Amazon GuardDuty features
Overview
Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior across your AWS environment. GuardDuty uses artificial intelligence (AI), machine learning (ML), anomaly detection, and malicious file discovery, using both AWS and industry-leading threat intelligence to help protect your AWS accounts, workloads, and data. Amazon GuardDuty is available as a security capability within the enhanced AWS Security Hub (Preview) and also as a standalone threat detection service. GuardDuty provides essential threat detection signals to help you prioritize your critical security issues and respond at scale. When using the enhanced Security Hub, GuardDuty findings are automatically enriched with critical context, allowing you to surface critical risks that may only become apparent when analyzed across the entire environment. GuardDuty is capable of analyzing tens of billions of events across multiple AWS data sources, including AWS CloudTrail logs, Amazon Virtual Private Cloud (Amazon VPC) Flow Logs, and DNS query logs. GuardDuty also monitors Amazon Simple Storage Service (Amazon S3) data events, Amazon Aurora login events, and runtime activity for Amazon Elastic Kubernetes Service (Amazon EKS), Amazon Elastic Compute Cloud (Amazon EC2), and Amazon Elastic Container Service (Amazon ECS)—including serverless container workloads on AWS Fargate.
