Amazon GuardDuty logo

Amazon GuardDuty

Amazon GuardDuty is an intelligent threat detection service that continuously monitors your AWS accounts, workloads, and data for malicious activity. It uses machine learning, anomaly detection, and integrated threat intelligence to identify and prioritize potential threats to your AWS environment.

1 APIs 6 Features
Anomaly DetectionComplianceMachine LearningMonitoringSecurityThreat Detection

APIs

Amazon GuardDuty API

The Amazon GuardDuty API provides programmatic access to manage detectors, findings, filters, trusted IP sets, and threat intelligence for continuous threat detection across AWS...

Features

Intelligent Threat Detection

Uses ML and anomaly detection to identify threats without manual configuration or rule management.

Integrated Threat Intelligence

Incorporates curated threat intelligence feeds from AWS, CrowdStrike, and Proofpoint for enhanced detection.

Multi-Account Support

Monitor all accounts in an AWS Organization from a central administrator account.

Continuous Monitoring

Analyzes CloudTrail, VPC Flow Logs, DNS logs, and S3 access logs 24/7 without performance impact.

Finding Prioritization

Automatically prioritizes findings by severity (Low, Medium, High) for efficient response.

Malware Protection

Scans EC2 instance volumes and S3 objects for malware and known threats.

Use Cases

Account Compromise Detection

Detect compromised AWS credentials and unauthorized API calls using ML-based anomaly detection.

Insider Threat Monitoring

Identify suspicious behavior from privileged users or compromised internal accounts.

Cryptocurrency Mining Detection

Detect and alert on unauthorized cryptocurrency mining using EC2 or Lambda resources.

Malware Detection

Scan workloads and data for malware and ransomware threats.

Data Exfiltration Prevention

Identify unusual data access patterns and potential exfiltration from S3 buckets.

Integrations

AWS Security Hub

Automatically send GuardDuty findings to Security Hub for centralized security management.

Amazon EventBridge

Trigger automated responses to findings using EventBridge rules and Lambda functions.

AWS Organizations

Enable GuardDuty organization-wide for centralized multi-account threat monitoring.

Amazon Detective

Investigate GuardDuty findings in depth using Detective for root cause analysis.

Amazon Macie

Combine with Macie for comprehensive data security and threat detection.

