Select your cookie preferences

We use essential cookies and similar tools that are necessary to provide our site and services. We use performance cookies to collect anonymous statistics, so we can understand how customers use our site and make improvements. Essential cookies cannot be deactivated, but you can choose “Customize” or “Decline” to decline performance cookies.

If you agree, AWS and approved third parties will also use cookies to provide useful site features, remember your preferences, and display relevant content, including relevant advertising. To accept or decline all non-essential cookies, choose “Accept” or “Decline.” To make more detailed choices, choose “Customize.”

Skip to main content

Overview

Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior across your AWS environment. GuardDuty uses artificial intelligence (AI), machine learning (ML), anomaly detection, and malicious file discovery, using both AWS and industry-leading threat intelligence to help protect your AWS accounts, workloads, and data. Amazon GuardDuty is available as a security capability within the enhanced AWS Security Hub (Preview) and also as a standalone threat detection service. GuardDuty provides essential threat detection signals to help you prioritize your critical security issues and respond at scale. When using the enhanced Security Hub, GuardDuty findings are automatically enriched with critical context, allowing you to surface critical risks that may only become apparent when analyzed across the entire environment. GuardDuty is capable of analyzing tens of billions of events across multiple AWS data sources, including AWS CloudTrail logs, Amazon Virtual Private Cloud (Amazon VPC) Flow Logs, and DNS query logs. GuardDuty also monitors Amazon Simple Storage Service (Amazon S3) data events, Amazon Aurora login events, and runtime activity for Amazon Elastic Kubernetes Service (Amazon EKS), Amazon Elastic Compute Cloud (Amazon EC2), and Amazon Elastic Container Service (Amazon ECS)—including serverless container workloads on AWS Fargate.

Missing alt text value

Page topics

Key features

Open all