This document lists all 150 AWS services supported by the AWS Inventory Tool, along with the specific resource types collected for each service.
Legend:
- (global) - Service is collected once globally, not per-region
Amazon Elastic Compute Cloud
instance- EC2 instancesvolume- EBS volumessnapshot- EBS snapshotsami- Amazon Machine Images (owned)security-group- Security groupskey-pair- Key pairselastic-ip- Elastic IP addressesnetwork-interface- Network interfacesplacement-group- Placement groups
AWS Lambda
function- Lambda functionslayer- Lambda layersevent-source-mapping- Event source mappings
Amazon Elastic Container Service
cluster- ECS clustersservice- ECS servicestask-definition- Task definitionscapacity-provider- Capacity providers
Amazon Elastic Kubernetes Service
cluster- EKS clustersnodegroup- Node groupsfargate-profile- Fargate profilesaddon- EKS add-ons
Amazon Elastic Container Registry
repository- ECR repositories
Amazon ECR Public
repository- Public repositories
Amazon Lightsail
instance- Lightsail instancesdatabase- Managed databasesbucket- Object storage bucketsdisk- Block storage disksload-balancer- Load balancerscontainer-service- Container servicesdistribution- CDN distributionscertificate- SSL/TLS certificatesdomain- DNS domainsstatic-ip- Static IPskey-pair- SSH key pairs
Amazon EC2 Auto Scaling
auto-scaling-group- Auto Scaling groupslaunch-configuration- Launch configurationsscaling-policy- Scaling policiesscheduled-action- Scheduled actions
AWS Application Auto Scaling
scalable-target- Scalable targetsscaling-policy- Scaling policies
AWS Elastic Beanstalk
application- Applicationsapplication-version- Application versionsenvironment- Environments
AWS Batch
compute-environment- Compute environmentsjob-queue- Job queuesjob-definition- Job definitionsscheduling-policy- Scheduling policies
AWS App Runner
service- App Runner servicesconnection- Source connectionsauto-scaling-configuration- Auto scaling configurationsvpc-connector- VPC connectorsobservability-configuration- Observability configurationsvpc-ingress-connection- VPC ingress connections
EC2 Image Builder
pipeline- Image pipelinesimage-recipe- Image recipescontainer-recipe- Container recipesinfrastructure-configuration- Infrastructure configurationsdistribution-configuration- Distribution configurationscomponent- Componentsworkflow- Workflowslifecycle-policy- Lifecycle policies
Amazon Simple Storage Service
bucket- S3 bucketstable-bucket- S3 Tables table bucketsnamespace- S3 Tables namespacestable- S3 Tables tables
Amazon Elastic File System
file-system- EFS file systemsaccess-point- Access pointsreplication-configuration- Replication configurations
Amazon FSx
file-system-lustre- FSx for Lustrefile-system-windows- FSx for Windows File Serverfile-system-ontap- FSx for NetApp ONTAPfile-system-openzfs- FSx for OpenZFSvolume-ontap- ONTAP volumesvolume-openzfs- OpenZFS volumesbackup- FSx backups
AWS Backup
vault- Backup vaultsplan- Backup plansframework- Audit frameworksreport-plan- Report plansrestore-testing-plan- Restore testing plans
AWS DataSync
agent- DataSync agentslocation- Source/destination locationstask- Transfer tasks
Amazon Data Lifecycle Manager
lifecycle-policy- Lifecycle policies
AWS Storage Gateway
gateway- Storage gatewaysfile-share- File sharesvolume- Storage volumestape- Virtual tapes
Amazon Relational Database Service
db-instance- RDS instancesdb-cluster- Aurora clustersdb-snapshot- Manual DB snapshotsdb-cluster-snapshot- Manual cluster snapshotsdb-subnet-group- Subnet groupsdb-parameter-group- Parameter groups (custom only)option-group- Option groups (custom only)db-proxy- RDS Proxy
Amazon DynamoDB
table- DynamoDB tablesglobal-table- Global tablesbackup- On-demand backupsstream- DynamoDB Streams
Amazon ElastiCache
cluster- Cache clustersreplication-group- Replication groupsserverless-cache- Serverless cachesuser-group- User groups
Amazon MemoryDB for Redis
cluster- MemoryDB clustersuser- Usersacl- Access control lists
Amazon DocumentDB
cluster- DocumentDB clustersinstance- Cluster instances
Amazon Neptune
cluster- Neptune clustersinstance- Cluster instances
