Amazon GuardDuty

2025-12-26T18:35:43+00:00

Bookmarks How It Works GuardDuty Findings Trusted IP Lists and Threat Lists Pricing Validate Your Knowledge Amazon GuardDuty Cheat Sheet Amazon GuardDuty is an intelligent threat detection service that analyzes billions of events across your AWS accounts from: AWS CloudTrail (user and API activity) Amazon VPC Flow Logs (network traffic) DNS Logs (name query patterns) Features UnauthorizedAccess: Detects API calls from external hosts using Lambda-created temporary credentials. Extended Threat Detection: Detects multi-stage attacks (EC2/ECS/EKS sequences). Runtime Monitoring Updates: Monitors latest agent versions for EC2, ECS, EKS-Fargate. Malware Protection for Backup: Scans EBS [...]