Semantic Vocabularies

Amazon Guardduty Context

247 classes · 297 properties

JSON-LD

API Governance Rules

Amazon GuardDuty API Rules

8 rules · 5 errors 2 warnings 1 info

SPECTRAL

JSON Structure

Amazon Guardduty Structure

12 properties

JSON STRUCTURE

Guardduty Accept Invitation Request Structure

2 properties

JSON STRUCTURE

Guardduty Access Control List Structure

2 properties

JSON STRUCTURE

Guardduty Access Key Details Structure

4 properties

JSON STRUCTURE

Guardduty Account Detail Structure

2 properties

JSON STRUCTURE

Guardduty Account Details Structure

0 properties

JSON STRUCTURE

Guardduty Account Free Trial Info Structure

3 properties

JSON STRUCTURE

Guardduty Account Free Trial Infos Structure

0 properties

JSON STRUCTURE

Guardduty Account Id Structure

0 properties

JSON STRUCTURE

Guardduty Account Ids Structure

0 properties

JSON STRUCTURE

Guardduty Account Level Permissions Structure

1 properties

JSON STRUCTURE

Guardduty Action Structure

7 properties

JSON STRUCTURE

Guardduty Addon Details Structure

2 properties

JSON STRUCTURE

Guardduty Admin Account Structure

2 properties

JSON STRUCTURE

Guardduty Admin Accounts Structure

0 properties

JSON STRUCTURE

Guardduty Admin Status Structure

0 properties

JSON STRUCTURE

Guardduty Administrator Structure

4 properties

JSON STRUCTURE

Guardduty Affected Resources Structure

0 properties

JSON STRUCTURE

Guardduty Archive Findings Request Structure

1 properties

JSON STRUCTURE

Guardduty Archive Findings Response Structure

0 properties

JSON STRUCTURE

Guardduty Auto Enable Members Structure

0 properties

JSON STRUCTURE

Guardduty Aws Api Call Action Structure

9 properties

JSON STRUCTURE

Guardduty Bad Request Exception Structure

0 properties

JSON STRUCTURE

Guardduty Block Public Access Structure

4 properties

JSON STRUCTURE

Guardduty Boolean Structure

0 properties

JSON STRUCTURE

Guardduty Bucket Level Permissions Structure

3 properties

JSON STRUCTURE

Guardduty Bucket Policy Structure

2 properties

JSON STRUCTURE

Guardduty City Structure

1 properties

JSON STRUCTURE

Guardduty Client Token Structure

0 properties

JSON STRUCTURE

Guardduty Condition Structure

12 properties

JSON STRUCTURE

Guardduty Container Structure

7 properties

JSON STRUCTURE

Guardduty Containers Structure

0 properties

JSON STRUCTURE

Guardduty Count By Coverage Status Structure

0 properties

JSON STRUCTURE

Guardduty Count By Resource Type Structure

0 properties

JSON STRUCTURE

Guardduty Count By Severity Structure

0 properties

JSON STRUCTURE

Guardduty Country Structure

2 properties

JSON STRUCTURE

Guardduty Coverage Filter Condition Structure

2 properties

JSON STRUCTURE

Guardduty Coverage Filter Criteria Structure

1 properties

JSON STRUCTURE

Guardduty Coverage Filter Criterion Structure

2 properties

JSON STRUCTURE

Guardduty Coverage Resource Details Structure

2 properties

JSON STRUCTURE

Guardduty Coverage Resource Structure

7 properties

JSON STRUCTURE

Guardduty Coverage Resources Structure

0 properties

JSON STRUCTURE

Guardduty Coverage Sort Criteria Structure

2 properties

JSON STRUCTURE

Guardduty Coverage Sort Key Structure

0 properties

JSON STRUCTURE

Guardduty Coverage Statistics Structure

2 properties

JSON STRUCTURE

Guardduty Coverage Statistics Type Structure

0 properties

JSON STRUCTURE

Guardduty Coverage Status Structure

0 properties

JSON STRUCTURE

Guardduty Create Detector Request Structure

