HAQM GuardDuty features
Overview
HAQM GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior across your AWS environment. GuardDuty uses artificial intelligence (AI), machine learning (ML), anomaly detection, and malicious file discovery, using both AWS and industry-leading threat intelligence to help protect your AWS accounts, workloads, and data. GuardDuty is capable of analyzing tens of billions of events across multiple AWS data sources, including AWS CloudTrail logs, HAQM Virtual Private Cloud (HAQM VPC) Flow Logs, and DNS query logs. GuardDuty also monitors HAQM Simple Storage Service (HAQM S3) data events, HAQM Aurora login events, and runtime activity for HAQM Elastic Kubernetes Service (HAQM EKS), HAQM Elastic Compute Cloud (HAQM EC2), and HAQM Elastic Container Service (HAQM ECS)—including serverless container workloads on AWS Fargate.