Amazon Redshift
cluster- Redshift clusterssubnet-group- Subnet groupsparameter-group- Parameter groupsserverless-namespace- Serverless namespacesserverless-workgroup- Serverless workgroups
Amazon Redshift Serverless
namespace- Namespacesworkgroup- Workgroupssnapshot- Snapshots
Amazon Keyspaces (for Apache Cassandra)
keyspace- Keyspacestable- Tables
Amazon OpenSearch Service
domain- OpenSearch domainsserverless-collection- Serverless collections
Amazon OpenSearch Serverless
collection- Collectionssecurity-policy- Security policiesaccess-policy- Access policiesvpc-endpoint- VPC endpoints
Amazon DynamoDB Accelerator
cluster- DAX clustersparameter-group- Parameter groupssubnet-group- Subnet groups
Amazon Aurora DSQL
cluster- DSQL clusters
Amazon Timestream for InfluxDB
db_instance- DB instancesdb_parameter_group- DB parameter groups
Amazon Virtual Private Cloud
vpc- VPCssubnet- Subnetsroute-table- Route tablesinternet-gateway- Internet gatewaysnat-gateway- NAT gatewaysnetwork-acl- Network ACLsvpc-endpoint- VPC endpointsvpc-peering- Peering connectionstransit-gateway- Transit gatewaystransit-gateway-attachment- Transit gateway attachmentsdhcp-options- DHCP option sets
Elastic Load Balancing v2
load-balancer- Application/Network/Gateway Load Balancerstarget-group- Target groupslistener- Listeners
Elastic Load Balancing (Classic)
classic-load-balancer- Classic Load Balancers
Amazon Route 53
hosted-zone- Hosted zoneshealth-check- Health checksquery-logging-config- Query logging configurations
Amazon Route 53 Resolver
resolver-endpoint- Resolver endpointsresolver-rule- Resolver rulesquery-log-config- Query log configurationsfirewall-rule-group- DNS Firewall rule groupsfirewall-domain-list- DNS Firewall domain lists
Amazon Route 53 Domains
domain- Registered domains
Amazon CloudFront
distribution- CDN distributionsfunction- CloudFront Functionsorigin-access-identity- Origin access identities (legacy)origin-access-control- Origin access controlscache-policy- Cache policies
AWS Global Accelerator
accelerator- Acceleratorslistener- Listenersendpoint-group- Endpoint groupscustom-routing-accelerator- Custom routing acceleratorsbyoip-cidr- BYOIP CIDRscross-account-attachment- Cross-account attachments
Amazon API Gateway (REST)
rest-api- REST APIsstage- Stagesapi-key- API keysusage-plan- Usage plansvpc-link- VPC links
Amazon API Gateway (HTTP/WebSocket)
http-api- HTTP APIswebsocket-api- WebSocket APIsstage- Stagesdomain-name- Custom domain namesvpc-link- VPC links
AWS AppSync
graphql-api- GraphQL APIsdata-source- Data sourcesfunction- Functionsapi-key- API keysdomain-name- Custom domain names
AWS Direct Connect
connection- Connectionsgateway- Direct Connect gatewaysvirtual-interface-private- Private virtual interfacesvirtual-interface-public- Public virtual interfacesvirtual-interface-transit- Transit virtual interfaceslag- Link aggregation groups
AWS Network Firewall
firewall- Firewallsfirewall-policy- Firewall policiesrule-group- Rule groupstls-inspection-configuration- TLS inspection configurations
AWS Cloud Map
namespace- Namespacesservice- Servicesinstance- Service instances
Amazon VPC Lattice
service-network- Service networksservice- Servicestarget-group- Target groupslistener- Listenersrule- Listener rulesservice-network-vpc-association- VPC associationsservice-network-service-association- Service associationsaccess-log-subscription- Access log subscriptions
AWS Network Manager
global-network- Global networkssite- Sitesdevice- Deviceslink- Linksconnection- Connections
AWS Identity and Access Management
user- IAM usersgroup- IAM groupsrole- IAM rolespolicy- Customer managed policiesinstance-profile- Instance profilessaml-provider- SAML providersoidc-provider- OIDC providers
AWS IAM Identity Center
instance- Identity Center instancespermission-set- Permission setsuser- Usersgroup- Groups
AWS Key Management Service
key- Customer managed keysalias- Key aliases
AWS Secrets Manager
secret- Secrets
AWS Certificate Manager
certificate- SSL/TLS certificates
AWS Private Certificate Authority
certificate-authority- Private CAspermission- CA permissions
AWS WAF v2
