ingest-guardduty-ocsf

Installation
SKILL.md

ingest-guardduty-ocsf

Thin passthrough ingestion skill: raw GuardDuty finding JSON in → canonical finding projection → OCSF 1.8 Detection Finding (2004) JSONL or native enriched finding JSONL out. GuardDuty is already a detection engine — this skill normalises its findings into the same wire format everything else in detection-engineering/ speaks, so downstream converters (convert-ocsf-to-sarif, convert-ocsf-to-mermaid-attack-flow) and evaluators consume them uniformly alongside detections from the custom detect-* skills.

Wire contract

Reads any of the three shapes the GuardDuty service emits:

  1. Single finding — one JSON object per line (NDJSON, e.g. EventBridge → Kinesis Firehose to S3)
  2. API ListFindings / GetFindings wrapper — top-level {"Findings": [...]} (the format returned by aws guardduty get-findings)
  3. EventBridge event envelope — top-level {"detail": {...}, "detail-type": "GuardDuty Finding", ...}; the skill auto-unwraps detail.

Writes OCSF 1.8 Detection Finding (class_uid: 2004, category_uid: 2). See ../OCSF_CONTRACT.md for the field-level pinning that every event matches.

When --output-format native is selected, it emits the same finding in the repo's native enriched shape with stable event_uid, normalized provider/account/severity fields, MITRE ATT&CK annotations, and preserved evidence/resource context, but without the OCSF envelope fields.

Native output format

--output-format native returns one JSON object per GuardDuty finding with:

Installs
1
GitHub Stars
3
First Seen
Apr 20, 2026
ingest-guardduty-ocsf — msaad00/cloud-ai-security-skills