6 properties

JSON STRUCTURE

Guardduty Create Detector Response Structure

2 properties

JSON STRUCTURE

Guardduty Create Filter Request Structure

7 properties

JSON STRUCTURE

Guardduty Create Filter Response Structure

1 properties

JSON STRUCTURE

Guardduty Create Ip Set Request Structure

6 properties

JSON STRUCTURE

Guardduty Create Ip Set Response Structure

1 properties

JSON STRUCTURE

Guardduty Create Members Request Structure

1 properties

JSON STRUCTURE

Guardduty Create Members Response Structure

1 properties

JSON STRUCTURE

Guardduty Criterion Key Structure

0 properties

JSON STRUCTURE

Guardduty Criterion Structure

0 properties

JSON STRUCTURE

Guardduty Data Source Free Trial Structure

1 properties

JSON STRUCTURE

Guardduty Data Source List Structure

0 properties

JSON STRUCTURE

Guardduty Data Source Status Structure

0 properties

JSON STRUCTURE

Guardduty Data Source Structure

0 properties

JSON STRUCTURE

Guardduty Data Sources Free Trial Structure

6 properties

JSON STRUCTURE

Guardduty Delete Detector Request Structure

0 properties

JSON STRUCTURE

Guardduty Delete Detector Response Structure

0 properties

JSON STRUCTURE

Guardduty Delete Filter Request Structure

0 properties

JSON STRUCTURE

Guardduty Delete Filter Response Structure

0 properties

JSON STRUCTURE

Guardduty Delete Ip Set Request Structure

0 properties

JSON STRUCTURE

Guardduty Delete Ip Set Response Structure

0 properties

JSON STRUCTURE

Guardduty Delete Members Request Structure

1 properties

JSON STRUCTURE

Guardduty Delete Members Response Structure

1 properties

JSON STRUCTURE

Guardduty Destination Properties Structure

2 properties

JSON STRUCTURE

Guardduty Destination Structure

3 properties

JSON STRUCTURE

Guardduty Destination Type Structure

0 properties

JSON STRUCTURE

Guardduty Destinations Structure

0 properties

JSON STRUCTURE

Guardduty Detector Feature Result Structure

0 properties

JSON STRUCTURE

Guardduty Detector Feature Structure

0 properties

JSON STRUCTURE

Guardduty Detector Id Structure

0 properties

JSON STRUCTURE

Guardduty Detector Ids Structure

0 properties

JSON STRUCTURE

Guardduty Detector Status Structure

0 properties

JSON STRUCTURE

Guardduty Dns Request Action Structure

3 properties

JSON STRUCTURE

Guardduty Domain Details Structure

1 properties

JSON STRUCTURE

Guardduty Double Structure

0 properties

JSON STRUCTURE

Guardduty Ebs Snapshot Preservation Structure

0 properties

JSON STRUCTURE

Guardduty Ebs Volume Details Structure

2 properties

JSON STRUCTURE

Guardduty Ebs Volume Scan Details Structure

6 properties

JSON STRUCTURE

Guardduty Ebs Volumes Result Structure

2 properties

JSON STRUCTURE

Guardduty Ecs Cluster Details Structure

8 properties

JSON STRUCTURE

Guardduty Ecs Task Details Structure

10 properties

JSON STRUCTURE

Guardduty Eks Cluster Details Structure

6 properties

JSON STRUCTURE

Guardduty Email Structure

0 properties

JSON STRUCTURE

Guardduty Eq Structure

0 properties

JSON STRUCTURE

Guardduty Equals Structure

0 properties

JSON STRUCTURE

Guardduty Evidence Structure

1 properties

JSON STRUCTURE

Guardduty Feature Status Structure

0 properties

JSON STRUCTURE

Guardduty Feedback Structure

0 properties

JSON STRUCTURE

Guardduty File Paths Structure

0 properties

JSON STRUCTURE

Guardduty Filter Action Structure

0 properties

JSON STRUCTURE

Guardduty Filter Condition Structure

3 properties

JSON STRUCTURE

