Appearance
Get multiple article metadata
OpenAPI definition
json
{
"openapi": "3.1.0",
"info": {
"title": "Entries",
"version": "1.0"
},
"servers": [
{
"url": "https://api.feedly.com/v3/entries/"
}
],
"components": {
"securitySchemes": {
"sec0": {
"type": "apiKey",
"name": "Authorization",
"in": "header",
"x-bearer-format": "bearer"
}
}
},
"security": [
{
"sec0": []
}
],
"paths": {
"/.mget": {
"post": {
"summary": "Get multiple article metadata",
"description": "",
"operationId": "get-multiple-article-metadata",
"requestBody": {
"content": {
"application/json": {
"schema": {
"type": "object",
"properties": {
"RAW_BODY": {
"type": "array",
"description": "Limit 1,000 entries per call",
"items": {
"type": "string"
}
}
}
}
}
}
},
"responses": {
"200": {
"description": "200",
"content": {
"application/json": {
"examples": {
"Result": {
"value": "[\n {\n \"fingerprint\": \"c392b42\",\n \"id\": \"UybWZO8Gre9MphC4ZSsEQwKCOEGrCNXcYdJXbwlpiMI=_19a0d0d8f78:497f7ef:752f71fa\",\n \"language\": \"en\",\n \"originId\": \"",\n \"origin\": {\n \"streamId\": \"feed/",\n \"title\": \"Detection.FYI\",\n \"htmlUrl\": \""\n },\n \"title\": \"AWS ConsoleLogin Failed Authentication\",\n \"published\": 1761136602000,\n \"crawled\": 1761155583864,\n \"summary\": {\n \"content\": \"Detects failed AWS console login attempts due to authentication failures. Monitoring these events is crucial for identifying potential brute-force attacks or unauthorized access attempts to AWS accounts.\",\n \"direction\": \"ltr\"\n },\n \"alternate\": [\n {\n \"href\": \"",\n \"type\": \"text/html\"\n }\n ],\n \"canonicalUrl\": \"",\n \"snippet\": \"\\n<div><div><div><div><div>\\n<p>Detects failed AWS console login attempts due to authentication failures. Monitoring these events is crucial for identifying potential brute-force attacks or unauthorized access attempts to AWS accounts.</p>\\n<div><pre tabindex=\\\"0\\\"><code><span><span> 1</span><span><span>title</span><span>:</span><span> </span><span>AWS ConsoleLogin Failed Authentication</span><span>\\n</span></span></span><span><span> 2</span><span><span></span><span>id</span><span>:</span><span> </span><span>6393e346-1977</span>-<span>46ef-8987-ad414a145fad</span><span>\\n</span></span></span><span><span> 3</span><span><span></span><span></span></span></span></code></pre></div></div></div></div></div></div>\",\n \"originContentType\": \"text/html\",\n \"fullContent\": \"\\n<div><div><div><div><div>\\n<p>Detects failed AWS console login attempts due to authentication failures. Monitoring these events is crucial for identifying potential brute-force attacks or unauthorized access attempts to AWS accounts.</p>\\n<div><pre tabindex=\\\"0\\\"><code><span><span> 1</span><span><span>title</span><span>:</span><span> </span><span>AWS ConsoleLogin Failed Authentication</span><span>\\n</span></span></span><span><span> 2</span><span><span></span><span>id</span><span>:</span><span> </span><span>6393e346-1977</span>-<span>46ef-8987-ad414a145fad</span><span>\\n</span></span></span><span><span> 3</span><span><span></span><span>status</span><span>:</span><span> </span><span>experimental</span><span>\\n</span></span></span><span><span> 4</span><span><span></span><span>description</span><span>:</span><span> </span><span>|</span><span>\\n</span></span></span><span><span> 5</span><span><span> </span><span> </span><span>Detects failed AWS console login attempts due to authentication failures. Monitoring these events is crucial for identifying potential brute-force attacks or unauthorized access attempts to AWS accounts.