UpdateFindingsFeedback
UpdateFindingsFeedback
Event
Submits USEFUL or NOT_USEFUL feedback and optional comments for findings associated with a detector. It does not perform ArchiveFindings or create a suppression filter. Treat findings’ visibility and state separately from feedback.
Security Context
Normal analyst triage uses this API. Unexpected feedback can provide investigation context, but it is not sufficient evidence of defense impairment; no ATT&CK mapping is assigned. A comment claiming a pentest is caller-supplied text, not proof of authorization.
Log Source
CloudTrail management event with eventSource: guardduty.amazonaws.com and eventName: UpdateFindingsFeedback. Check errors and resulting resource state; a null response does not by itself indicate failure.
Key Fields
| Field | Investigation value |
|---|---|
requestParameters.detectorId, findingIds | Regional detector and affected findings; resolve their actual contents. |
requestParameters.feedback, comments | Feedback and claimed rationale, not a suppression configuration. |
eventTime, awsRegion, recipientAccountId, eventID | Timeline, service Region, account, and correlation identifiers. |
What to Investigate
- Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
- Verify caller authorization and the triage record, then retrieve the referenced findings.
- Compare feedback with actual finding state and ArchiveFindings events.
- Correlate CreateFilter or detector changes only if present; do not invent earlier findings or an evasion chain.
Sample Event
Synthetic scenario. Draco labels two fictional finding IDs NOT_USEFUL. The record does not establish their finding types, whether they concern him, or an authorized pentest.
Exact CloudTrail field presence, service-event details, response nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not establish content sensitivity, ownership intent, or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T21:36:50Z", "eventSource": "guardduty.amazonaws.com", "eventName": "UpdateFindingsFeedback", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "detectorId": "0123456789abcdef0123456789abcdef", "findingIds": [ "f2c0a4d4e5b6a7c8d9e0f1a2b3c4d5e6", "a3d1b5e5f6c7b8d9e0f1a2b3c4d5e6f7" ], "feedback": "NOT_USEFUL", "comments": "false positive \u2014 internal pentest" }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000111001000", "eventID": "90000000-0000-4000-8000-000111001001", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "guardduty.us-east-1.amazonaws.com" }}