Guardduty Filter Criteria Structure

1 properties

JSON STRUCTURE

Guardduty Filter Criterion List Structure

0 properties

JSON STRUCTURE

Guardduty Filter Criterion Structure

2 properties

JSON STRUCTURE

Guardduty Filter Description Structure

0 properties

JSON STRUCTURE

Guardduty Filter Name Structure

0 properties

JSON STRUCTURE

Guardduty Filter Names Structure

0 properties

JSON STRUCTURE

Guardduty Filter Rank Structure

0 properties

JSON STRUCTURE

Guardduty Finding Criteria Structure

1 properties

JSON STRUCTURE

Guardduty Finding Id Structure

0 properties

JSON STRUCTURE

Guardduty Finding Ids Structure

0 properties

JSON STRUCTURE

Guardduty Finding Statistic Type Structure

0 properties

JSON STRUCTURE

Guardduty Finding Statistic Types Structure

0 properties

JSON STRUCTURE

Guardduty Finding Statistics Structure

1 properties

JSON STRUCTURE

Guardduty Finding Structure

15 properties

JSON STRUCTURE

Guardduty Finding Type Structure

0 properties

JSON STRUCTURE

Guardduty Finding Types Structure

0 properties

JSON STRUCTURE

Guardduty Findings Structure

0 properties

JSON STRUCTURE

Guardduty Flags List Structure

0 properties

JSON STRUCTURE

Guardduty Free Trial Feature Result Structure

0 properties

JSON STRUCTURE

Guardduty Geo Location Structure

2 properties

JSON STRUCTURE

Guardduty Get Detector Request Structure

0 properties

JSON STRUCTURE

Guardduty Get Detector Response Structure

8 properties

JSON STRUCTURE

Guardduty Get Filter Request Structure

0 properties

JSON STRUCTURE

Guardduty Get Filter Response Structure

6 properties

JSON STRUCTURE

Guardduty Get Findings Request Structure

2 properties

JSON STRUCTURE

Guardduty Get Findings Response Structure

1 properties

JSON STRUCTURE

Guardduty Get Ip Set Request Structure

0 properties

JSON STRUCTURE

Guardduty Get Ip Set Response Structure

5 properties

JSON STRUCTURE

Guardduty Get Members Request Structure

1 properties

JSON STRUCTURE

Guardduty Get Members Response Structure

2 properties

JSON STRUCTURE

Guardduty Groups Structure

0 properties

JSON STRUCTURE

Guardduty Guard Duty Arn Structure

0 properties

JSON STRUCTURE

Guardduty Host Path Structure

1 properties

JSON STRUCTURE

Guardduty Iam Instance Profile Structure

2 properties

JSON STRUCTURE

Guardduty Instance Arn Structure

0 properties

JSON STRUCTURE

Guardduty Instance Details Structure

13 properties

JSON STRUCTURE

Guardduty Integer Structure

0 properties

JSON STRUCTURE

Guardduty Integer Value With Max Structure

0 properties

JSON STRUCTURE

Guardduty Invitation Structure

4 properties

JSON STRUCTURE

Guardduty Invitations Structure

0 properties

JSON STRUCTURE

Guardduty Invite Members Request Structure

3 properties

JSON STRUCTURE

Guardduty Invite Members Response Structure

1 properties

JSON STRUCTURE

Guardduty Ip Set Format Structure

0 properties

JSON STRUCTURE

Guardduty Ip Set Ids Structure

0 properties

JSON STRUCTURE

Guardduty Ip Set Status Structure

0 properties

JSON STRUCTURE

Guardduty Ipv6 Addresses Structure

0 properties

JSON STRUCTURE

Guardduty Kubernetes Configuration Structure

1 properties

JSON STRUCTURE

Guardduty Kubernetes Details Structure

2 properties

JSON STRUCTURE

Guardduty Kubernetes User Details Structure

3 properties

JSON STRUCTURE

Guardduty Lambda Details Structure

9 properties

JSON STRUCTURE

Guardduty Lineage Object Structure

9 properties

JSON STRUCTURE

Guardduty Lineage Structure

0 properties

