Amazon GuardDuty
Jon Bonso2025-11-30T11:06:09+00:00Bookmarks How It Works GuardDuty Findings Trusted IP Lists and Threat Lists Pricing Validate Your Knowledge Amazon GuardDuty Cheat Sheet An intelligent threat detection service. It analyzes billions of events across your AWS accounts from AWS CloudTrail (AWS user and API activity in your accounts), Amazon VPC Flow Logs (network traffic data), and DNS Logs (name query patterns). How It Works Backdoor: Compromised resource contacting a C&C server. CryptoCurrency: Mining software detected. Trojan: Silent malicious activity. Stealth: Attempting to hide actions/tracks. PenTest: Intentional testing tools or vulnerability scanners. EKS Protection: Monitors Kubernetes [...]