</span><span>\\n</span></span></span><span><span> 6</span><span><span></span><span>references</span><span>:</span><span>\\n</span></span></span><span><span> 7</span><span><span> </span>- <span></span><span>\\n</span></span></span><span><span> 8</span><span><span> </span>- <span></span><span>\\n</span></span></span><span><span> 9</span><span><span> </span>- <span></span><span>\\n</span></span></span><span><span>10</span><span><span></span><span>author</span><span>:</span><span> </span><span>Ivan Saakov, Nasreddine Bencherchali</span><span>\\n</span></span></span><span><span>11</span><span><span></span><span>date</span><span>:</span><span> </span><span>2025-10-19</span><span>\\n</span></span></span><span><span>12</span><span><span></span><span>tags</span><span>:</span><span>\\n</span></span></span><span><span>13</span><span><span> </span>- <span>attack.credential-access</span><span>\\n</span></span></span><span><span>14</span><span><span> </span>- <span>attack.t1110</span><span>\\n</span></span></span><span><span>15</span><span><span></span><span>logsource</span><span>:</span><span>\\n</span></span></span><span><span>16</span><span><span> </span><span>product</span><span>:</span><span> </span><span>aws</span><span>\\n</span></span></span><span><span>17</span><span><span> </span><span>service</span><span>:</span><span> </span><span>cloudtrail</span><span>\\n</span></span></span><span><span>18</span><span><span></span><span>detection</span><span>:</span><span>\\n</span></span></span><span><span>19</span><span><span> </span><span>selection</span><span>:</span><span>\\n</span></span></span><span><span>20</span><span><span> </span><span>eventName</span><span>:</span><span> </span><span>'ConsoleLogin'</span><span>\\n</span></span></span><span><span>21</span><span><span> </span><span>errorMessage</span><span>:</span><span> </span><span>'Failed authentication'</span><span>\\n</span></span></span><span><span>22</span><span><span> </span><span>condition</span><span>:</span><span> </span><span>selection</span><span>\\n</span></span></span><span><span>23</span><span><span></span><span>falsepositives</span><span>:</span><span>\\n</span></span></span><span><span>24</span><span><span> </span>- <span>Legitimate failed login attempts by authorized users. Investigate the source of repeated failed login attempts.</span><span>\\n</span></span></span><span><span>25</span><span><span></span><span>level</span><span>:</span><span> </span><span>medium</span><span>\\n</span></span></span></code></pre></div>\\n</div>\\n</div></div></div></div>\",\n \"unread\": true,\n \"categories\": [\n {\n \"id\": \"enterprise/christeam/category/a1b9d077-7806-4b29-8f1c-d17ebc172ea3\",\n \"label\": \"AI: Ad-Hoc Research\"\n }\n ],\n \"commonTopics\": [\n {\n \"type\": \"detectionRule\",\n \"label\": \"Sigma rules\",\n \"id\": \"nlp/f/topic/7010\",\n \"score\": 1,\n \"salienceLevel\": \"about\"\n }\n ],\n \"entities\": [\n {\n \"type\": \"org\",\n \"disambiguated\": true,\n \"label\": \"Amazon Web Services\",\n \"id\": \"nlp/f/entity/gz:org:amazon-web-services\",\n \"mentions\": [\n {\n \"text\": \"AWS\"\n }\n ],\n \"salienceLevel\": \"about\"\n },\n {\n \"type\": \"mitreAttack\",\n \"disambiguated\": true,\n \"label\": \"Brute Force (Enterprise T1110)\",\n \"id\": \"nlp/f/entity/gz:mi:attack-pattern-a93494bb-4b80-4ea1-8695-3236a49916fd\",\n \"mentions\": [\n {\n \"text\": \"brute-force\"\n },\n {\n \"text\": \"t1110\"\n }\n ],\n \"salienceLevel\": \"mention\"\n },\n {\n \"type\": \"mitreAttack\",\n \"disambiguated\": true,\n \"label\": \"Credential Access (Enterprise TA0006)\",\n \"id\": \"nlp/f/entity/gz:mi:x-mitre-tactic-2558fd61-8c75-4730-94c4-11926db2a263\",\n \"causes\": [\n {\n \"label\": \"Brute Force (Enterprise T1110)\",\n \"id\": \"nlp/f/entity/gz:mi:attack-pattern-a93494bb-4b80-4ea1-8695-3236a49916fd\"\n }\n ],\n \"mentions\": [\n {\n \"text\": \"credential-access\"\n }\n ],\n \"salienceLevel\": \"mention\"\n },\n {\n \"type\": \"mitreAttack\",\n \"disambiguated\": true,\n \"label\": \"Tactics and Techniques\",\n \"id\": \"nlp/f/entity/gz:mi-any\",\n \"causes\": [\n {\n \"label\": \"Brute Force (Enterprise T1110)\",\n \"id\": \"nlp/f/entity/gz:mi:attack-pattern-a93494bb-4b80-4ea1-8695-3236a49916fd\"\n },\n {\n \"label\": \"Credential Access (Enterprise TA0006)\",\n \"id\": \"nlp/f/entity/gz:mi:x-mitre-tactic-2558fd61-8c75-4730-94c4-11926db2a263\"\n }\n ],\n \"mentions\": [],\n \"salienceLevel\": \"mention\"\n }\n ],\n \"leoSummary\": {\n \"sentences\": []\n },\n \"indicatorsOfCompromise\": {\n \"mentions\": [],\n \"exports\": [],\n \"sigmaRules\": {\n \"count\": 1,\n \"url\": \""\n }\n },\n \"attackNavigator\": {\n \"url\": \"",\n \"ttpCount\": 1\n },\n \"sources\": [\n {\n \"streamId\": \"feed/",\n \"title\": \"Detection rules\",\n \"feedlyFeedType\": \"WebAlert\",\n \"searchTerms\": {\n \"parts\": [\n {\n \"id\": \"nlp/f/topic/7010\",\n \"label\": \"Sigma rules\"\n }\n ],\n \"isComplexFilter\": true\n }\n },\n {\n \"streamId\": \"feed/",\n \"title\": \"Sigma Rules\",\n \"feedlyFeedType\": \"WebAlert\",\n \"searchTerms\": {\n \"parts\": [\n {\n \"id\": \"nlp/f/topic/7010\",\n \"label\": \"Sigma rules\"\n }\n ],\n \"isComplexFilter\": false\n }\n },\n {\n \"streamId\": \"feed/",\n \"title\": \"Detection Rules\",\n \"feedlyFeedType\": \"WebAlert\",\n \"searchTerms\": {\n \"parts\": [\n {\n \"id\": \"nlp/f/topic/7010\",\n \"label\": \"Sigma rules\"\n }\n ],\n \"isComplexFilter\": true\n }\n },\n {\n \"streamId\": \"feed/",\n \"title\": \"PIR5.4 What new detection rules have been published?\",\n \"feedlyFeedType\": \"WebAlert\",\n \"searchTerms\": {\n \"parts\": [\n {\n \"id\": \"nlp/f/topic/7010\",\n \"label\": \"Sigma rules\"\n }\n ],\n \"isComplexFilter\": true\n }\n },\n {\n \"streamId\": \"feed/",\n \"title\": \"Sigma rules\",\n \"feedlyFeedType\": \"WebAlert\",\n \"searchTerms\": {\n \"parts\": [\n {\n \"id\": \"nlp/f/topic/7010\",\n \"label\": \"Sigma rules\"\n }\n ],\n \"isComplexFilter\": false\n }\n },\n {\n \"streamId\": \"feed/",\n \"title\": \"MITRE Tactics\",\n \"feedlyFeedType\": \"WebAlert\",\n \"searchTerms\": {\n \"parts\": [\n {\n \"id\": \"nlp/f/entity/gz:mi:x-mitre-tactic-2558fd61-8c75-4730-94c4-11926db2a263\",\n \"label\": \"Credential Access (Enterprise TA0006)\",\n \"type\": \"mitreAttack\"\n }\n ],\n \"isComplexFilter\": true\n }\n },\n {\n \"streamId\": \"feed/",\n \"title\": \"Detection Rules\",\n \"feedlyFeedType\": \"WebAlert\",\n \"searchTerms\": {\n \"parts\": [\n {\n \"id\": \"nlp/f/topic/7010\",\n \"label\": \"Sigma rules\"\n }\n ],\n \"isComplexFilter\": true\n }\n },\n {\n \"streamId\": \"feed/",\n \"title\": \"Detection Rules\",\n \"feedlyFeedType\": \"WebAlert\",\n \"searchTerms\": {\n \"parts\": [\n {\n \"id\": \"nlp/f/topic/7010\",\n \"label\": \"Sigma rules\"\n }\n ],\n \"isComplexFilter\": true\n }\n },\n {\n \"streamId\": \"feed/",\n \"title\": \"Sigma rules and hunting queries\",\n \"feedlyFeedType\": \"WebAlert\",\n \"searchTerms\": {\n \"parts\": [\n {\n \"id\": \"nlp/f/topic/7010\",\n \"label\": \"Sigma rules\"\n }\n ],\n \"isComplexFilter\": true\n }\n },\n {\n \"streamId\": \"feed/",\n \"title\": \"Detection Rules\",\n \"feedlyFeedType\": \"WebAlert\",\n \"searchTerms\": {\n \"parts\": [\n {\n \"id\": \"nlp/f/topic/7010\",\n \"label\": \"Sigma rules\"\n }\n ],\n \"isComplexFilter\": true\n }\n },\n {\n \"streamId\": \"feed/",\n \"title\": \"Troubleshooting\",\n \"feedlyFeedType\": \"WebAlert\",\n \"searchTerms\": {\n \"parts\": [\n {\n \"id\": \"nlp/f/entity/gz:org:amazon-web-services\",\n \"label\": \"Amazon Web Services\",\n \"type\": \"org\"\n }\n ],\n \"isComplexFilter\": true\n }\n },\n {\n \"streamId\": \"feed/",\n \"title\": \"DT Rules\",\n \"feedlyFeedType\": \"WebAlert\",\n \"searchTerms\": {\n \"parts\": [\n {\n \"id\": \"nlp/f/topic/7010\",\n \"label\": \"Sigma rules\"\n }\n ],\n \"isComplexFilter\": true\n }\n }\n ]\n },\n {\n \"language\": \"en\",\n \"id\": \"9SoZXMyUC2YuPYM5lOZapZAqx/84/0Bi+Qgx7L3rclM=_186099a7824:d77052:6d2d67a6\",\n \"createdBy\": {\n \"userAgent\": \"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36\",\n \"application\": \"feedly\"\n },\n \"origin\": {\n \"title\": \"The Cyber Express\",\n \"streamId\": \"feed/",\n \"htmlUrl\": \""\n },\n \"content\": {\n \"content\": \"<div><div>\\n<p>A BreachForums user under the alias IntelBroker claims to have posted the customer data of Verizon Communications on the forum. The threat actor has claimed to have access to a database of 7.5 million Verizon customer records. Verizon has verified the data on the request from The Cyber Express.</p>\\n<blockquote><p>According to their initial review of this matter, the data appears to be obtained approximately two weeks ago when a Verizon vendor experienced a security breach, Verizon spokesperson <strong>Richard Young</strong> told The Cyber Express.</p>\\n<p>“This vendor creates videos for Verizon to assist customers with billing-related questions. The vendor had access to customer first names, device types, and service plans. The vendor did not have <a href=\\\"">access to Social Security</a> numbers, credit card numbers, or other personally identifiable customer information,” Young said.</p>\\n<p>We have severed this vendor’s <a href=\\\"">access to our systems</a> and suspended use of their services. Our review of this matter continues.”</p></blockquote>\\n<p>Commonly known as <a rel=\\\"noopener nofollow\\\" href=\\\"" target=\\\"_blank\\\">Verizon</a>, the American multinational telecommunications conglomerate is a corporate component of the Dow Jones Industrial Average. <a rel=\\\"nofollow noopener\\\" href=\\\"" target=\\\"_blank\\\">According to Statista</a>, Verizon has a retail customer base of approximately 143 million subscribers in 2021.</p>\\n<p>“In January 2023, a database of 7.5 million customers belonging to the Verizon was stolen by hackers,” claimed the post by IntelBroker. A sample of the hashed <a href=\\\"">data posted</a> indicates mobile and online subscription details.</p>\\n<p>The post, made on Friday, had the link to download the entire data tranche. IntelBroker’s present avatar has been active on the forum since October 2022. Its previous targets include <a href=\\\"">Autotrader</a>, <a href=\\\"">Volvo</a>, <a href=\\\"">Hilton Hotels</a>, and <a href=\\\"">AT&T</a>.