Amazon GuardDuty logo

Amazon GuardDuty

Amazon GuardDuty is an intelligent threat detection service that continuously monitors your AWS accounts, workloads, and data for malicious activity. It uses machine learning, anomaly detection, and integrated threat intelligence to identify and prioritize potential threats to your AWS environment.

1 APIs 1 Capabilities 6 Features
Anomaly DetectionAWSComplianceMachine LearningMonitoringSecurityThreat Detection

APIs

Amazon GuardDuty API

The Amazon GuardDuty API provides programmatic access to manage detectors, findings, filters, trusted IP sets, and threat intelligence for continuous threat detection across AWS...

Capabilities

Amazon GuardDuty Threat Detection

Workflow capability for security teams using Amazon GuardDuty for AWS threat detection and response. Covers finding management, detector configuration, threat intelligence integ...

Run with Naftiko

Features

Intelligent Threat Detection

Uses ML and anomaly detection to identify threats without manual configuration or rule management.

Integrated Threat Intelligence

Incorporates curated threat intelligence feeds from AWS, CrowdStrike, and Proofpoint for enhanced detection.

Multi-Account Support

Monitor all accounts in an AWS Organization from a central administrator account.

Continuous Monitoring

Analyzes CloudTrail, VPC Flow Logs, DNS logs, and S3 access logs 24/7 without performance impact.

Finding Prioritization

Automatically prioritizes findings by severity (Low, Medium, High) for efficient response.

Malware Protection

Scans EC2 instance volumes and S3 objects for malware and known threats.

Use Cases

Account Compromise Detection

Detect compromised AWS credentials and unauthorized API calls using ML-based anomaly detection.

Insider Threat Monitoring

Identify suspicious behavior from privileged users or compromised internal accounts.

Cryptocurrency Mining Detection

Detect and alert on unauthorized cryptocurrency mining using EC2 or Lambda resources.

Malware Detection

Scan workloads and data for malware and ransomware threats.

Data Exfiltration Prevention

Identify unusual data access patterns and potential exfiltration from S3 buckets.

Integrations

AWS Security Hub

Automatically send GuardDuty findings to Security Hub for centralized security management.

Amazon EventBridge

Trigger automated responses to findings using EventBridge rules and Lambda functions.

AWS Organizations

Enable GuardDuty organization-wide for centralized multi-account threat monitoring.

Amazon Detective

Investigate GuardDuty findings in depth using Detective for root cause analysis.

Amazon Macie

Combine with Macie for comprehensive data security and threat detection.

Semantic Vocabularies

Amazon Guardduty Context

247 classes · 297 properties

JSON-LD

API Governance Rules

Amazon GuardDuty API Rules

8 rules · 5 errors 2 warnings 1 info

SPECTRAL

Resources

🌐
Portal
Portal
🔗
Documentation
Documentation
📜
TermsOfService
TermsOfService
📜
PrivacyPolicy
PrivacyPolicy
💬
Support
Support
📰
Blog
Blog
👥
GitHubOrganization
GitHubOrganization
🌐
Console
Console
📝
SignUp
SignUp
🟢
StatusPage
StatusPage
🔗
Contact
Contact
🔗
SpectralRules
SpectralRules
🔗
Vocabulary
Vocabulary
🔗
NaftikoCapability
NaftikoCapability