このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。
Goal
Detect when an AWS GuardDuty finding has been raised.
Strategy
AWS GuardDuty is a native threat detection service that monitors:
- CloudTrail management events
- AWS CloudTrail data events for Amazon S3
- DNS logs
- Kubernetes audit logs
- Amazon VPC flow logs
- RDS login activity monitoring
It also analyzes Amazon EBS volume data for Malware Protection in Amazon GuardDuty. With these data sources, GuardDuty generates security findings for your account.
Triage and response
- Investigate the GuardDuty finding to determine if it is malicious or benign.
- If the finding is deemed malicious, follow the remediation guidance provided by Amazon along with any internal incident response processes.
- Otherwise findings can be managed to reduce false positives through:
Changelog
- 7 September 2023 - Updated group by value for EC2 query.
- 28 November 2023 - Added query for Runtime findings.
- 19 December 2023 - Added query for Runtime findings from ECS clusters.