</p>\\n<p><img data-lazy-sizes=\\\"(max-width: 746px) 100vw, 746px\\\" src=\\\"" alt=\\\"\\\" data-lazy-src=\\\"" srcset=\\\"data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7\\\" data-pin-no-hover=\\\"true\\\" data-lazy-srcset=\\\" 300w, 1024w, 768w, 1536w, 150w, 360w, 750w, 1140w, 1729w\\\" width=\\\"746\\\" class=\\\"wp-image-17467\\\" data-recalc-dims=\\\"1\\\" height=\\\"373\\\"></p>\\n<h3>Verizon and data breaches</h3>\\n<p>Independent researchers were analysing the sample <a href=\\\"">data at the time</a> of publishing this report. If the tranche turns out to be authentic, this would be the company’s second major <a href=\\\"">data breach</a> in the past 12 months.</p>\\n<p>Verizon in May 2022 confirmed a data breach where the full names, email addresses, corporate ID numbers, and phone numbers of Verizon employees were compromised. According to a <a rel=\\\"nofollow noopener\\\" href=\\\"" target=\\\"_blank\\\">report</a> from Motherboard, the data was shared with the publication by the hacker who reached out to them.</p>\\n<p>The company popped up in <a href=\\\"">cybersecurity news</a> over a data breach five years before that.</p>\\n<p>In 2017, the telecommunication company <a rel=\\\"nofollow noopener\\\" href=\\\"" target=\\\"_blank\\\">conceded</a> that the personal data of 6 million customers had been leaked online. The leak was caused by a misconfigured <a href=\\\"">security setting on a cloud</a> server, which was the result of “human error.</p>\\n<p>The data, which included customer <a href=\\\"">phone numbers</a>, names, and some PIN codes, was publicly available online due to a mistake made by NICE Systems, an Israel-based company that Verizon was working with to facilitate customer service calls.</p>\\n<p>The <a href=\\\"">data of telecommunication users</a> was collected over a period of six months, and Verizon closed the security hole on June 22.</p>\\n<h5><em><strong><span dir=\\\"ltr\\\">Update: The article was updated on January 27, 2023, with confirmations, and analysis from Verizon.</span></strong></em></h5>\\n</div></div>\",\n \"direction\": \"ltr\"\n },\n \"title\": \"Verizon Investigates Customer Data Breach, Says No PII Compromised\",\n \"author\": \"Editorial\",\n \"crawled\": 1675198363684,\n \"published\": 1675198363684,\n \"updated\": 1675198363684,\n \"alternate\": [\n {\n \"href\": \""\n }\n ],\n \"canonical\": [\n {\n \"type\": \"text/html\",\n \"href\": \""\n }\n ],\n \"visual\": {\n \"width\": 746,\n \"processor\": \"feedly-nikon-v3.1\",\n \"url\": \"",\n \"height\": 373,\n \"contentType\": \"image/jpeg\"\n },\n \"canonicalUrl\": \"",\n \"unread\": false,\n \"commonTopics\": [\n {\n \"type\": \"topic\",\n \"id\": \"nlp/f/topic/3003\",\n \"label\": \"Cyber Security\",\n \"score\": 1,\n \"causes\": [\n {\n \"id\": \"nlp/f/topic/4009\",\n \"label\": \"Cyber Attacks\"\n }\n ],\n \"salienceLevel\": \"about\"\n },\n {\n \"type\": \"cyberEvent\",\n \"targets\": [\n {\n \"text\": \"Verizon Communications\",\n \"id\": \"nlp/f/entity/gz:org:verizon\",\n \"confidence\": 0.9280639886856079\n }\n ],\n \"id\": \"nlp/f/topic/4009\",\n \"label\": \"Cyber Attacks\",\n \"score\": 0.998,\n \"salienceLevel\": \"about\"\n },\n {\n \"type\": \"technology\",\n \"id\": \"nlp/f/topic/2256\",\n \"label\": \"Tech\",\n \"score\": 0.692,\n \"salienceLevel\": \"about\"\n },\n {\n \"type\": \"topic\",\n \"id\": \"nlp/f/topic/603\",\n \"label\": \"Cyber Crime\",\n \"score\": 0.931,\n \"salienceLevel\": \"about\"\n },\n {\n \"type\": \"topic\",\n \"id\": \"nlp/f/topic/1025\",\n \"label\": \"Hacking\",\n \"score\": 0.97,\n \"salienceLevel\": \"about\"\n },\n {\n \"type\": \"topic\",\n \"id\": \"nlp/f/topic/4004\",\n \"label\": \"Data Breach\",\n \"score\": 0.997,\n \"salienceLevel\": \"about\"\n },\n {\n \"type\": \"industryTopic\",\n \"id\": \"nlp/f/topic/4027\",\n \"label\": \"Telecom Industry\",\n \"score\": 1,\n \"salienceLevel\": \"about\"\n }\n ],\n \"entities\": [\n {\n \"disambiguated\": true,\n \"type\": \"org\",\n \"id\": \"nlp/f/entity/gz:org:verizon\",\n \"label\": \"Verizon\",\n \"salienceLevel\": \"about\",\n \"mentions\": [\n {\n \"text\": \"Verizon Communications\"\n },\n {\n \"text\": \"Verizon\"\n }\n ]\n },\n {\n \"disambiguated\": true,\n \"type\": \"org\",\n \"id\": \"nlp/f/entity/gz:org:at-t\",\n \"label\": \"AT&T\",\n \"salienceLevel\": \"mention\",\n \"mentions\": [\n {\n \"text\": \"AT&T\"\n }\n ]\n },\n {\n \"disambiguated\": true,\n \"type\": \"org\",\n \"id\": \"nlp/f/entity/gz:org:hilton-worldwide\",\n \"label\": \"Hilton Worldwide\",\n \"salienceLevel\": \"mention\",\n \"mentions\": [\n {\n \"text\": \"Hilton Hotels\"\n }\n ]\n },\n {\n \"disambiguated\": true,\n \"type\": \"org\",\n \"id\": \"nlp/f/entity/gz:org:travel-and-hospitality-industry-companies\",\n \"label\": \"Travel & Hospitality Companies\",\n \"causes\": [\n {\n \"id\": \"nlp/f/entity/gz:org:hilton-worldwide\",\n \"label\": \"Hilton Worldwide\"\n }\n ],\n \"salienceLevel\": \"mention\",\n \"mentions\": []\n },\n {\n \"disambiguated\": true,\n \"type\": \"org\",\n \"id\": \"nlp/f/entity/gz:org:telecom-industry-companies\",\n \"label\": \"Telecom Companies\",\n \"causes\": [\n {\n \"id\": \"nlp/f/entity/gz:org:verizon\",\n \"label\": \"Verizon\"\n },\n {\n \"id\": \"nlp/f/entity/gz:org:at-t\",\n \"label\": \"AT&T\"\n }\n ],\n \"salienceLevel\": \"about\",\n \"mentions\": []\n },\n {\n \"disambiguated\": true,\n \"type\": \"org\",\n \"id\": \"nlp/f/entity/gz:org:fortune-500-companies\",\n \"label\": \"Fortune 500 Companies\",\n \"causes\": [\n {\n \"id\": \"nlp/f/entity/gz:org:verizon\",\n \"label\": \"Verizon\"\n },\n {\n \"id\": \"nlp/f/entity/gz:org:at-t\",\n \"label\": \"AT&T\"\n }\n ],\n \"salienceLevel\": \"about\",\n \"mentions\": []\n }\n ],\n \"leoSummary\": {\n \"sentences\": [\n {\n \"text\": \"According to their initial review of this matter, the data appears to be obtained approximately two weeks ago when a Verizon vendor experienced a security breach, Verizon spokesperson Richard Young told The Cyber Express.\"\n },\n {\n \"text\": \"A BreachForums user under the alias IntelBroker claims to have posted the customer data of Verizon Communications on the forum.\"\n }\n ]\n },\n \"indicatorsOfCompromise\": {\n \"exports\": [],\n \"mentions\": []\n }\n }\n]"
}
},
"schema": {
"type": "array",
"items": {
"type": "object",
"properties": {
"fingerprint": {
"type": "string",
"example": "c392b42"
},
"id": {
"type": "string",
"example": "UybWZO8Gre9MphC4ZSsEQwKCOEGrCNXcYdJXbwlpiMI=_19a0d0d8f78:497f7ef:752f71fa"
},
"language": {
"type": "string",
"example": "en"
},
"originId": {
"type": "string",
"example": ""
},
"origin": {
"type": "object",
"properties": {
"streamId": {
"type": "string",
"example": "feed/"
},
"title": {
"type": "string",
"example": "Detection.FYI"
},
"htmlUrl": {
"type": "string",
"example": ""
}
}
},
"title": {
"type": "string",
"example": "AWS ConsoleLogin Failed Authentication"
},
"published": {
"type": "integer",
"example": 1761136602000,
"default": 0
},
"crawled": {
"type": "integer",
"example": 1761155583864,
"default": 0
},
"summary": {
"type": "object",
"properties": {
"content": {
"type": "string",
"example": "Detects failed AWS console login attempts due to authentication failures. Monitoring these events is crucial for identifying potential brute-force attacks or unauthorized access attempts to AWS accounts."
