagemaker_training_job | AWS SageMaker Training Job |
aws_savingsplans_savings_plan | AWS Savings Plans Savings Plan |
aws_scheduler_schedule | AWS EventBridge Scheduler Schedule |
aws_secretsmanager_secret | AWS Secrets Manager Secret |
aws_securityhub_action_target | AWS Security Hub Action Target |
aws_securityhub_enabled_product_subscription | AWS Securityhub Enabled Product Subscription |
aws_securityhub_finding | AWS Security Hub Finding |
aws_securityhub_finding_aggregator | AWS Security Hub Finding Aggregator |
aws_securityhub_hub | AWS Security Hub |
aws_securityhub_insight | AWS Securityhub Insight |
aws_securityhub_member | AWS Securityhub Member |
aws_securityhub_product | AWS Securityhub Product |
aws_securityhub_standards_control | AWS Security Hub Standards Control |
aws_securityhub_standards_subscription | AWS Security Hub Standards Subscription |
aws_securitylake_data_lake | AWS Security Lake Data Lake |
aws_securitylake_subscriber | AWS Security Lake Subscriber |
aws_serverlessapplicationrepository_application | AWS Serverless Application Repository Application |
aws_service_discovery_instance | AWS Service Discovery Instance |
aws_service_discovery_namespace | AWS Service Discovery Namespace |
aws_service_discovery_service | AWS Service Discovery Service |
aws_servicecatalog_portfolio | AWS Service Catalog Portfolio |
aws_servicecatalog_portfolio_share | AWS Service Catalog Portfolio Share |
aws_servicecatalog_product | AWS Service Catalog Product |
aws_servicecatalog_provisioned_product | AWS Service Catalog Provisioned Product |
aws_servicequotas_auto_management_configuration | AWS Service Quotas Auto Management Configuration |
aws_servicequotas_default_service_quota | AWS Service Quotas Default Service Quota |
aws_servicequotas_service | AWS Service Quotas Service |
aws_servicequotas_service_quota | AWS Service Quotas Service Quota |
aws_servicequotas_service_quota_change_request | AWS Service Quotas Service Quota Change Request |
aws_ses_domain_identity | AWS SES Domain Identity |
aws_ses_email_identity | AWS SES Email Identity |
aws_ses_template | AWS SES Template |
aws_sesv2_suppressed_destination | AWS SESv2 Suppressed Destination |
aws_sfn_state_machine | AWS Step Functions State Machine |
aws_sfn_state_machine_execution | AWS Step Functions State Machine Execution |
aws_sfn_state_machine_execution_history | AWS Step Functions State Machine Execution History |
aws_shield_attack | AWS Shield Attack |
aws_shield_attack_statistic | AWS Shield Attack Statistic |
aws_shield_drt_access | AWS Shield DRT Access |
aws_shield_emergency_contact | AWS Shield Emergency Contact |
aws_shield_protection | AWS Shield Protection |
aws_shield_protection_group | AWS Shield Protection Group |
aws_shield_subscription | AWS Shield Subscription |
aws_simspaceweaver_simulation | AWS SimSpace Weaver Simulation |
aws_sns_subscription | AWS SNS Subscription |
aws_sns_topic | AWS SNS Topic |
aws_sns_topic_subscription | AWS SNS Topic Subscription |
aws_sqs_queue | AWS SQS Queue |
aws_ssm_association | AWS SSM Association |
aws_ssm_document | AWS SSM Document |
aws_ssm_document_permission | AWS SSM Document Permission |
aws_ssm_inventory | AWS SSM Inventory |
aws_ssm_inventory_entry | AWS SSM Inventory Entry |
aws_ssm_maintenance_window | AWS SSM Maintenance Window |
aws_ssm_managed_instance | AWS SSM Managed Instance |
aws_ssm_managed_instance_compliance | AWS SSM Managed Instance Compliance |
aws_ssm_managed_instance_patch_state | AWS SSM Managed Instance Patch State |
aws_ssm_parameter | AWS SSM Parameter |
aws_ssm_patch_baseline | AWS SSM Patch Baseline |
aws_ssm_service_setting | AWS SSM Service Setting |
aws_ssmincidents_response_plan | AWS SSMIncidents Response Plan |
aws_ssoadmin_account_assignment | AWS SSO Account Assignment |
aws_ssoadmin_customer_policy_attachment | AWS SSO Customer Managed Policy Attachment |
aws_ssoadmin_instance | AWS SSO Instance |
aws_ssoadmin_managed_policy_attachment | AWS SSO Managed Policy Attachment |
