Netskope Help

Supported AWS Entities for Real-time Protection

The table below describes the AWS services and attributes supported by Netskope for Real-time Protection.

  • Supported browser activities are qualified on Google Chrome.

  • Supported CLI activities are qualified on AWS CLI versions 1.7 and 2.0 for SQS, SNS, and S3.

Category

Entity/service

Attributes

Browser Activity

CLI Activity

Collaboration service

WorkDocs

Comment

Create, Delete

CLI Never qualified

Account

Edit, Delete

CLI Never qualified

Link

Share, Delete

CLI Never qualified

User

Login Attempt, Login Failed, Logout, Invite, Login Successful

CLI Never qualified

File

Edit, Create, Move, Share, Upload, Download, View, Delete

CLI Never qualified

Folder

Edit, Create, Move, View, Delete

CLI Never qualified

Compute

EC2

Volume

Create, Edit, Attach, Detach, Delete

Create, Delete, View

Snapshot

Create, Edit, Delete

Create, Delete, View

Instances

Create, Edit, View, Start, Shutdown, Delete, Reboot, Attach

Create, Delete

Tags

Create, Delete

Create, Delete, View

AMIs

Create, Edit, Delete, Share, View All

Load Balancer

Create, Edit, Delete

Security Group

Create, Edit, Delete

Edit, Create, Delete

Elastic IPs

Create, Attach, Detach, Delete

Placement Groups

Create, Delete

Edit, Create, Delete

Key Pairs

Create, Delete, Upload, Download

Attach, View,

Launch Configuration

Create, Delete, Edit

Login

Login Attempt, Login Failed, Login Successful, Logout

Auto Scaling group

Create, Edit, Delete

Spot Requests

Create, Delete, View All

Network Interfaces

Create, Delete

Attach, Detach

Reports

View

Lambda

Function

Edit, Create, Publish, Download, Delete, View All, View

Create, Delete, View

Layer

Create, Delete

Trigger

Create, View, Delete

Create, Delete

Alias

Create, View, Delete

Create, Delete

File

Upload

Configurations

View

Container Service

ECR

Repository

Edit, Create, Delete

View, Create, Delete

Rule

Edit, Create, Delete

Images

View

View

Token

View

View

Tag

Edit, Create, Delete

Policy

Edit, View, Delete

Delete

Permission

Edit, Delete

EC2 ContainerService

Task

Start, Create

CLI Never qualified

Repository

Create, Delete

CLI Never qualified

Service

Edit, Create, Delete

CLI Never qualified

Cluster

Create, Delete

CLI Never qualified

Images

Create

CLI Never qualified

Folder

Create, Delete

CLI Never qualified

Cluster

EKS

CreateCluster, CreateFargateProfile, DeleteCluster, ListClusters, DeleteFargateProfile, DescribeCluster, DescribeFargateProfile, ListFargateProfiles, TagResource, UntagResource, ListTagsForResource, CreateNodegroup, DeleteNodegroup DescribeNodegroup, ListNodegroups, ListUpdates , DescribeUpdate, UpdateClusterConfig, UpdateClusterVersion, UpdateNodegroupConfig, UpdateNodegroupVersion

Database

RDS

Engine

View All

Group

Edit, Create, Copy, View All, Delete, View

Edit, Create, Copy, View All, Delete, View

Option

View All

Parameters

View All

Database

Edit, Create, Reboot, Start, Shutdown, Download, Copy, View All, Delete

Edit, Create, Reboot, Start, Shutdown, Download, Copy, View All, Delete

File

Download, View All

Settings

View All

Instance

Edit, View All, View

Edit, View All, View

Cluster

Edit, View All, Copy, Create, Delete, View

Tag

View All

Snapshot

Edit, Create, Copy, View All, Delete, View

Certificates

View All

Policy

Edit, Create, Delete

Action

View All

Event

Edit, Create, View, View All, Delete

Subscription

Edit, Create, View All, Delete

DynamoDB

Node

Edit, Reboot, Delete

Index

Create, Delete

Task

Create, Delete

Group

Edit, Create, Delete

Subnet

Edit, Create, Delete

Cluster

Edit, View All, Copy, Create, Delete, View

Table

Create, Delete

Create, Delete

Snapshot

Edit, Create, Copy, View All, Delete, View

Certificates

View All

Policy

Edit, Create, Delete

Action

View All

Event

Edit, Create, View, View All, Delete

Subscription

Edit, Create, View All, Delete

Drive

CloudDrive

Folder

Create, Delete, View

Create, Delete, View

File

Delete All, Edit, Create, Share, Upload, Download, View, Delete

Delete All, Edit, Create, Share, Upload, Download, View, Delete

Settings

Edit

Identity Management

IAM

Groups

Create, Delete, Edit

Create, Delete, Edit, View, View All, Attach, Detach

Users

Create, Delete, Edit

Create, Delete, Edit, View, View All, Attach, Detach

Roles

Create, Delete

Create, Delete, Edit, View, View All, Attach, Detach

Policies

Create, Delete, Attach, Detach

Create, Delete, Edit, View, View All, Attach, Detach

Messaging Service

SQS

Queue

Edit, Create, Post, Delete

Edit, Create, Post, Delete

Message

Post, Delete

Post, Delete

Poll

Start, Stop

Network

VPC

Virtual Network

Edit, Attach, Create, Detach, Delete

Logs

Create

Tags

Edit

Notification service

SNS

Topic

Edit, Subscribe, Create, Unsubscribe, Delete

Edit, Subscribe, Create, Unsubscribe, Delete

Application

Edit, Create, Delete

Edit, Create, Delete

Message

Post

Post

Security

KMS

User

Edit, Terminate

Key

Edit, Create, Stop, Start, Terminate

Edit, Create, Stop, Start, Terminate

Storage

S3

Bucket

Edit, View All, Upload, Delete, Create, View

Create, Delete

Files

Copy, Edit, Create, Move, Share, Upload, Sync, Download, View, View All, Delete

Upload, Download, Sync, Copy, Edit and Delete

Folder

Edit, Create, Delete, View

Copy and Delete

Tags

Create, Edit and Delete

Create, Edit and Delete

Image

Upload

Upload