web-acl-regional- Regional Web ACLsweb-acl-cloudfront- CloudFront Web ACLsip-set-regional- Regional IP setsip-set-cloudfront- CloudFront IP setsrule-group-regional- Regional rule groupsrule-group-cloudfront- CloudFront rule groupsregex-pattern-set-regional- Regional regex pattern setsregex-pattern-set-cloudfront- CloudFront regex pattern sets
Amazon GuardDuty
detector- Detectorsfilter- Filtersip-set- Trusted IP liststhreat-intel-set- Threat intelligence sets
Amazon Inspector
account-status- Account statusfilter- Suppression rules
AWS Security Hub
hub- Security Hub enablementenabled-standard- Enabled standardsinsight- Custom insightsautomation-rule- Automation rules
AWS Directory Service
directory- Directories
Amazon Cognito
user-pool- User poolsuser-pool-client- App clientsidentity-pool- Identity pools
AWS IAM Access Analyzer
analyzer- Analyzersarchive-rule- Archive rules
Amazon Macie
classification-job- Classification jobscustom-data-identifier- Custom data identifiersfindings-filter- Findings filtersallow-list- Allow listsmember- Member accounts
Amazon Detective
graph- Behavior graphsmember- Member accountsinvestigation- Investigations
AWS Shield Advanced
subscription- Shield Advanced subscriptionprotection- Protected resourcesprotection-group- Protection groups
AWS Firewall Manager
policy- Security policiesapps-list- Application listsprotocols-list- Protocol listsresource-set- Resource sets
AWS CloudHSM
cluster- HSM clustersbackup- Cluster backups
AWS Audit Manager
assessment- Assessmentsframework- Custom frameworks
Amazon Security Lake
data-lake- Data lake configurationsubscriber- Subscribers
Amazon CloudWatch
metric-alarm- Metric alarmscomposite-alarm- Composite alarmsdashboard- Dashboardsmetric-stream- Metric streams
Amazon CloudWatch Logs
log-group- Log groupsdestination- Destinations
AWS CloudTrail
trail- Trailsevent-data-store- Event data stores
AWS Systems Manager
parameter- Parameter Store parametersdocument- SSM documents (custom only)maintenance-window- Maintenance windowspatch-baseline- Patch baselines (custom only)association- State Manager associations
AWS Config
configuration-recorder- Configuration recordersdelivery-channel- Delivery channelsconfig-rule- Config rulesconformance-pack- Conformance packsconfiguration-aggregator- Aggregators
Amazon Simple Notification Service
topic- SNS topicssubscription- Subscriptions
Amazon Simple Queue Service
queue- SQS queues
Amazon EventBridge
event-bus- Event busesrule- Rulesarchive- Archivesapi-destination- API destinationsconnection- Connections
AWS X-Ray
group- X-Ray groupssampling-rule- Sampling rules
Amazon Managed Grafana
workspace- Grafana workspaces
Amazon Managed Service for Prometheus
workspace- Prometheus workspacesrule-groups-namespace- Rule groupsalert-manager- Alert manager configurations
AWS Cost Explorer
cost-category- Cost categoriesanomaly-monitor- Anomaly monitorsanomaly-subscription- Anomaly subscriptionssavings-plan- Savings Plans
AWS Budgets
budget- Budgetsbudget-action- Budget actions
AWS Compute Optimizer
ec2-recommendation- EC2 recommendationsasg-recommendation- Auto Scaling recommendationsebs-recommendation- EBS recommendationslambda-recommendation- Lambda recommendations
Service Quotas
quota-request- Quota increase requests
AWS Resource Groups
group- Resource groups
AWS Health
event- Health events
Amazon CloudWatch Synthetics
canary- Canariesgroup- Canary groups
AWS AppConfig
application- Applicationsenvironment- Environmentsconfiguration-profile- Configuration profilesdeployment-strategy- Deployment strategies
AWS Organizations
organization- Organizationroot- Rootorganizational-unit- Organizational unitsaccount- Member accountspolicy- SCPs and other policiesdelegated-administrator- Delegated administrators
AWS Service Catalog
portfolio- Portfoliosproduct- Products
AWS Resilience Hub
app- Applicationsresiliency-policy- Resiliency policies
AWS Step Functions
state-machine- State machinesactivity- Activities
Amazon Kinesis Data Streams
stream- Data streamsstream-consumer- Enhanced fan-out consumers
Amazon Kinesis Data Firehose
delivery-stream- Delivery streams
Amazon Managed Streaming for Apache Kafka
cluster- MSK clustersserverless-cluster- Serverless clustersconfiguration- Cluster configurationsconnector- MSK Connect connectors
AWS Serverless Application Repository
application- Published applications
Amazon EventBridge Scheduler
schedule-group- Schedule groupsschedule- Schedules
Amazon EventBridge Pipes
pipe- Pipes
Amazon EventBridge Schema Registry
registry- Registriesdiscoverer- Schema discoverers
AWS CloudFormation
stack- Stacksstack-set- Stack sets
AWS CodeArtifact
domain- Domainsrepository- Repositoriespackage-group- Package groups
AWS CodeBuild
project- Build projectsreport-group- Report groups
AWS CodePipeline
pipeline- Pipelines
AWS CodeDeploy
application- Applicationsdeployment-group- Deployment groupsdeployment-config- Deployment configurations
AWS Device Farm
project- Projectstest-grid-project- Desktop browser testing projectsvpce-configuration- VPC endpoint configurations
Amazon Athena
workgroup- Workgroupsdata-catalog- Data catalogs (custom only)named-query- Named queries
AWS Glue
database- Data Catalog databasestable- Data Catalog tablesjob- ETL jobscrawler- Crawlersconnection- Connectionsregistry- Schema registries
Amazon Managed Workflows for Apache Airflow
environment- MWAA environments
AWS Lake Formation
registered-resource- Registered resourceslf-tag- LF-Tagsdata-cells-filter- Data cell filters
Amazon EMR
cluster- EMR clusters (active)studio- EMR Studiosserverless-application- EMR Serverless applications
Amazon EMR Serverless
application- Applications
AWS Clean Rooms
collaboration- Collaborationsmembership- Membershipsconfigured-table- Configured tables
Amazon QuickSight
dashboard- Dashboardsdata-set- Data setsdata-source- Data sourcesanalysis- Analyses
Amazon DataZone
domain- Domainsproject- Projectsenvironment- Environments
Amazon SageMaker
notebook-instance- Notebook instancesendpoint- Inference endpointsmodel- Modelsdomain- SageMaker Studio domainstraining-job- Training jobs (active)feature-group- Feature groups
Amazon Bedrock
custom-model- Custom modelscustomization-job- Model customization jobs (active)provisioned-throughput- Provisioned throughputguardrail- Guardrailsagent- Bedrock Agentsknowledge-base- Knowledge basesdata-source- Knowledge base data sources
Amazon Lex V2
bot- Botsbot-alias- Bot aliases
Amazon Rekognition
collection- Face collectionsproject- Custom Labels projectsstream-processor- Stream processors
Amazon Textract
adapter- Custom adapters
Amazon Transcribe
vocabulary- Custom vocabulariesvocabulary-filter- Vocabulary filterslanguage-model- Custom language modelscall-analytics-category- Call Analytics categories
Amazon Translate
terminology- Custom terminologiesparallel-data- Parallel data
Amazon Comprehend
document-classifier- Document classifiersentity-recognizer- Entity recognizersendpoint- Endpointsflywheel- Flywheels
Amazon Polly
lexicon- Pronunciation lexicons
Amazon Personalize
dataset-group- Dataset groupsdataset- Datasetssolution- Solutionscampaign- Campaigns
Amazon Kendra
index- Indexesdata-source- Data sources
Amazon Fraud Detector
detector- Detectorsevent-type- Event typesmodel- Models
AWS Elemental MediaConvert
queue- Queuespreset- Presetsjob-template- Job templates
AWS Elemental MediaConnect
flow- Flowsbridge- Bridgesgateway- Gateways
AWS Elemental MediaPackage
channel- Channelsorigin-endpoint- Origin endpoints
AWS Elemental MediaLive
channel- Channelsinput- Inputsinput-security-group- Input security groups
AWS Elemental MediaStore
container- Containers
AWS Elemental MediaTailor
playback-configuration- Playback configurationschannel- Channelssource-location- Source locations
Amazon Interactive Video Service
channel- Channelsrecording-configuration- Recording configurationsplayback-key-pair- Playback key pairs
AWS Transfer Family
server- SFTP/FTPS/FTP serversuser- Server usersworkflow- Workflowsconnector- SFTP connectorscertificate- Certificatesprofile- AS2 profilesagreement- AS2 agreementshost-key- SSH host keysweb-app- Web apps
AWS Database Migration Service
replication-instance- Replication instancesendpoint- Source/target endpointsreplication-task- Migration tasksreplication-subnet-group- Subnet groupscertificate- Certificates
Amazon WorkSpaces
workspace- WorkSpacesdirectory- WorkSpaces directories
AWS Amplify
app- Amplify appsbranch- Branchesdomain- Custom domains
Amazon Connect
instance- Connect instancescontact-flow- Contact flowsqueue- Queuesrouting-profile- Routing profiles
AWS IoT Core
thing- Thingsthing-type- Thing typesthing-group- Thing groupspolicy- IoT policiescertificate- Device certificates
AWS IoT SiteWise
asset- Assetsasset-model- Asset modelsgateway- Gatewaysportal- Portals
AWS Resource Access Manager
resource-share- Resource sharesresource-share-invitation- Pending invitations
AWS Resource Explorer
index- Indexesview- Views
Amazon MQ
broker- Message brokersconfiguration- Broker configurations
Amazon Simple Email Service v2
email-identity- Email identitiesconfiguration-set- Configuration setscontact-list- Contact listsdedicated-ip-pool- Dedicated IP poolsemail-template- Email templates
Amazon AppFlow
flow- Flowsconnector-profile- Connector profiles
Amazon GameLift
fleet- Fleetsbuild- Buildsscript- Scriptsalias- Aliasesgame-session-queue- Game session queuesmatchmaking-configuration- Matchmaking configurationsmatchmaking-rule-set- Matchmaking rule sets
AWS Outposts
outpost- Outpostssite- Sites
AWS Fault Injection Simulator
experiment-template- Experiment templatesexperiment- Experiments
Amazon Location Service
map- Mapsplace-index- Place indexesroute-calculator- Route calculatorsgeofence-collection- Geofence collectionstracker- Trackers
| Category | Services | Resource Types |
|---|---|---|
| Compute | 13 | 50+ |
| Storage | 7 | 25+ |
| Database | 14 | 45+ |
| Networking | 16 | 60+ |
| Security | 20 | 50+ |
| Management & Monitoring | 22 | 50+ |
| Serverless | 8 | 15+ |
| Developer Tools | 6 | 15+ |
| Analytics | 9 | 30+ |
| AI/ML | 12 | 40+ |
| Media | 7 | 20+ |
| Migration & Transfer | 2 | 15+ |
| End User Computing | 3 | 10+ |
| IoT | 2 | 10+ |
| Other | 9 | 25+ |
| Total | 150 | 415+ |
The following AWS default/managed resources are automatically excluded from inventory results to avoid noise:
| Service | Excluded Resources | Reason |
|---|---|---|
| keyspaces | system, system_schema, system_schema_mcs, system_multiregion_info keyspaces |
AWS system keyspaces (not user-created) |
| lakeformation | data-lake-settings |
Default settings that exist in every AWS account/region |
| mediaconvert | Default queue |
AWS default queue that exists in every region |
| route53resolver | AWSManagedDomains* firewall domain lists |
AWS-managed threat intelligence lists |
| timestream-influxdb | InfluxDBV3Core, InfluxDBV3Enterprise, InfluxDBV3Enterprise1Node parameter groups |
AWS default parameter groups (not user-created) |
| xray | Default group |
AWS default group that exists in every region |
These resources are created and managed by AWS automatically and are not considered user-owned infrastructure.
Some AWS services are global (account-wide) rather than regional. When filtering by region, awsmap intelligently handles these based on their control plane location.
These services have their control plane in us-east-1 and are included when scanning us-east-1 or with --include-global:
| Service | Description |
|---|---|
| iam | Identity and Access Management (users, roles, policies) |
| organizations | AWS Organizations (accounts, OUs, SCPs) |
| route53 | Route 53 DNS (hosted zones, records) |
| route53domains | Route 53 Domains (registered domains) |
| cloudfront | CloudFront CDN (distributions) |
| shield | AWS Shield (protections) |
| budgets | AWS Budgets |
| ce | Cost Explorer |
| health | AWS Health Dashboard |
These services have their control plane in us-west-2 and are included when scanning us-west-2 or with --include-global:
| Service | Description |
|---|---|
| networkmanager | Network Manager (global networks, transit gateways) |
| globalaccelerator | Global Accelerator (accelerators, endpoints) |
S3 bucket names are globally unique, but each bucket has a specific region. awsmap treats S3 as a regional service and filters buckets by their actual region when using -r.
Reference: AWS Global Services Documentation