aws_ssoadmin_permission_set | AWS SSO Permission Set |
aws_sts_caller_identity | AWS STS Caller Identity |
aws_synthetics_canary | AWS CloudWatch Synthetics Canary |
aws_tagging_resource | AWS Tagging Resource |
aws_timestreamwrite_database | AWS Timestreamwrite Database |
aws_timestreamwrite_table | AWS Timestreamwrite Table |
aws_transfer_connector | AWS Transfer Connector |
aws_transfer_server | AWS Transfer Server |
aws_transfer_user | AWS Transfer User |
aws_trusted_advisor_check_result | AWS Trusted Advisor Check Result |
aws_trusted_advisor_check_summary | AWS Trusted Advisor Check Summary |
aws_vpc | AWS VPC |
aws_vpc_block_public_access_options | AWS VPC Block Public Access Options |
aws_vpc_customer_gateway | AWS VPC Customer Gateway |
aws_vpc_dhcp_options | AWS VPC DHCP Options |
aws_vpc_egress_only_internet_gateway | AWS VPC Egress Only Internet Gateway |
aws_vpc_eip | AWS VPC Elastic IP |
aws_vpc_eip_address_transfer | AWS VPC Elastic IP Address Transfer |
aws_vpc_endpoint | AWS VPC Endpoint |
aws_vpc_endpoint_service | AWS VPC Endpoint Service |
aws_vpc_flow_log | AWS VPC Flowlog |
aws_vpc_flow_log_event | AWS VPC Flow Log events from CloudWatch Logs |
aws_vpc_internet_gateway | AWS VPC Internet Gateway |
aws_vpc_nat_gateway | AWS VPC Network Address Translation Gateway |
aws_vpc_nat_gateway_metric_bytes_out_to_destination | AWS VPC Nat Gateway Cloudwatch Metrics - BytesOutToDestination |
aws_vpc_network_acl | AWS VPC Network ACL |
aws_vpc_peering_connection | AWS VPC Peering Connection |
aws_vpc_route | AWS VPC Route |
aws_vpc_route_table | AWS VPC Route table |
aws_vpc_security_group | AWS VPC Security Group |
aws_vpc_security_group_rule | AWS VPC Security Group Rule |
aws_vpc_security_group_vpc_association | AWS VPC Security Group VPC Association |
aws_vpc_subnet | AWS VPC Subnet |
aws_vpc_verified_access_endpoint | AWS VPC verified access Endpoint |
aws_vpc_verified_access_group | AWS VPC Verified Access Group |
aws_vpc_verified_access_instance | AWS VPC Verified Access Instance |
aws_vpc_verified_access_trust_provider | AWS VPC Verified Access Trust Provider |
aws_vpc_vpn_connection | AWS VPC VPN Connection |
aws_vpc_vpn_gateway | AWS VPC VPN Gateway |
aws_waf_rate_based_rule | AWS WAF Rate Based Rule |
aws_waf_rule | AWS WAF Rule |
aws_waf_rule_group | AWS WAF Rule Group |
aws_waf_web_acl | AWS WAF Web ACL |
aws_wafregional_rule | AWS WAF Regional Rule |
aws_wafregional_rule_group | AWS WAF Regional Rule Group |
aws_wafregional_web_acl | AWS WAF Regional Web ACL |
aws_wafv2_ip_set | AWS WAFv2 IP Set |
aws_wafv2_regex_pattern_set | AWS WAFv2 Regex Pattern Set |
aws_wafv2_rule_group | AWS WAFv2 Rule Group |
aws_wafv2_web_acl | AWS WAFv2 Web ACL |
aws_wellarchitected_answer | AWS Well-Architected Answer |
aws_wellarchitected_check_detail | AWS Well-Architected Check Detail |
aws_wellarchitected_check_summary | AWS Well-Architected Check Summary |
aws_wellarchitected_consolidated_report | AWS Well-Architected Consolidated Report |
aws_wellarchitected_lens | AWS Well-Architected Lens |
aws_wellarchitected_lens_review | AWS Well-Architected Lens Review |
aws_wellarchitected_lens_review_improvement | AWS Well-Architected Lens Review Improvement |
aws_wellarchitected_lens_review_report | AWS Well-Architected Lens Review Report |
aws_wellarchitected_lens_share | AWS Well-Architected Lens Share |
aws_wellarchitected_milestone | AWS Well-Architected Milestone |
aws_wellarchitected_notification | AWS Well-Architected Notification |
aws_wellarchitected_share_invitation | AWS Well-Architected Share Invitation |
aws_wellarchitected_workload | AWS Well-Architected Workload |
aws_wellarchitected_workload_share | AWS Well-Architected Workload Share |
aws_workspaces_directory | AWS Workspaces Directory |
aws_workspaces_workspace | AWS Workspaces |
Next steps
- Connections — health, credentials and settings after you connect
- Query languages — syntax, parameters and time ranges
- Chatting with Scout — ask questions without writing a query
- All integrations — the rest of the catalog