GuardDuty
GuardDuty is AWS's managed threat detection service that continuously analyzes CloudTrail logs, VPC Flow Logs, and DNS logs using machine learning and threat intelligence to detect compromised instances, credential misuse, and cryptocurrency mining — with no agents to install. It generates findings but does not block anything on its own; automated response requires wiring findings to EventBridge and Lambda.
A security team at a Bengaluru fintech wires GuardDuty findings through EventBridge to a Lambda function that automatically isolates a compromised EC2 instance by swapping its Security Group to deny-all, buying time for manual investigation.
What It Catches
- EC2 instances communicating with known crypto-mining pools or C&C servers
- IAM credentials used from a Tor exit node or an unfamiliar geolocation
- Root account activity — any use of root is inherently suspicious
- Unusual outbound data volume suggesting exfiltration
GuardDuty vs Inspector vs Macie
GuardDuty answers "is something being attacked right now," Inspector answers "does this system have exploitable vulnerabilities," and Macie answers "does this S3 bucket contain sensitive data." All three should run together.
RememberSophisticated attackers often disable GuardDuty as a first move after compromise — alert immediately on
DeleteDetectororDisassociateMembersCloudTrail events.
Frequently Asked Questions
What data sources does GuardDuty actually analyze, and does it need agents installed?
GuardDuty is agentless — it consumes CloudTrail management and data events, VPC Flow Logs, and DNS query logs directly from AWS's control plane, so there's nothing to deploy on instances. It cross-references this activity against AWS threat intelligence feeds and applies anomaly detection models to flag things like credential compromise, unusual API call patterns, and instances communicating with known cryptomining pools.
Why do teams get surprised that enabling GuardDuty doesn't stop an attack?
GuardDuty only generates findings — it has no enforcement capability on its own. A common mistake is enabling it and assuming that's the whole job done. Real protection requires routing findings through EventBridge to a Lambda function (or Security Hub) that automatically isolates the instance, revokes credentials, or blocks the IP. Without that wiring, findings just sit in the console until someone reads them.