},
"direction": {
"type": "string",
"example": "ltr"
}
}
},
"alternate": {
"type": "array",
"items": {
"type": "object",
"properties": {
"href": {
"type": "string",
"example": ""
},
"type": {
"type": "string",
"example": "text/html"
}
}
}
},
"canonicalUrl": {
"type": "string",
"example": ""
},
"snippet": {
"type": "string",
"example": "\n<div><div><div><div><div>\n<p>Detects failed AWS console login attempts due to authentication failures. Monitoring these events is crucial for identifying potential brute-force attacks or unauthorized access attempts to AWS accounts.</p>\n<div><pre tabindex=\"0\"><code><span><span> 1</span><span><span>title</span><span>:</span><span> </span><span>AWS ConsoleLogin Failed Authentication</span><span>\n</span></span></span><span><span> 2</span><span><span></span><span>id</span><span>:</span><span> </span><span>6393e346-1977</span>-<span>46ef-8987-ad414a145fad</span><span>\n</span></span></span><span><span> 3</span><span><span></span><span></span></span></span></code></pre></div></div></div></div></div></div>"
},
"originContentType": {
"type": "string",
"example": "text/html"
},
"fullContent": {
"type": "string",
"example": "\n<div><div><div><div><div>\n<p>Detects failed AWS console login attempts due to authentication failures. Monitoring these events is crucial for identifying potential brute-force attacks or unauthorized access attempts to AWS accounts.</p>\n<div><pre tabindex=\"0\"><code><span><span> 1</span><span><span>title</span><span>:</span><span> </span><span>AWS ConsoleLogin Failed Authentication</span><span>\n</span></span></span><span><span> 2</span><span><span></span><span>id</span><span>:</span><span> </span><span>6393e346-1977</span>-<span>46ef-8987-ad414a145fad</span><span>\n</span></span></span><span><span> 3</span><span><span></span><span>status</span><span>:</span><span> </span><span>experimental</span><span>\n</span></span></span><span><span> 4</span><span><span></span><span>description</span><span>:</span><span> </span><span>|</span><span>\n</span></span></span><span><span> 5</span><span><span> </span><span> </span><span>Detects failed AWS console login attempts due to authentication failures. Monitoring these events is crucial for identifying potential brute-force attacks or unauthorized access attempts to AWS accounts.</span><span>\n</span></span></span><span><span> 6</span><span><span></span><span>references</span><span>:</span><span>\n</span></span></span><span><span> 7</span><span><span> </span>- <span></span><span>\n</span></span></span><span><span> 8</span><span><span> </span>- <span></span><span>\n</span></span></span><span><span> 9</span><span><span> </span>- <span></span><span>\n</span></span></span><span><span>10</span><span><span></span><span>author</span><span>:</span><span> </span><span>Ivan Saakov, Nasreddine Bencherchali</span><span>\n</span></span></span><span><span>11</span><span><span></span><span>date</span><span>:</span><span> </span><span>2025-10-19</span><span>\n</span></span></span><span><span>12</span><span><span></span><span>tags</span><span>:</span><span>\n</span></span></span><span><span>13</span><span><span> </span>- <span>attack.credential-access</span><span>\n</span></span></span><span><span>14</span><span><span> </span>- <span>attack.t1110</span><span>\n</span></span></span><span><span>15</span><span><span></span><span>logsource</span><span>:</span><span>\n</span></span></span><span><span>16</span><span><span> </span><span>product</span><span>:</span><span> </span><span>aws</span><span>\n</span></span></span><span><span>17</span><span><span> </span><span>service</span><span>:</span><span> </span><span>cloudtrail</span><span>\n</span></span></span><span><span>18</span><span><span></span><span>detection</span><span>:</span><span>\n</span></span></span><span><span>19</span><span><span> </span><span>selection</span><span>:</span><span>\n</span></span></span><span><span>20</span><span><span> </span><span>eventName</span><span>:</span><span> </span><span>'ConsoleLogin'</span><span>\n</span></span></span><span><span>21</span><span><span> </span><span>errorMessage</span><span>:</span><span> </span><span>'Failed