Amazon Web Services (AWS) introduced a fully managed intelligent threat detection service for protecting their AWS accounts and workloads by continuously monitoring account activity for malicious or unauthorized behavior.
Amazon GuardDuty continuously applies machine learning to identify any events that fall outside the normal patterns. AWS said it is using both proprietary, AWS-developed threat intelligence sources and industry-leading third-party sources.
Amazon GuardDuty can send all findings to AWS CloudWatch Events and supports API endpoints through the AWS SDK, allowing for interoperability with third-party solutions such as Alert Logic, Evident.io, Palo Alto Networks, Rapid7, Redlock, Splunk, Sumo Logic, and Trend Micro.
