Glossary

    Threat Detection

    Monitoring & Detection

    Threat Detection is the process of identifying potential security threats in real-time or near-real-time. In AWS, threat detection combines multiple data sources (API logs, network traffic, DNS queries) with machine learning and threat intelligence to surface malicious activity.

    AWS Threat Detection Services

    • GuardDuty: behavioral analysis and anomaly detection across accounts
    • Inspector: vulnerability scanning for EC2, Lambda, ECR, plus code security (SAST, SCA, and IaC scanning) since 2025
    • Macie: sensitive data discovery in S3
    • Security Hub: aggregation and compliance checks
    • CloudWatch Anomaly Detection: metric-based anomaly alerts
    • EventBridge: real-time event routing for automated response

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.