Book a demo call with us
Cross icon
Cloud
Threat-intel

AWS GuardDuty

Coming soon

AWS's intelligent threat detection service that continuously monitors CloudTrail logs, VPC Flow Logs, and DNS logs for malicious activity. It uses machine learning and threat intelligence to identify compromised accounts, unusual API behavior, and unauthorized deployments.

AWS GuardDuty

What is AWS GuardDuty?

AWS GuardDuty is Amazon's managed threat detection service for cloud environments. It continuously analyzes CloudTrail event logs, VPC Flow Logs, and DNS query logs using a combination of machine learning models, anomaly detection, and curated threat intelligence feeds. GuardDuty identifies behaviors that indicate compromised EC2 instances, credential theft, cryptocurrency mining, unusual data exfiltration patterns, and reconnaissance activity targeting AWS resources. Because it operates at the account level without requiring any agents or sensors, it provides broad coverage across the entire AWS environment with minimal operational overhead. The findings it generates are structured, severity-rated, and ready to feed directly into SIEM or SOAR pipelines for further investigation.

How does AWS GuardDuty work with Qevlar?

GuardDuty findings flow into Qevlar's investigation engine, allowing automated triage of cloud security alerts. When GuardDuty flags a compromised instance or an unusual API call pattern, Qevlar can correlate that finding with identity data, network logs, and endpoint telemetry to determine the true scope and impact without manual analyst intervention.

Want to help your analysts focus on the most critical alerts?

Frequently asked questions

What is AWS GuardDuty?

bar
bar

AWS GuardDuty is Amazon's managed threat detection service. It continuously analyzes CloudTrail, VPC Flow Logs and DNS logs using machine learning and threat intelligence to surface compromised accounts, credential misuse and unusual cloud activity.

What can you do with AWS GuardDuty in Qevlar?

bar
bar

GuardDuty findings can flow into Qevlar for automated triage, where each finding is correlated with identity, network and endpoint data to determine the true scope and impact before an analyst gets involved.

Does Qevlar help with GuardDuty alert volume?

bar
bar

Yes. Rather than reviewing findings one by one, Qevlar investigates them automatically and prioritizes the ones that represent genuine threats, cutting the noise that GuardDuty can generate at scale.

Can a GuardDuty finding be investigated across other tools?

bar
bar

Yes. Qevlar treats a GuardDuty finding as a starting point and pivots into the rest of your stack — cloud logs, identity and endpoint telemetry — to build a complete picture of the activity.

Other integrations