authentication'</span><span>\n</span></span></span><span><span>22</span><span><span> </span><span>condition</span><span>:</span><span> </span><span>selection</span><span>\n</span></span></span><span><span>23</span><span><span></span><span>falsepositives</span><span>:</span><span>\n</span></span></span><span><span>24</span><span><span> </span>- <span>Legitimate failed login attempts by authorized users. Investigate the source of repeated failed login attempts.</span><span>\n</span></span></span><span><span>25</span><span><span></span><span>level</span><span>:</span><span> </span><span>medium</span><span>\n</span></span></span></code></pre></div>\n</div>\n</div></div></div></div>"
},
"unread": {
"type": "boolean",
"example": true,
"default": true
},
"categories": {
"type": "array",
"items": {
"type": "object",
"properties": {
"id": {
"type": "string",
"example": "enterprise/christeam/category/a1b9d077-7806-4b29-8f1c-d17ebc172ea3"
},
"label": {
"type": "string",
"example": "AI: Ad-Hoc Research"
}
}
}
},
"commonTopics": {
"type": "array",
"items": {
"type": "object",
"properties": {
"type": {
"type": "string",
"example": "detectionRule"
},
"label": {
"type": "string",
"example": "Sigma rules"
},
"id": {
"type": "string",
"example": "nlp/f/topic/7010"
},
"score": {
"type": "integer",
"example": 1,
"default": 0
},
"salienceLevel": {
"type": "string",
"example": "about"
}
}
}
},
"entities": {
"type": "array",
"items": {
"type": "object",
"properties": {
"type": {
"type": "string",
"example": "org"
},
"disambiguated": {
"type": "boolean",
"example": true,
"default": true
},
"label": {
"type": "string",
"example": "Amazon Web Services"
},
"id": {
"type": "string",
"example": "nlp/f/entity/gz:org:amazon-web-services"
},
"mentions": {
"type": "array",
"items": {
"type": "object",
"properties": {
"text": {
"type": "string",
"example": "AWS"
}
}
}
},
"salienceLevel": {
"type": "string",
"example": "about"
}
}
}
},
"leoSummary": {
"type": "object",
"properties": {
"sentences": {
"type": "array",
"items": {
"type": "object",
"properties": {}
}
}
}
},
"indicatorsOfCompromise": {
"type": "object",
"properties": {
"mentions": {
"type": "array",
"items": {
"type": "object",
"properties": {}
}
},
"exports": {
"type": "array",
"items": {
"type": "object",
"properties": {}
}
},
"sigmaRules": {
"type": "object",
"properties": {
"count": {
"type": "integer",
"example": 1,
"default": 0
},
"url": {
"type": "string",
"example": ""
}
}
}
}
},
"attackNavigator": {
"type": "object",
"properties": {
"url": {
"type": "string",
"example": ""
},
"ttpCount": {
"type": "integer",
"example": 1,
"default": 0
}
}
},
"sources": {
"type": "array",
"items": {
"type": "object",
"properties": {
"streamId": {
"type": "string",
"example": "feed/"
},
"title": {
"type": "string",
"example": "Detection rules"
},
"feedlyFeedType": {
"type": "string",
"example": "WebAlert"
},
"searchTerms": {
"type": "object",
"properties": {
"parts": {
"type": "array",
"items": {
"type": "object",
"properties": {
"id": {
"type": "string",
"example": "nlp/f/topic/7010"
},
"label": {
"type": "string",
"example": "Sigma rules"
}
}
}
},
"isComplexFilter": {
"type": "boolean",
"example": true,
"default": true
}
}
}
}
}
}
}
}
}
}
}
},
"400": {
"description": "400",
"content": {
"application/json": {
"examples": {
"Result": {
"value": "{}"
}
},
"schema": {
"type": "object",
"properties": {}
}
}
}
}
},
"deprecated": false
}
}
},
"x-readme": {
"headers": [],
"explorer-enabled": true,
"proxy-enabled": true
},
"x-readme-fauxas": true,
"_id": "6643b6e8d54f2c0010c9711b:68f943e369a2ccbf9f57e0e8"
}