Glossary

    GuardDuty

    Monitoring & Detection

    Amazon GuardDuty is a managed threat detection service that continuously analyzes data from CloudTrail management and data events, VPC Flow Logs, DNS logs, EKS audit logs, and S3 data events to identify malicious or unauthorized activity.

    What GuardDuty Detects

    • Compromised credentials: API calls from unusual locations or known malicious IPs
    • Crypto mining: EC2 instances communicating with mining pools
    • Data exfiltration: unusual S3 access patterns or DNS tunneling
    • Privilege escalation: anomalous IAM activity
    • Malware: EBS volume scanning for known threats
    • Multi-stage attack sequences: Extended Threat Detection (ETD) correlates events across EC2, ECS, and EKS into attack timelines

    Related AWS Services

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.