AWS GuardDuty Educational Infographic

AWS GuardDuty

Intelligent threat detection through continuous monitoring and machine learning.

The Data Ingredients

GuardDuty consumes massive streams of metadata to identify patterns.

VPC Flow Logs

Analyzes network traffic patterns entering and leaving your virtual private cloud.

AWS CloudTrail

Monitors API activity and management events to detect unauthorized account access.

DNS Query Logs

Identifies instances communicating with known malicious domains or C&C servers.

S3 Data Events

Detects suspicious access patterns or unusual data volume transfers in S3 buckets.

The Detection Engine

How raw data transforms into actionable security intelligence.

LOG DATA MACHINE LEARNING ANALYSIS Anomaly & Behavioral Detection SECURITY FINDINGS Prioritized by Severity

Behavioral Analysis

Uses ML to establish a “normal” baseline for your account and flags deviations.

Threat Intelligence

Integrates AWS and 3rd-party feeds to identify known malicious IP addresses.

Automated Response

Pairs with EventBridge and Lambda for near-real-time threat remediation.

0
Infrastructure to
Manage
1-Click
Deployment
Across Accounts
24/7
Continuous
Monitoring

AWS GuardDuty Infographic • Cloud Security Educational Series

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top