JSON STRUCTURE

Guardduty List Coverage Request Structure

4 properties

JSON STRUCTURE

Guardduty List Coverage Response Structure

2 properties

JSON STRUCTURE

Guardduty List Detectors Request Structure

0 properties

JSON STRUCTURE

Guardduty List Detectors Response Structure

2 properties

JSON STRUCTURE

Guardduty List Filters Request Structure

0 properties

JSON STRUCTURE

Guardduty List Filters Response Structure

2 properties

JSON STRUCTURE

Guardduty List Findings Request Structure

4 properties

JSON STRUCTURE

Guardduty List Findings Response Structure

2 properties

JSON STRUCTURE

Guardduty List Invitations Request Structure

0 properties

JSON STRUCTURE

Guardduty List Invitations Response Structure

2 properties

JSON STRUCTURE

Guardduty List Ip Sets Request Structure

0 properties

JSON STRUCTURE

Guardduty List Ip Sets Response Structure

2 properties

JSON STRUCTURE

Guardduty List Members Request Structure

0 properties

JSON STRUCTURE

Guardduty List Members Response Structure

2 properties

JSON STRUCTURE

Guardduty Local Ip Details Structure

1 properties

JSON STRUCTURE

Guardduty Local Port Details Structure

2 properties

JSON STRUCTURE

Guardduty Location Structure

0 properties

JSON STRUCTURE

Guardduty Login Attribute Structure

4 properties

JSON STRUCTURE

Guardduty Login Attributes Structure

0 properties

JSON STRUCTURE

Guardduty Long Structure

0 properties

JSON STRUCTURE

Guardduty Long Value Structure

0 properties

JSON STRUCTURE

Guardduty Map Equals Structure

0 properties

JSON STRUCTURE

Guardduty Master Structure

4 properties

JSON STRUCTURE

Guardduty Max Results Structure

0 properties

JSON STRUCTURE

Guardduty Member Structure

8 properties

JSON STRUCTURE

Guardduty Members Structure

0 properties

JSON STRUCTURE

Guardduty Memory Regions List Structure

0 properties

JSON STRUCTURE

Guardduty Name Structure

0 properties

JSON STRUCTURE

Guardduty Neq Structure

0 properties

JSON STRUCTURE

Guardduty Network Connection Action Structure

7 properties

JSON STRUCTURE

Guardduty Network Interface Structure

10 properties

JSON STRUCTURE

Guardduty Network Interfaces Structure

0 properties

JSON STRUCTURE

Guardduty Non Empty String Structure

0 properties

JSON STRUCTURE

Guardduty Not Equals Structure

0 properties

JSON STRUCTURE

Guardduty Order By Structure

0 properties

JSON STRUCTURE

Guardduty Org Feature Status Structure

0 properties

JSON STRUCTURE

Guardduty Org Feature Structure

0 properties

JSON STRUCTURE

Guardduty Organization Ebs Volumes Structure

1 properties

JSON STRUCTURE

Guardduty Organization Structure

4 properties

JSON STRUCTURE

Guardduty Owner Structure

1 properties

JSON STRUCTURE

Guardduty Permission Configuration Structure

2 properties

JSON STRUCTURE

Guardduty Port Probe Action Structure

2 properties

JSON STRUCTURE

Guardduty Port Probe Detail Structure

3 properties

JSON STRUCTURE

Guardduty Port Probe Details Structure

0 properties

JSON STRUCTURE

Guardduty Positive Long Structure

0 properties

JSON STRUCTURE

Guardduty Private Ip Addresses Structure

0 properties

JSON STRUCTURE

Guardduty Process Details Structure

13 properties

JSON STRUCTURE

Guardduty Product Code Structure

2 properties

JSON STRUCTURE

Guardduty Product Codes Structure

0 properties

JSON STRUCTURE

Guardduty Public Access Structure

2 properties

JSON STRUCTURE

Guardduty Publishing Status Structure

0 properties

JSON STRUCTURE

