From the course: AWS Administration: Security Fundamentals

Unlock this course with a free trial

Join today to access over 25,300 courses taught by industry experts.

AWS GuardDuty

AWS GuardDuty

- [Instructor] Another interesting security service to consider is GuardDuty. GuardDuty has several detection categories. The primary detection categories, it's looking at reconnaissance activity, suggesting attacks may be happening. It looks at EC2 instance compromise patterns. Is there something going on in the background that you are not aware of? It also looks at the account as a whole and checks out, is it being compromised? Looking at the API calls to this account, do these API calls make sense? And finally, is there some sort of compromise going on with accessing specific S3 buckets? Now, that's the big picture of using GuardDuty, but there's other features we'll look at as well that GuardDuty carries out. And every time I look at the GuardDuty documentation, there's new features being added. So in a nutshell, could I not use GuardDuty and use, say, CloudTrail and CloudWatch and some of the logging services?…

Contents