ingest-guardduty-ocsf
ingest-guardduty-ocsf
Thin passthrough ingestion skill: raw GuardDuty finding JSON in → canonical finding projection → OCSF 1.8 Detection Finding (2004) JSONL or native enriched finding JSONL out. GuardDuty is already a detection engine — this skill normalises its findings into the same wire format everything else in detection-engineering/ speaks, so downstream converters (convert-ocsf-to-sarif, convert-ocsf-to-mermaid-attack-flow) and evaluators consume them uniformly alongside detections from the custom detect-* skills.
Wire contract
Reads any of the three shapes the GuardDuty service emits:
- Single finding — one JSON object per line (NDJSON, e.g. EventBridge → Kinesis Firehose to S3)
- API
ListFindings/GetFindingswrapper — top-level{"Findings": [...]}(the format returned byaws guardduty get-findings) - EventBridge event envelope — top-level
{"detail": {...}, "detail-type": "GuardDuty Finding", ...}; the skill auto-unwrapsdetail.
Writes OCSF 1.8 Detection Finding (class_uid: 2004, category_uid: 2). See ../OCSF_CONTRACT.md for the field-level pinning that every event matches.
When --output-format native is selected, it emits the same finding in the repo's native enriched shape with stable event_uid, normalized provider/account/severity fields, MITRE ATT&CK annotations, and preserved evidence/resource context, but without the OCSF envelope fields.
Native output format
--output-format native returns one JSON object per GuardDuty finding with: