Skip to main content

Amazon GuardDuty

AWS managed threat detection service that monitors CloudTrail, VPC Flow Logs, and DNS logs for anomalies across accounts and workloads.

Technical Architecture & Overview

Amazon GuardDuty is a managed threat detection service from AWS. It continuously monitors AWS CloudTrail management events, VPC Flow Logs, Route 53 DNS query logs, and optional protection plans for EKS, ECS, EC2, S3, RDS, Lambda, and AI workloads. GuardDuty uses threat intelligence feeds, anomaly detection, and machine learning to produce findings.

Targeted Technical Use Cases

Continuous threat detection and anomaly detection across AWS accounts, workloads, and data without agent deployment for foundational features.

Evaluation & Trade-offs

Core Strengths

  • +Managed service with no infrastructure to maintain for foundational features.
  • +Integrates with AWS Security Hub, SNS, and Lambda for automated response.
  • +Broad data source coverage including CloudTrail, VPC Flow Logs, and DNS logs.

Trade-Offs & Limitations

  • -Costs scale with analyzed log volume and enabled protection plans.
  • -Can generate noisy or unclear findings that require tuning.
  • -Cannot inspect non-AWS environments.

Defensive Security Application

Enable GuardDuty in all active AWS regions and route findings to a SIEM or ticketing workflow for investigation and automated response.

Frequently Asked Questions

What is Amazon GuardDuty?

Amazon GuardDuty is a managed threat detection service from AWS. It continuously monitors AWS CloudTrail management events, VPC Flow Logs, Route 53 DNS query logs, and optional protection plans for EKS, ECS, EC2, S3, RDS, Lambda, and AI workloads. GuardDuty uses threat intelligence feeds, anomaly detection, and machine learning to produce findings.

What is Amazon GuardDuty used for?

Continuous threat detection and anomaly detection across AWS accounts, workloads, and data without agent deployment for foundational features.

What are the strengths of Amazon GuardDuty?
  • +Managed service with no infrastructure to maintain for foundational features.
  • +Integrates with AWS Security Hub, SNS, and Lambda for automated response.
  • +Broad data source coverage including CloudTrail, VPC Flow Logs, and DNS logs.
What are the limitations of Amazon GuardDuty?
  • +Costs scale with analyzed log volume and enabled protection plans.
  • +Can generate noisy or unclear findings that require tuning.
  • +Cannot inspect non-AWS environments.
How is Amazon GuardDuty used defensively?

Enable GuardDuty in all active AWS regions and route findings to a SIEM or ticketing workflow for investigation and automated response.