6,598 open-source and SaaS tools, with GitHub stats refreshed every day.

Amazon GuardDuty

SaaS

Managed AWS threat detection service that monitors accounts, workloads and data for malicious activity and anomalous behavior.

aws.amazon.com
Amazon GuardDuty homepage screenshot

About Amazon GuardDuty

Amazon GuardDuty is a managed threat detection service from AWS. It continuously analyzes activity in an AWS environment to spot suspicious or malicious behavior affecting accounts, workloads and stored data, and it produces findings that security teams can review and act on.

GuardDuty draws on AWS data sources such as CloudTrail event logs, VPC flow logs and DNS logs, and has protection plans that extend coverage to services such as S3, EKS and Lambda, along with malware detection. Findings can be sent to other AWS services, such as Security Hub and EventBridge, to trigger alerts or automated responses.

It is a fully managed AWS service with no infrastructure to deploy, enabled per account and region, and it can be run across an organization through AWS Organizations. Charges are usage based and detailed on the AWS pricing page.

Key features

  • Continuous threat detection for AWS accounts
  • Analysis of CloudTrail, VPC flow and DNS logs
  • Protection plans for S3, EKS and Lambda
  • Malware detection for workloads
  • Findings integrated with Security Hub and EventBridge

Good fit for

  • →Monitoring AWS accounts for compromise
  • →Feeding detections into automated response
Tags
threat-detection
aws
cloud-security
monitoring
malware
siem
managed-service

Open-source alternatives to Amazon GuardDuty

See all

SaaS alternatives to Amazon GuardDuty

See all