Guardduty Rds Db Instance Details Structure

6 properties

JSON STRUCTURE

Guardduty Rds Db User Details Structure

5 properties

JSON STRUCTURE

Guardduty Rds Login Attempt Action Structure

2 properties

JSON STRUCTURE

Guardduty Remote Account Details Structure

2 properties

JSON STRUCTURE

Guardduty Remote Ip Details Structure

5 properties

JSON STRUCTURE

Guardduty Remote Port Details Structure

2 properties

JSON STRUCTURE

Guardduty Resource Details Structure

1 properties

JSON STRUCTURE

Guardduty Resource List Structure

0 properties

JSON STRUCTURE

Guardduty Resource Structure

12 properties

JSON STRUCTURE

Guardduty Resource Type Structure

0 properties

JSON STRUCTURE

Guardduty Runtime Context Structure

20 properties

JSON STRUCTURE

Guardduty Runtime Details Structure

2 properties

JSON STRUCTURE

Guardduty S3 Bucket Detail Structure

8 properties

JSON STRUCTURE

Guardduty S3 Bucket Details Structure

0 properties

JSON STRUCTURE

Guardduty S3 Logs Configuration Structure

1 properties

JSON STRUCTURE

Guardduty Scan Condition Pair Structure

2 properties

JSON STRUCTURE

Guardduty Scan Condition Structure

1 properties

JSON STRUCTURE

Guardduty Scan Criterion Key Structure

0 properties

JSON STRUCTURE

Guardduty Scan Criterion Structure

0 properties

JSON STRUCTURE

Guardduty Scan Detections Structure

4 properties

JSON STRUCTURE

Guardduty Scan File Path Structure

4 properties

JSON STRUCTURE

Guardduty Scan Resource Criteria Structure

2 properties

JSON STRUCTURE

Guardduty Scan Result Details Structure

1 properties

JSON STRUCTURE

Guardduty Scan Result Structure

0 properties

JSON STRUCTURE

Guardduty Scan Status Structure

0 properties

JSON STRUCTURE

Guardduty Scan Structure

14 properties

JSON STRUCTURE

Guardduty Scan Threat Name Structure

4 properties

JSON STRUCTURE

Guardduty Scan Threat Names Structure

0 properties

JSON STRUCTURE

Guardduty Scanned Item Count Structure

3 properties

JSON STRUCTURE

Guardduty Scans Structure

0 properties

JSON STRUCTURE

Guardduty Security Context Structure

1 properties

JSON STRUCTURE

Guardduty Security Group Structure

2 properties

JSON STRUCTURE

Guardduty Security Groups Structure

0 properties

JSON STRUCTURE

Guardduty Service Additional Info Structure

2 properties

JSON STRUCTURE

Guardduty Service Structure

14 properties

JSON STRUCTURE

Guardduty Sort Criteria Structure

2 properties

JSON STRUCTURE

Guardduty Source Ips Structure

0 properties

JSON STRUCTURE

Guardduty Sources Structure

0 properties

JSON STRUCTURE

Guardduty String Structure

0 properties

JSON STRUCTURE

Guardduty Subnet Ids Structure

0 properties

JSON STRUCTURE

Guardduty Tag Key List Structure

0 properties

JSON STRUCTURE

Guardduty Tag Key Structure

0 properties

JSON STRUCTURE

Guardduty Tag Map Structure

0 properties

JSON STRUCTURE

Guardduty Tag Resource Request Structure

1 properties

JSON STRUCTURE

Guardduty Tag Resource Response Structure

0 properties

JSON STRUCTURE

Guardduty Tag Structure

2 properties

JSON STRUCTURE

Guardduty Tag Value Structure

0 properties

JSON STRUCTURE

Guardduty Tags Structure

0 properties

JSON STRUCTURE

Guardduty Threat Detected By Name Structure

4 properties

JSON STRUCTURE

Guardduty Threat Intel Set Format Structure

0 properties

JSON STRUCTURE

Guardduty Threat Intel Set Ids Structure

0 properties

JSON STRUCTURE

Guardduty Threat Intel Set Status Structure

0 properties

JSON STRUCTURE

Guardduty Threat Names Structure

0 properties

JSON STRUCTURE

Guardduty Timestamp Structure

0 properties

JSON STRUCTURE

Guardduty Total Structure

2 properties

JSON STRUCTURE

Guardduty Trigger Details Structure

2 properties

JSON STRUCTURE

Guardduty Unprocessed Account Structure

2 properties

JSON STRUCTURE

Guardduty Unprocessed Accounts Structure

0 properties

JSON STRUCTURE

Guardduty Untag Resource Request Structure

0 properties

JSON STRUCTURE

Guardduty Untag Resource Response Structure

0 properties

JSON STRUCTURE

Guardduty Update Detector Request Structure

4 properties

JSON STRUCTURE

Guardduty Update Detector Response Structure

0 properties

JSON STRUCTURE

Guardduty Update Filter Request Structure

4 properties

JSON STRUCTURE

Guardduty Update Filter Response Structure

1 properties

JSON STRUCTURE

Guardduty Update Ip Set Request Structure

3 properties

JSON STRUCTURE

Guardduty Update Ip Set Response Structure

0 properties

JSON STRUCTURE

Guardduty Usage Account Result List Structure

0 properties

JSON STRUCTURE

Guardduty Usage Account Result Structure

2 properties

JSON STRUCTURE

Guardduty Usage Criteria Structure

4 properties

JSON STRUCTURE

Guardduty Usage Data Source Result Structure

2 properties

JSON STRUCTURE

Guardduty Usage Feature List Structure

0 properties

JSON STRUCTURE

Guardduty Usage Feature Result List Structure

0 properties

JSON STRUCTURE

Guardduty Usage Feature Result Structure

2 properties

JSON STRUCTURE

Guardduty Usage Feature Structure

0 properties

JSON STRUCTURE

Guardduty Usage Resource Result Structure

2 properties

JSON STRUCTURE

Guardduty Usage Statistic Type Structure

0 properties

JSON STRUCTURE

Guardduty Usage Statistics Structure

5 properties

JSON STRUCTURE

Guardduty Volume Detail Structure

7 properties

JSON STRUCTURE

Guardduty Volume Details Structure

0 properties

JSON STRUCTURE

Guardduty Volume Mount Structure

2 properties

JSON STRUCTURE

Guardduty Volume Mounts Structure

0 properties

JSON STRUCTURE

Guardduty Volume Structure

2 properties

JSON STRUCTURE

Guardduty Volumes Structure

0 properties

JSON STRUCTURE

Guardduty Vpc Config Structure

3 properties

JSON STRUCTURE

Example Payloads

Amazon Guardduty Example

6 fields

EXAMPLE

Guardduty Action Example

6 fields

EXAMPLE

Guardduty City Example

1 fields

EXAMPLE

Guardduty Condition Example

6 fields

EXAMPLE

Guardduty Container Example

6 fields

EXAMPLE

Guardduty Country Example

2 fields

EXAMPLE

Guardduty Evidence Example

1 fields

EXAMPLE

Guardduty Finding Example

6 fields

EXAMPLE

Guardduty Host Path Example

1 fields

EXAMPLE

Guardduty Invitation Example

4 fields

EXAMPLE

Guardduty Master Example

4 fields

EXAMPLE

Guardduty Member Example

6 fields

EXAMPLE

Guardduty Owner Example

1 fields

EXAMPLE

Guardduty Resource Example

6 fields

EXAMPLE

Guardduty Scan Example

6 fields

EXAMPLE

Guardduty Service Example

6 fields

EXAMPLE

Guardduty Tag Example

2 fields

EXAMPLE

Guardduty Total Example

2 fields

EXAMPLE

Guardduty Volume Example

2 fields

EXAMPLE

Guardduty Vpc Config Example

3 fields

EXAMPLE

Visuals

Amazon GuardDuty screenshot

Resources

🌐
Portal
Portal
🔗
Documentation
Documentation
📜
TermsOfService
TermsOfService
📜
PrivacyPolicy
PrivacyPolicy
💬
Support
Support
📰
Blog
Blog
👥
GitHubOrganization
GitHubOrganization
🌐
Console
Console
📝
SignUp
SignUp
🟢
StatusPage
StatusPage
🔗
Contact
Contact
🔗
SpectralRules
SpectralRules
🔗
Vocabulary
Vocabulary

