Amazon GuardDuty Threat Detection
Workflow capability for security teams using Amazon GuardDuty for AWS threat detection and response. Covers finding management, detector configuration, threat intelligence integration, and automated response workflows.
What You Can Do
MCP Tools
list-detectors
List all active GuardDuty detectors across the account
get-detector-status
Get the configuration and status of a GuardDuty detector
list-threat-findings
List active threat findings detected by GuardDuty with severity filters
get-finding-details
Get detailed information about specific threat findings including full context
archive-findings
Archive threat findings that have been reviewed and resolved
create-finding-filter
Create a suppression filter to reduce noise from benign findings
list-finding-filters
List all finding suppression filters
list-trusted-ip-sets
List trusted IP address sets excluded from threat detection
create-trusted-ip-set
Create a trusted IP set to exclude known safe IPs from alerts
list-threat-intel-sets
List threat intelligence sets used for enhanced detection
get-findings-statistics
Get finding statistics and severity counts for security posture overview
list-members
List member accounts monitored by this GuardDuty administrator account