# AWS GuardDuty

> Amazon GuardDuty is a managed threat detection service that analyzes CloudTrail, VPC flow and DNS logs to find compromised resources and attacks.

- Source: https://www.itwonderlab.com/aws-guardduty/
- Published: 2026-02-27
- Updated: 2026-02-27
- Author: Javier Ruiz Jiménez (https://www.javierruizjimenez.com/)
- Site: IT Wonder Lab (https://www.itwonderlab.com/)

---

**Amazon GuardDuty** continuously analyzes [CloudTrail](https://www.itwonderlab.com/aws-cloudtrail/) events, VPC Flow Logs and DNS logs, with optional protection for S3, EKS, RDS, Lambda and malware scanning, and reports **findings** such as unusual API calls, credentials used from a strange location or instances talking to known malicious IPs. It needs no agents. It is enabled per region (or centrally for an organization) and charges by volume of analyzed data.

With Terraform: `aws_guardduty_detector` and `aws_guardduty_detector_feature`. See [security monitoring](https://www.itwonderlab.com/terraform-aws-security-monitoring/).