Sources

Raw ↑
aid: amazon-guardduty
name: Amazon GuardDuty
description: >-
  Amazon GuardDuty is an intelligent threat detection service that continuously monitors your AWS accounts, workloads,
  and data for malicious activity. It uses machine learning, anomaly detection, and integrated threat intelligence to
  identify and prioritize potential threats to your AWS environment.
type: Index
image: https://a0.awsstatic.com/libra-css/images/logos/aws_logo_smile_1200x630.png
url: https://raw.githubusercontent.com/api-evangelist/amazon-guardduty/refs/heads/main/apis.yml
created: '2024-01-15'
modified: '2026-05-19'
specificationVersion: '0.19'
tags:
  - Anomaly Detection
  - AWS
  - Compliance
  - Machine Learning
  - Monitoring
  - Security
  - Threat Detection
apis:
  - aid: amazon-guardduty:amazon-guardduty-api
    name: Amazon GuardDuty API
    description: >-
      The Amazon GuardDuty API provides programmatic access to manage detectors, findings, filters, trusted IP sets, and
      threat intelligence for continuous threat detection across AWS accounts and workloads.
    humanURL: https://aws.amazon.com/guardduty/
    baseURL: https://guardduty.amazonaws.com
    tags:
      - Security
      - Threat Detection
      - Machine Learning
    properties:
      - type: Documentation
        url: https://docs.aws.amazon.com/guardduty/latest/APIReference/Welcome.html
      - type: OpenAPI
        url: openapi/amazon-guardduty-openapi.yml
      - type: GettingStarted
        url: https://aws.amazon.com/guardduty/getting-started/
      - type: Pricing
        url: https://aws.amazon.com/guardduty/pricing/
      - type: FAQ
        url: https://aws.amazon.com/guardduty/faqs/
      - type: APIReference
        url: https://docs.aws.amazon.com/guardduty/latest/APIReference/Welcome.html
      - type: Authentication
        url: https://docs.aws.amazon.com/general/latest/gr/signature-version-4.html
      - type: JSONSchema
        url: json-schema/guardduty-finding-schema.json
      - type: JSONLD
        url: json-ld/amazon-guardduty-context.jsonld
common:
  - type: Portal
    url: https://aws.amazon.com/guardduty/
  - type: Documentation
    url: https://docs.aws.amazon.com/guardduty/
  - type: TermsOfService
    url: https://aws.amazon.com/service-terms/
  - type: PrivacyPolicy
    url: https://aws.amazon.com/privacy/
  - type: Support
    url: https://aws.amazon.com/premiumsupport/
  - type: Blog
    url: https://aws.amazon.com/blogs/security/tag/amazon-guardduty/
  - type: GitHubOrganization
    url: https://github.com/aws
  - type: Console
    url: https://console.aws.amazon.com/guardduty/
  - type: SignUp
    url: https://portal.aws.amazon.com/billing/signup
  - type: StatusPage
    url: https://health.aws.amazon.com/health/status
  - type: Contact
    url: https://aws.amazon.com/contact-us/
  - type: SpectralRules
    url: rules/amazon-guardduty-spectral-rules.yml
  - type: Vocabulary
    url: vocabulary/amazon-guardduty-vocabulary.yaml
  - type: Features
    data:
      - name: Intelligent Threat Detection
        description: Uses ML and anomaly detection to identify threats without manual configuration or rule management.
      - name: Integrated Threat Intelligence
        description: Incorporates curated threat intelligence feeds from AWS, CrowdStrike, and Proofpoint for enhanced detection.
      - name: Multi-Account Support
        description: Monitor all accounts in an AWS Organization from a central administrator account.
      - name: Continuous Monitoring
        description: Analyzes CloudTrail, VPC Flow Logs, DNS logs, and S3 access logs 24/7 without performance impact.
      - name: Finding Prioritization
        description: Automatically prioritizes findings by severity (Low, Medium, High) for efficient response.
      - name: Malware Protection
        description: Scans EC2 instance volumes and S3 objects for malware and known threats.
  - type: UseCases
    data:
      - name: Account Compromise Detection
        description: Detect compromised AWS credentials and unauthorized API calls using ML-based anomaly detection.
      - name: Insider Threat Monitoring
        description: Identify suspicious behavior from privileged users or compromised internal accounts.
      - name: Cryptocurrency Mining Detection
        description: Detect and alert on unauthorized cryptocurrency mining using EC2 or Lambda resources.
      - name: Malware Detection
        description: Scan workloads and data for malware and ransomware threats.
      - name: Data Exfiltration Prevention
        description: Identify unusual data access patterns and potential exfiltration from S3 buckets.
  - type: Integrations
    data:
      - name: AWS Security Hub
        description: Automatically send GuardDuty findings to Security Hub for centralized security management.
      - name: Amazon EventBridge
        description: Trigger automated responses to findings using EventBridge rules and Lambda functions.
      - name: AWS Organizations
        description: Enable GuardDuty organization-wide for centralized multi-account threat monitoring.
      - name: Amazon Detective
        description: Investigate GuardDuty findings in depth using Detective for root cause analysis.
      - name: Amazon Macie
        description: Combine with Macie for comprehensive data security and threat detection.
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com
    url: https://apievangelist.com