AWS GuardDuty

· 1 min read · AWS

Amazon GuardDuty continuously analyzes CloudTrail events, VPC Flow Logs and DNS logs, with optional protection for S3, EKS, RDS, Lambda and malware scanning, and reports findings such as unusual API calls, credentials used from a strange location or instances talking to known malicious IPs. It needs no agents. It is enabled per region (or centrally for an organization) and charges by volume of analyzed data.

With Terraform: aws_guardduty_detector and aws_guardduty_detector_feature. See security monitoring.

More tutorials that use GuardDuty

#AWS #Security