Glossary

    Amazon Detective

    Monitoring & Detection

    Amazon Detective makes it easy to analyze, investigate, and quickly identify the root cause of security findings or suspicious activities. It automatically collects log data from CloudTrail, VPC Flow Logs, GuardDuty findings, and EKS audit logs.

    How It Works

    • Builds a behavior graph from up to 12 months of historical data
    • Uses machine learning, statistical analysis, and graph theory to link related findings
    • Visualizes resource interactions, API call patterns, and network connections

    Investigation Features

    • Finding Groups: automatically groups related GuardDuty findings into potential security incidents
    • Entity Profiles: detailed timelines for IP addresses, IAM principals, EC2 instances
    • Investigation Summaries: AI-generated narratives explaining unusual behavior

    Integration

    • One-click pivot from GuardDuty or Security Hub findings to Detective
    • Multi-account support via Organizations
    • No log management or ETL required - automatic ingestion

    Related AWS Services

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.