Amazon GuardDuty
wikipedia:Amazon GuardDuty (Nov 2017) [1] threat detection uses
- AWS CloudTrail logs:
- CloudTrail management events: activated by default, cannot be disabled.
- S3 protection: S3 data events (Jul 2020)[2], full list https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html
- EC2 Instance Credential Exfiltration (Jan 2022) [3]
- Homepage: https://aws.amazon.com/guardduty/
Detection examples
- Compromised EC2 instances mining bitcoin
- An attacker scanning your web servers for known application vulnerabilities
- GuardDuty does not process requests to objects that you have made publicly accessible, but it does alert you when a bucket is made publicly accessible
Cost
Formats
- TXT
- STIX
- OTX_CSV
- ALIEN_VAULT
- PROOF_POINT
- FIRE_EYE
Related
- AWS CloudTrail management event analysis
- Delegated Administrator
- CrowdStrike
- AWS CloudTrail Insights
- AWS Guardrails in AWS Control Tower
EC2 instance i-XXXXXXX is communicating with IP address 163.x.x.x.x on the Tor Anonymizing Proxy network marked as an Entry node. Jump to navigationJump to search
- aws-guardduty-agent
Activities
- https://aws.amazon.com/premiumsupport/knowledge-center/guardduty-cloudwatch-sns-rule/
- Read FAQ: https://aws.amazon.com/guardduty/faqs/
- Read https://stackoverflow.com/questions/tagged/amazon-guardduty?tab=Votes
- Alarms: https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_findings_cloudwatch.html
- https://github.com/aws-samples/amazon-guardduty-for-aws-organizations-with-terraform
See also
- Amazon GuardDuty:
aws guardduty
[ list-detector | list-findings | create-detector | update-detector ]
- AWS GuardDuty, S3 protection, for EKS.
aws guardduty
, Finding type, aws-guardduty-agent EKS addon, Runtine Monitoring - AWS security, AWS Security Hub, AWS CloudTrail, Amazon GuardDuty, Amazon Detective, AWS WAF, AWS Audit Manager, Amazon Fraud Detector, Cloudsploit, AWS Certified Security - Specialty, AWS Security Assurance Services, AWS GDPR, Amazon Inspector, AWS Network Firewall, Zelkova
Advertising: